On November 28, 2023, Hi School Pharmacy appeared on the LockBit 3.0 ransomware leak site, claiming the company had been hit by a ransomware attack in which internal files were exfiltrated. The listing, hosted on the group’s dark-web portal, states that data was stolen and will be published unless the pharmacy meets the attackers’ demands. Anyone who has filled a prescription, worked at, or done business with the British Columbia-based chain now faces the possibility that sensitive personal and corporate records are in criminal hands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the Leak-Site Listing
The LockBit 3.0 portal explicitly names hi-schoolpharmacy.com and describes the incident as a successful ransomware deployment followed by data exfiltration. The posting does not quantify how many records were taken, nor does it list specific file types beyond the generic label “internal files.” No sample data appears to have been released at the time the listing went live, and the disclosure gives no exact breach date. What is certain is that the attackers claim to possess files taken from the pharmacy’s network and have set a publication deadline typical of their extortion cycle.
Why This Matters for You and Your Family
If you or a family member have used Hi School Pharmacy to fill prescriptions, the stolen internal files could contain names, addresses, dates of birth, prescription histories, and possibly payment details. Even without an exact record count, the exposure of pharmacy data carries long-term risk: health information is among the most sensitive categories because it cannot be changed like a password and can be used for insurance fraud, blackmail, or identity theft. Employees’ payroll records, supplier contracts, and internal emails may also be included, increasing the chance that someone connected to you ends up doxxed or targeted with phishing that references real prescription or employment details.
The Doxxing and Identity-Chain Risk
Ransomware groups rarely stop at one leak. Once internal files surface, other criminals scrape them for email addresses, usernames, and phone numbers that link to your broader digital footprint. A single credential or personal detail from the pharmacy breach can be combined with information from earlier breaches to map your identity across social media, shopping accounts, and children’s gaming profiles. These identity chains often lead to account takeovers, SIM-swapping attempts, or targeted harassment. Credential leaks like this one cascade into account takeovers and doxxing chains, especially when gaming accounts belonging to teenagers share the same family email or phone number listed in a parent’s pharmacy record.