A ransomware crew calling itself Storm says it broke into PANTHERx Rare, a national specialty pharmacy built around rare-disease and orphan-drug treatment.
The listing appeared on Storm’s dark-web site and was logged by leak-site monitors on September 15, with the intrusion estimated a day earlier. DeXpose reported the claim the same day, and a class-action firm, Bryson Harris Suciu & DeMay, opened an investigation into the possible exposure. Storm published no data samples and no victim count, and PANTHERx has not confirmed a breach.
Specialty pharmacies sit in an unusual spot in the care chain. They hold prescription and diagnosis detail, insurance and payment records, and the manufacturer programs that fund expensive therapies. For rare-disease patients, a diagnosis itself can be identifying, and the pool of people taking a given orphan drug is small enough that a leaked list can point at individuals.
Storm has spent the week posting healthcare and financial victims, including an Ohio tire chain and a credit union, a spread that suggests broad access rather than careful targeting. A listing is a threat, not proof of data theft.
Providers that buy specialty pharmacy services should confirm whether their vendor contracts require breach notification timelines and whether the pharmacy reports into their own incident-response plan.