On August 26, 2022, Moroccan pharmaceutical company galenica.ma appeared on the LockBit 3.0 ransomware leak site. The listing states that the group exfiltrated internal files during a ransomware attack and is now threatening to publish them if demands are not met. Anyone whose personal or medical information passed through Galenica’s systems may have been exposed, even though the exact number of affected records remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch galenica.ma
Get alerted the next time galenica.ma files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about galenica.ma’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The LockBit 3.0 listing for galenica.ma states that attackers gained access to the company’s network, encrypted systems, and exfiltrated internal files. The disclosure does not specify the volume or exact types of data taken, only that sensitive internal documents were removed. As is typical with LockBit operations, the group set a publication deadline and offered to negotiate via their onion-site portal. The primary source listing, archived on ransomware.live, contains no further technical details about the initial access vector or the precise contents of the stolen archive.
Why This Matters for You and Your Family
When a healthcare-adjacent company like Galenica is breached, the consequences reach far beyond corporate embarrassment. Internal files often contain patient names, prescription records, national identification numbers, insurance details, or employee payroll data. If any of that information belongs to you or a family member, it can be used for identity theft, insurance fraud, or targeted phishing. Even without a confirmed record count, the uncertainty itself creates risk: you cannot assume your data is safe simply because the leak site does not list specific fields.
Doxxing and Identity-Chain Risks
Stolen internal files frequently include email addresses, phone numbers, and employee or customer usernames that link real identities to online handles. Attackers and opportunistic criminals then chain these details across dozens of other platforms. A single leaked work email can expose personal accounts, social-media profiles, and even children’s gaming logins that reuse the same password. Once the chain begins, doxxing escalates quickly from leaked documents to full identity profiles sold on underground forums.