On February 11, 2025, Malaysian pharmaceutical manufacturer Xepa-Soul Pattinson (M) Sdn Bhd appeared on the leak site of the lynx ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which produces a wide range of off-patent medicines used by pharmacies, clinics and hospitals across Malaysia.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Xepa Soul
Get alerted the next time Xepa Soul files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Xepa Soul’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involves Xepa-Soul Pattinson, a company founded in 1967 in Singapore and now based in Malacca, Malaysia. The lynx ransomware group posted details of the breach on its leak site on February 11, 2025. Available reporting describes the data as internal files exfiltrated after a ransomware deployment, though the exact volume and specific types of records remain unconfirmed by the company. No public statement from Xepa has detailed the precise data categories exposed or the number of individuals whose information may be affected.
Why This Matters for You and Your Family
When a pharmaceutical company’s internal files are stolen, the information inside often includes names, addresses, national identification numbers, medical prescriptions, insurance details and payment records of patients, suppliers and employees. If your family has ever filled a prescription at a Malaysian pharmacy, received medication from a clinic supplied by Xepa, or worked with any healthcare provider that uses their products, your personal data could be among the records now in attackers’ hands. Once leaked, this information does not expire. It can be sold, combined with other breaches, and used months or years later to commit identity theft, file fraudulent insurance claims, or open accounts in your name.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one company. Criminals frequently cross-reference stolen internal spreadsheets against other breach databases to build detailed profiles. A single email address or phone number from this incident can link your gaming username, social-media handles, children’s school records and home address into a single chain. Public reporting shows these chains are then used for doxxing, targeted phishing, or extortion. Credential leaks like this one routinely cascade into account takeovers on gaming platforms, where children’s accounts become entry points for further harassment or financial fraud.