Roughly 940 MB of internal network-security material sits at the center of an extortion claim against AstraZeneca’s Turkish pharmaceutical business. The group calling itself N0n says the haul covers firewall rules, device definitions and remote-access mappings for all three of the company’s sites in the country, and that those sites are enforcing a total network blackout until a settlement lands.
Alongside that material, the crew says it swept up about 1.35 million connection records touching Microsoft 365 and Intune, SAP Concur, a UniFi camera estate and internal applications. It describes the target as GxP pharmaceutical manufacturing and posted a September 21 deadline. Threat trackers logged the claim on September 18, 2026.
AstraZeneca has not confirmed the intrusion, and tracker claims of this kind often prove overstated. What makes the case notable for care providers is the target profile. Pharmaceutical manufacturing sits upstream of the drug supply that hospitals, clinics and specialty pharmacies depend on, and manufacturing floor systems are rarely built with the network segmentation that office IT gets.
For healthcare security teams, the pattern repeats a familiar lesson: third-party manufacturing and distribution partners hold network diagrams, access maps and identity records that are worth as much to an extortion crew as patient data.