On April 2, 2024, pharmaceutical developer Crinetics Pharmaceuticals appeared on the LockBit 3.0 ransomware leak site with the claim that internal files had been exfiltrated. The listing, hosted on the group’s .onion portal and mirrored on ransomware.live, states that data was taken during a ransomware incident but does not specify the volume of records, the exact types of files, or the number of individuals whose information may be inside the archive.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch crinetics.com
Get alerted the next time crinetics.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about crinetics.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Posting
The LockBit 3.0 panel entry for crinetics.com states that the company was hit by a ransomware attack and that attackers successfully exfiltrated internal files. No sample data is shown publicly, no ransom amount is listed in the visible post, and the disclosure does not quantify how many patient records, employee records, or research documents were taken. The posting follows the group’s standard format: company name, date added, and a countdown clock for the extortion deadline. Crinetics has not yet issued a public regulatory filing detailing the scope, so the precise scale of exposure remains unknown to outsiders.
Why This Matters for You and Your Family
When a biotechnology firm like Crinetics is breached, the information at risk often includes names, addresses, dates of birth, Social Security numbers, medical diagnoses, insurance details, and clinical-trial participant records. Even if you have never directly interacted with the company, your data may have been shared by a treating physician, a clinical-trial coordinator, an insurer, or a family member enrolled in one of their endocrine-disease studies. Once that information sits in an attacker’s archive, it can be sold, published, or used to build synthetic identities that target you or your relatives for years to come. Medical data commands a premium on underground markets precisely because it is difficult to change and highly useful for fraud, blackmail, or insurance scams.
The Doxxing and Identity-Chain Risk
Internal files frequently contain spreadsheets that link employee and patient identities to email addresses, phone numbers, and sometimes even home addresses. Attackers routinely cross-reference these details with credential leaks from other breaches, creating long identity chains that tie your work email to your personal accounts, your children’s gaming usernames, and your family’s physical location. A single exposed medical record can therefore cascade into account takeovers across email, banking, and online gaming platforms. DoxxScan by GalaxyWarden continuously monitors 13.1B+ breach records and 100+ platforms with AI-powered identity-chain mapping that surfaces these linkages before criminals exploit them. The service also provides hands-on remediation by specialists and household coverage that includes children’s gaming accounts, which are common entry points for doxxing chains that begin with credential leaks like this one.