HomeSecurityMedochemie: Qilin ransomware claims attack on Cypriot pharmaceutical company

Medochemie: Qilin ransomware claims attack on Cypriot pharmaceutical company

Medochemie , one of Cyprus ’ largest pharmaceutical companies with international operations, appeared on August 19, 2026, on the list of victims of the notorious Qilin ransomware group . The group listed the company on its dark web leak site, claiming to have gained access to the organization’s internal data. Medochemie has not yet publicly confirmed the incident and no stolen files have yet been made public.

Medochemie Qilin ransomware attack Cyprus pharmaceutical company

According to Ransomware.live, the listing appeared at 11:01 UTC on August 19, with an estimated attack date of the same day. The incident is part of a larger wave of Qilin activity that added five new victims to its portal on the same day: Philippe Hottinguer Group (France), InVentry (UK), Smart Energies (France), WIS Logistics (US), and Medochemie Ltd (Cyprus).

See also: Medusa Ransomware: New victims in critical infrastructure

What is Medochemie and why does it matter?

Medochemie is a Cypriot multinational pharmaceutical company specializing in the development, production and international distribution of branded generic medicines. It was founded in 1976 and currently operates in more than 100 countries, covering therapeutic categories including antibiotics, cardiovascular, gastrointestinal, analgesics, dermatological and many more. The company employs hundreds of employees in Cyprus and has WHO GMP, FDA certifications and European EMA approvals.

The SecNews technical team points out that a successful ransomware attack on a pharmaceutical organization of this size could have serious implications for the drug supply chain, clinical trial documents, intellectual property (patents, formulations), and personal data of patients or employees. Furthermore, any leakage of patient data or medical records raises serious obligations under the GDPR, but also under the NIS2 for critical infrastructures, where the healthcare sector is fully included.

Qilin ransomware leak site dark web victim list
Qilin maintains a leak site on the dark web where it gradually publishes victims' data to pressure them into paying ransom.

Who is the Qilin ransomware group?

Qilin (also known as Agenda ) is one of the most active Ransomware-as-a-Service (RaaS) groups , first appearing in October 2022. The group operates with a dual-extortion model: encrypting systems and simultaneously extracting data, threatening publication if a ransom is not paid. Qilin has recorded hundreds of victims internationally and has specialized in attacks on the healthcare sector.

Qilin malware is written in Rust and Golang, languages ​​that provide cross-platform compatibility (Windows, Linux, VMware ESXi) and make it difficult to analyze by anti-malware defenses. It uses ChaCha20 and AES cryptographic algorithms, while the latest generation versions include automatic propagation capabilities within corporate networks via PsExec and SMB tools. Initial entry is usually via phishing emails, exploitation of VPN vulnerabilities, or attacks on user credentials.

What Qilin claims — and what remains uncertain

According to Orizon threat intelligence, Medochemie's listing on Qilin's leak site is not accompanied by a specific description of the stolen data or a sample screenshot. HookPhish and MedRisk characterize the claim as high severity but unconfirmed, as there is no official announcement yet from Medochemie itself, nor from any IT security authority or regulatory body.

Qilin’s historical tactics show that the group typically proceeds with a gradual release of data to pressure the victim into paying. If sample documents, employee records, or customer data emerge in the coming weeks, the claim will be considered confirmed. The Recent Breaches classification classifies the incident as HIGH severity with a clear label for “unverified claim, pending independent verification”.

See also: Ransomware attacks on critical infrastructure: Analysis

Implications for Cyprus and the pharmaceutical ecosystem

The Medochemie incident is the nineteenth ransomware incident on a Cypriot entity recorded in the Ransomware.live database. Cyprus, as an EU member state with significant activity in pharmaceuticals, tourism and financial services, is increasingly being targeted by cyberattacks. The Cyprus Digital Security Authority (DSA) and the national CSIRT-CY are responsible for supporting organizations in such incidents, while the NIS2 directive sets out immediate reporting obligations within 24 hours of becoming aware of a serious incident.

The attack on Medochemie follows a series of similar incidents against European pharmaceutical organizations. Qilin's targeting of pharmaceutical companies becomes extremely profitable not only because of the high value of the stolen data (formulas, clinical studies, patient data), but also because the companies are pressured by regulators to restore operations quickly, which increases the pressure to pay ransoms.

What Medochemie should do and what customers/partners can do

The SecNews technical team recommends that Medochemie immediately activate an Incident Response with preservation of all forensic evidence before any restoration, mandatory password reset and revocation of active sessions for all users, rotation of API keys and certificates that may have been exposed, and submission of a report within the prescribed deadlines (72 hours GDPR, 24 hours NIS2) to the Cyprus Data Protection Authority and CSIRT-CY.

For Greek and Cypriot patients using Medochemie medicines, there is no immediate risk to their medication. However, if someone has registered personal information through the company's websites or applications, they should be careful of suspicious emails, SMS or phone calls impersonating Medochemie or partner companies. Informants with further information can contact anonymously via the report.secnews.gr — SecNews is monitoring the case and will update as soon as new information emerges.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS