The Global ransomware group has listed Hangzhou Qihan Biotech on its leak site, claiming to have taken data from the company on August 12 and posting the listing sixteen days later. Trackers logged the claim on August 28, and the company has not publicly confirmed any intrusion.
Qihan Biotech is a Hangzhou-based company working on gene editing and cell and organ therapies, including immune-privileged cells and xenogeneic organs intended to treat cancer and organ failure. The sector tags on the listing mark it as healthcare, and threat trackers flag the claim as unverified with no disclosed volume of data.
Hudson Rock data tied to the company’s domain shows a small external footprint, with one employee credential appearing in infostealer logs and 22 exposed services, suggesting the firm is a modest target rather than a large enterprise.
For biotech and pharma companies, the listing is a reminder that research-stage firms hold commercially sensitive data that extortion groups increasingly view as leverage, even when the organization itself is small. Unverified claims still warrant a response plan, including reviewing cloud access, segmenting research systems, and preparing notification procedures in case files actually surface. The Global group, which uses a leak-site playbook similar to larger gangs, has posted a mix of industrial and healthcare targets this month.