Metaencryptor gang lists German drug importer MPA Pharma on leak site

Metaencryptor listed German pharmaceutical importer MPA Pharma GmbH on its leak site in a fresh drug supply chain claim.

MedRisk Staff
By
2 Min Read

The Metaencryptor ransomware gang has listed German pharmaceutical importer MPA Pharma GmbH on its leak site, adding a drug supply chain company to its string of August victims.

MPA Pharma, based in Germany, imports and trades patented and generic pharmaceuticals, provides contract manufacturing for third parties, and supplies pharmacies and medical businesses. The company has operated for more than 35 years, and the tracker profile tied to the listing carries a revenue figure of $614M.

Ransomware.live shows the listing was posted August 23, with an estimated intrusion date the same day. GalaxyWarden’s breach index independently logged the entry with a high severity rating on the same day.

The claim is unconfirmed, and MPA Pharma has not publicly commented. A compromise at a pharmaceutical importer is significant beyond the data itself: these firms sit between manufacturers and pharmacies, so an extended outage could delay medication deliveries, and stolen procurement records can expose pricing and supplier relationships.

Pharma and distribution companies should treat extortion claims as a trigger for supply chain review, not just IT forensics. Verifying that ERP and order systems remain under attacker control, testing backup restoration for logistics platforms, and notifying trading partners early are the immediate priorities.

Researchers flag the listing as an unconfirmed claim, standard practice for tracker sites that index leak posts without verifying the underlying data.

Share This Article