The thegentlemen ransomware group has claimed a breach of Vitex Pharmaceuticals, an Australian contract manufacturer of vitamins and supplements. Trackers logged the leak site listing on August 7, with the intrusion estimated to have started a day earlier.
Vitex was previously targeted by LockBit 5.0 in April 2026, making it a repeat ransomware victim within roughly four months. The earlier claim has not been publicly resolved, and the company has not confirmed either incident. thegentlemen’s post describes stolen confidential files including client data, according to the trackers.
The company manufactures vitamins and supplements for retail and private label brands, placing its systems in the pharma supply chain that feeds pharmacies and health retailers. A breach of that kind can expose formulation details, supplier contracts, and customer order data even when clinical records are not involved.
The repeat targeting underlines how quickly attackers recycle previously compromised organizations. Supplement and pharmaceutical manufacturers should treat any prior compromise as a reason to reauthenticate every system, rotate vendor portal credentials, and monitor for data appearing on leak sites.
