Pharmaceutical distribution has become an attractive target for ransomware operators, who view logistics partners as softer entry points than hospitals and manufacturers. The Spacebears crew says it broke into the systems of a Swiss pharmaceutical wholesaler, an incident tracked by the DeXpose and ransomware.live services.
The company in question, Elixi International SA, is based in Chiasso and ships medicines to markets around the world. The claim, reported August 10, says the group compromised sensitive data and is threatening to release it unless negotiations begin. The threat actor statement lists SQL databases, personal information of employees and clients, and financial documents as the material in its hands.
Elixi has not publicly confirmed the incident, and the claim remains unverified. Distributors occupy a sensitive spot in the pharmaceutical supply chain: they sit between manufacturers and pharmacies, meaning a compromise can ripple into downstream operations even when clinical infrastructure is untouched.
For pharmaceutical and life sciences organizations, the incident is a reminder that extortion gangs are targeting logistics and distribution partners, not just manufacturers and hospitals. Third-party risk programs should cover distributors and wholesalers, including contractual breach notification commitments and evidence of segmentation between corporate systems and order processing. Companies that find themselves on a leak site should resist negotiating with the group before engaging incident response and legal counsel, and should validate backups while monitoring for data resale on underground forums.
