CSIDB logo
Incident

MSPharma

Incident posture

Attack window
Apr 2021
Location
Jordan
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
MSPharma
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A pharmaceutical company operating as MSPharma in Jordan was targeted in a cyberattack claimed by the Avaddon ransomware group, with threat actors leaking files reportedly belonging to its parent entity, United Pharmaceutical Manufacturing Co. Concurrently, the Sodinokibi (REvil) ransomware group published screenshots of stolen data from a separate attack on Milan-based Mipharm SPA, though both incidents appeared on cybercriminal leak sites around the same period. The compromised data from MSPharma included internal company files, though the full impact remains unconfirmed as the victim did not respond to verification attempts at the time of reporting.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around April 26, 2021, the Sodinokibi (REvil) cybercriminal group claimed responsibility for a cyberattack targeting Milan-based pharmaceutical company Mipharm SPA. The group published screenshots of data allegedly stolen from the company's servers, demonstrating unauthorized access to internal systems. The publication occurred on the threat actors' dedicated leak site, though the exact date of the initial intrusion was not disclosed in available reports. DataBreaches.net documented this incident, noting Mipharm.it as one of two pharmacological research firms featured on cybercriminal platforms during this period. The attack formed part of REvil's broader ransomware operations, which typically involved data exfiltration followed by extortion threats. No specific details regarding the compromised data types, encryption of systems, or ransom demands were confirmed in the source material.

Concurrently, the Avaddon ransomware group claimed an attack on MSPharma.com, a Jordan-based entity identified through online research as United Pharmaceutical Manufacturing Co. (operating as MSPharma). Archived leak files prominently featured United Pharmaceutical Manufacturing Co.'s branding, suggesting the potential exposure of corporate documents or proprietary information. DataBreaches.net attempted to contact MSPharma to verify the breach but received no response by the article's publication date. The scope of impacted systems, operational disruption, or data categories affected in the MSPharma incident remained unconfirmed. Both attacks exemplified the targeting of pharmaceutical sector entities by prominent ransomware groups during this timeframe, though neither company's containment measures, incident response actions, or ultimate resolution were publicly detailed in the source material.

Sources

Sources available to members: 1 source.

CSIDB