ransomware Credible South Africa (ZA) pharma

Cipla South Africa listed by the Akira ransomware group

Cipla South Africa

📅 09 December 2024
CompanyCipla South Africa
Domaincipla.com
CountrySouth Africa (ZA)
Sectorpharma
Breach date2024-12-09
People affectedNot disclosed
Ransomware groupakira
Data typescorporate records, product data, employee information

Overview

The Akira ransomware group has listed Cipla, the global pharmaceutical company with operations in South Africa, on its leak site. The company focuses on complex generics across its markets. The listing appeared on 9 December 2024.

What was published

The group has listed the company as a victim but has not published detailed data descriptions at this stage. The archive is expected to include corporate records, product data and employee information.

Risks for affected individuals

  • Employees' personal records may be exposed.
  • Product and formulation data could be of commercial value.
  • Corporate information may be misused.

What remains unknown

  • Whether data has been exfiltrated.
  • The volume of records involved.
  • The timeline of any release.

What affected people should do

Employees should update credentials and watch for phishing referencing the company. Cipla South Africa should notify staff and partners, review compromised systems, and coordinate with South African authorities on the response.