On March 4, 2026, the Italian pharmaceutical IT company Formula50 appeared on the LockBit 5 ransomware leak site with internal files listed for public download after the group claimed to have exfiltrated data during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from Reporting
Public reporting indicates that LockBit 5 posted a dedicated page for Formula50 on its onion leak site. The company, which provides specialized IT services to the pharmaceutical sector at a national level in Italy, had an unknown number of internal documents taken. Available reporting describes the exposed material as internal files, though the precise volume and exact contents remain unclear from the initial posting. The incident follows the group’s typical pattern of encrypting victim systems, exfiltrating selected data beforehand, and then publishing samples when ransom demands go unmet.
Why This Matters for You and Your Family
When a company that handles sensitive health-related records or partner information suffers a breach, the ripple effects can reach ordinary people. If you or your family have ever received medical services, filled prescriptions, or interacted with pharmacies or health-tech providers that might use Formula50’s systems, your personal details could be caught in the leak. Health data and associated contact information are especially valuable to identity thieves because they combine medical history with addresses, phone numbers, and sometimes payment details. Once such information surfaces on dark-web forums, it rarely disappears. Criminals reuse it for months or years, increasing the chance that someone will target you or your children with phishing, insurance fraud, or more sophisticated scams.
The Doxxing and Identity-Chain Risks
A single corporate breach rarely stops at the company name. Internal files often contain spreadsheets of partners, employee directories, email correspondence, or configuration details that link corporate accounts to personal ones. Attackers and subsequent buyers can chain these fragments together: an email address found in one document leads to a reused password at a consumer site, which leads to a gaming account belonging to your child, which reveals a home address. This is exactly how credential leaks cascade into full doxxing. Gaming accounts are frequent targets because children often use the same email or password patterns as their parents, turning one breach into a household compromise.