ransomware
Credible
South Africa (ZA)
pharma
Cipla South Africa listed by the Akira ransomware group
Cipla South Africa
CompanyCipla South Africa
Domaincipla.com
CountrySouth Africa (ZA)
Sectorpharma
Breach date2024-12-09
People affectedNot disclosed
Ransomware groupakira
Data typescorporate records, product data, employee information
Overview
The Akira ransomware group has listed Cipla, the global pharmaceutical company with operations in South Africa, on its leak site. The company focuses on complex generics across its markets. The listing appeared on 9 December 2024.
What was published
The group has listed the company as a victim but has not published detailed data descriptions at this stage. The archive is expected to include corporate records, product data and employee information.
Risks for affected individuals
- Employees' personal records may be exposed.
- Product and formulation data could be of commercial value.
- Corporate information may be misused.
What remains unknown
- Whether data has been exfiltrated.
- The volume of records involved.
- The timeline of any release.
What affected people should do
Employees should update credentials and watch for phishing referencing the company. Cipla South Africa should notify staff and partners, review compromised systems, and coordinate with South African authorities on the response.