On August 25, 2024, Australian pharmaceutical company Arrotex Pharmaceuticals appeared on the leak site operated by the morpheus Ransomware Group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which operates the website dbghealth.com.au and generates roughly $92 million in revenue. The exact number of people whose information may be exposed remains unknown, and the leak-site listing does not detail precisely which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from the Listing
The primary disclosure on the morpheus leak site indicates that Arrotex Pharmaceuticals suffered a ransomware incident in which attackers successfully exfiltrated internal files before encrypting systems or demanding payment. No specific volume of records is published, nor does the listing enumerate the categories of data involved beyond the broad description of internal files. The notification does not provide a ransom demand figure or a public deadline, though such listings typically appear after initial extortion attempts have failed or gone unanswered. Public reporting on morpheus states the group uses this leak site to publish proof of compromise and to pressure victims into payment.
Why This Matters for You and Your Family
When a healthcare-adjacent company like Arrotex loses control of internal files, the information inside often includes details that can be traced back to patients, suppliers, employees, or business partners. Even if your name is not on a customer list, any document containing your address, date of birth, phone number, email, or insurance information creates a permanent record that can surface years later. For ordinary families this means heightened risk of identity theft, insurance fraud, and targeted scams that exploit healthcare relationships. The breach also underscores how data you entrust to pharmacies, doctors, and suppliers can escape through third-party vendors you never directly chose.
Doxxing and Identity-Chain Risks
Exfiltrated internal files frequently contain spreadsheets, emails, or databases that link names to contact details, employee IDs, or customer reference numbers. Attackers and subsequent buyers can combine these fragments with other leaks to build a complete identity chain: email to phone, phone to home address, address to family members. Once that chain exists, credential-stuffing attacks against personal accounts become trivial. Children’s gaming accounts are especially vulnerable because kids often reuse email addresses or passwords tied to a parent’s work or healthcare records. A single leak like this can therefore cascade into doxxing campaigns that expose your full household.