On November 5, 2023, Currax Pharmaceuticals appeared on the leak site operated by the alphv ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the specialty biopharmaceutical company. The disclosure does not quantify how many individuals are affected, nor does it list the specific types of records taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the alphv Listing
The primary disclosure on the alphv leak site indicates that Currax Pharmaceuticals suffered a ransomware intrusion in which attackers successfully exfiltrated internal files before encryption. No patient count, employee count, or exact data inventory is provided. The listing follows the group’s standard format: a victim profile, proof-of-exfiltration samples, and a countdown timer for public data release if demands are not met. Public reporting on alphv confirms the group typically uses this dual extortion model—threatening both operational disruption and data publication.
Currax Pharmaceuticals develops and markets prescription medicines focused on obesity and smoking cessation. Any internal files taken could therefore contain sensitive information related to drug development, clinical trial records, supplier contracts, employee personal data, or partner agreements. The leak site does not detail what was taken, so the precise exposure remains unknown.
Why This Matters for You and Your Family
When a healthcare-adjacent company like Currax is breached, ordinary patients, study participants, employees, and their households face downstream risk. Even if your name is not on a public patient list, related records can link back to you through shared addresses, insurance details, or family-member employment. A single leak can supply the missing piece that ties your email, phone number, or date of birth to other stolen credentials. Internal files exfiltrated in such attacks often include spreadsheets or documents that attackers later parse for personally identifiable information.