6 June 2022

Industrial Spy claims to have stolen sensitive data from pharmaceutical giant Novartis


Industrial Spy claims to have stolen sensitive data from pharmaceutical giant Novartis

Swiss pharmaceutical company Novartis has confirmed it suffered a cyberattack, but said that no sensitive data has been stolen in the incident.

According to the tech news website BleepingComputer, the Industrial Spy data-extortion gang  began selling data allegedly stolen from Novartis on their extortion marketplace for the price of $500,000 in bitcoins.

First spotted in April 2022, the Industrial Spy marketplace sells stolen data from compromised companies, as well as offering free stolen data to its members. The marketplace offers different tiers of data offerings, with "premium" stolen data packages costing millions of dollars and lower-tier data that can be bought as individual files for as little as $2. More recently, Industrial Spy has launched its own ransomware operation.

Threat actor claims that the data offered for sale is related to RNA and DNA-based drug technology and tests from Novartis and were stolen “directly from the laboratory environment of the manufacturing plant.”

Novartis said in a statement that it is aware of the claims and after a thorough investigation it can confirm that no sensitive data has been compromised.

“We take data privacy and security very seriously and have implemented industry standard measures in response to these kind of threats to ensure the safety of our data,” the company said, without elaborating on when the incident has occurred or how the attackers have gained access to its systems.


Back to the list

Latest Posts

New Cuttlefish malware steals credentials from SOHO routers

New Cuttlefish malware steals credentials from SOHO routers

Cuttlefish implements the functionality that allows it to execute HTTP and DNS hijacking.
1 May 2024
ZLoader malware resurfaces with anti-analysis feature

ZLoader malware resurfaces with anti-analysis feature

The trojan made a comeback around September 2023 after lying dormant for almost two years.
1 May 2024
Large-scale malware campaigns plant malicious content in Docker Hub repos

Large-scale malware campaigns plant malicious content in Docker Hub repos

Nearly 20% of all Docker Hub repositories analyzed hosted malware or malicious content.
1 May 2024