CSIDB logo
Incident

Rekah

Incident posture

Attack window
Jun 2024
Location
Israel
Status
Historical
CIA posture
Available to members
Updated
2026-01-02 16:07

Linked entities

Victim
Rekah
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber attack targeted an Israeli pharmaceutical company, Rekah, forcing the shutdown of its distribution system after unauthorized access to subsidiary systems was detected. The company proactively disabled compromised systems and assembled a team with external cybersecurity experts to contain the breach, investigate the incident, and restore operations, while preliminary assessments indicated limited damage. Production systems remained unaffected, and temporary manual distribution methods were being explored to mitigate prolonged disruption, with the CEO noting existing customer inventories likely prevented immediate supply shortages despite the halted automated distribution.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 1, 2024, Israeli pharmaceutical company Rekah publicly confirmed a cyber attack targeting its subsidiary Ophir & Shalpharm Medicines and Cosmetics, which operates the central computerized distribution and sales system for the parent organization. The intrusion by an unauthorized party prompted Rekah to proactively shut down the compromised systems to prevent further damage, halting all automated distribution operations. CEO Mordechai Algrably stated the company immediately established a specialized incident response team comprising internal staff and external cybersecurity professionals to contain the breach, investigate its scope, and restore affected infrastructure. Preliminary assessments indicated the attack did not cause substantial damage, though full system functionality had not yet been restored at the time of reporting. Rekah emphasized ongoing efforts to minimize operational disruptions and financial impacts while prioritizing system recovery.

The cyber attack exclusively disrupted Rekah's distribution network, leaving production systems for medicines, cosmetics, vitamins, and nutritional supplements unaffected. Algrably noted pharmacies and hospitals—the company's primary customers—typically maintain several days of inventory, reducing immediate risks of product shortages despite distribution halts. The company evaluated manual order fulfillment processes as a contingency if system restoration required extended time, though such measures would necessitate direct coordination with critical clients like hospitals. Rekah, valued at approximately $37 million and controlled by Fimi Fund since 2015, assured stakeholders through stock exchange filings that all necessary resources were allocated to resume normal operations. No threat actor attribution, data compromise details, or specific recovery timelines were disclosed during the initial response phase.

Sources

Sources available to members: 1 source.

CSIDB