On March 14, 2025, pharmaceutical manufacturer Perrigo appeared on the leak site of the termite ransomware group, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Perrigo
Get alerted the next time Perrigo files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Perrigo’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Perrigo, founded in 1887 and headquartered in Dublin, Ireland, is a global supplier and manufacturer of private-label over-the-counter pharmaceuticals. The termite ransomware group posted evidence of the breach on its leak site, accessible via the .onion address tracked by ransomware.live. Available reporting describes the exposed material as internal files, though the precise volume and full list of data types have not been independently verified in open sources. No confirmed victim count for individuals has been released, and it remains unclear exactly which categories of sensitive information—such as employee records, customer details, or supplier contracts—were taken.
Why This Matters for You and Your Family
When a healthcare supplier like Perrigo suffers a breach, the ripple effects can reach ordinary families who rely on its products or whose information sits in its systems. Internal files often contain names, addresses, dates of birth, contact details, and sometimes payment or insurance information. Once that data leaves the company’s control, it can surface on dark-web markets, fueling identity theft, fraudulent tax filings, or medical fraud in your name. For parents, the exposure of family-linked records can also put children at risk, especially when gaming accounts or school-related details share the same email addresses or passwords used for healthcare services.
March 14, 2025 marks the public confirmation of this incident. The longer the stolen data circulates without action, the higher the chance it will be packaged and sold. Families cannot assume that a large corporation will notify every affected person quickly or completely.