Neopharm Labs Inc.
Incident posture
Linked entities
- Victim
- Neopharm Labs Inc.
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Neopharm Labs Inc. disclosed a data breach after a ransomware attack led to the exfiltration and online publication of employee personal data. A subsequent system restoration temporarily allowed internal access to certain human resources files without normal restrictions. Exposed information included names, contact details, employment and payroll data, banking and social insurance numbers, government identifiers, medical and disciplinary records, identity documents and financial account information. The company is offering affected employees a complimentary 24‑month identity protection service and directs questions to its human resources team via email.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 15, 2026, Neopharm Labs Inc. detected unauthorized activity affecting certain parts of its IT infrastructure, which was later confirmed to be a ransomware attack. During the attack, threat actors exfiltrated data and subsequently published it online. The company reported the incident to the Massachusetts Office of Consumer Affairs and Business Regulation on September 30, 2026. After the ransomware event, as systems were restored, a secondary exposure occurred when human resources files were accessible internally without the usual access restrictions from August 1 to August 10, 2026. Neopharm stated that access was restored to normal levels on August 10, 2026, but it could not confirm whether any of those files had been viewed during that window.
The types of personal information that may have been compromised include names, addresses, telephone numbers, email addresses, employment details such as position, hire dates and employment status, compensation and payroll records including T4 slips, banking and direct deposit information, social insurance numbers, social security numbers, other government identifiers, benefits information, medical or leave‑related details, disciplinary or performance‑related data, copies of or information from identity documents, financial account information, driver’s license numbers and credit or debit card numbers. To assist affected individuals, Neopharm is providing a complimentary 24‑month subscription to myTrueIdentity through TransUnion of Canada Inc. Employees can enroll by visiting www.mytrueidentity.ca and using the activation code included in their notification letters, with the code needing to be redeemed by January 31, 2027. For any technical issues during enrollment, individuals may call TransUnion Canada at 1‑888‑228‑4939. Questions about the breach or requests for more specific personal information can be directed to Neopharm’s human resources team via email at [email protected].
Neopharm has noted that additional categories of data, such as dates of birth and further government identifiers, may also have been involved though the full extent of the exposure has not yet been disclosed. The company continues to monitor the situation and has made the aforementioned support services available to all current and former employees whose information was potentially affected.
Sources
Sources available to members: 1 source.