Menu
Browse

Cyber Incident Victim: Lupin

Date:

Nov 2020

Location:

India

Summary

A major Indian pharmaceutical company experienced a cybersecurity breach impacting several internal IT systems, though core operations remained unaffected. This incident occurred shortly after a ransomware attack forced another pharmaceutical firm to isolate servers and temporarily halt global manufacturing operations. Such attacks reflect heightened targeting of the healthcare sector during the pandemic, with industry reports indicating malicious attacks now account for half of healthcare breaches. The sector faces significantly higher financial impacts from breaches compared to other industries and requires nearly a year on average to detect and contain incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early November 2020, Indian pharmaceutical company Lupin disclosed a cybersecurity breach affecting multiple internal IT systems. The incident occurred within two weeks of a ransomware attack targeting competitor Dr. Reddy’s Laboratories, which had forced global manufacturing shutdowns and server isolation at that firm. Lupin confirmed the security event through a public statement on November 5, 2020, clarifying that core operational systems remained unaffected. While the company did not specify the attack vector or duration of system compromise, it acknowledged disruptions to non-core IT infrastructure. This dual targeting of major Indian pharmaceutical companies occurred against the backdrop of increased cyberattacks on healthcare organizations during the COVID-19 pandemic. The disclosure followed a June 2020 incident where security researcher Sai Krishna Kothapalli demonstrated vulnerabilities in Indian healthcare systems by accessing sensitive patient data.

Cyber Incident Image

Healthcare sector breaches during this period carried significant financial consequences, with IBM’s 2020 report calculating average costs of $7.3 million per incident – 84% above cross-industry averages. Verizon’s 2020 Data Breach Investigations Report identified ransomware attacks by financially motivated groups as predominant threats to the industry. Detection and containment timelines remained protracted, with healthcare organizations requiring approximately 329 days on average to identify and resolve breaches according to IBM’s data. Half of all healthcare data breaches stemmed from malicious attacks rather than technical failures or human error. The Lupin incident exemplified broader global challenges, with nations like Germany responding through legislative measures for patient data protection as cyber threats escalated across the healthcare sector worldwide.

Sources
Sources available to members
1 source