Critical Unverified

Pharma5 Ransomware Claim by INC Ransom (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming pharma5.ma data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming pharma5.ma data breach - full size

Claim Summary

On or around September 25, 2026, the ransomware group tracked as “incransom” allegedly listed pharma5.ma, a Morocco-based healthcare and pharmaceutical organization, on its dark web leak site. According to the threat actor’s own claim, the group exfiltrated approximately 50GB of data and is threatening to publish it unless a demand is met.

The listing purportedly includes the organization’s physical address in Casablanca’s Maârif Extension district, a contact phone number, and a broad description of the stolen material. As with all leak site posts, this claim is unverified and should be treated as an assertion by the attacker, not as confirmed fact. Ransomware operators frequently inflate data volumes and the sensitivity of stolen material to increase pressure on victims.

Threat Actor Profile

The group behind this claim is incransom, a ransomware operation that has been active in the broader RaaS (ransomware-as-a-service) ecosystem. Public research on this specific group remains limited. Yazoul Security has no confirmed tooling inventory for incransom at this time, and the group’s total known victim count is not established in open sources.

Because tooling and TTP documentation is sparse, defenders should not assume a fixed playbook. INC-style operations have historically favored double extortion - encryption combined with data theft - and have been observed targeting a wide range of sectors, including healthcare, manufacturing, and professional services. The absence of public research does not mean the group is inactive; it often means victims are paying quietly or reporting is delayed.

Where detection guidance exists, we recommend focusing on:

  • Unusual outbound data transfers to cloud storage or file-sharing services
  • Mass file access and staging behavior (e.g., large archive creation)
  • Credential dumping and lateral movement tooling
  • Shadow copy deletion and backup tampering

No specific YARA rules are publicly attributed to this group at the time of writing. Generic ransomware behavior rules and Sigma detections for exfiltration staging remain the most practical coverage.

Alleged Data Exposure

According to the threat actor, the leaked dataset totals roughly 50GB and purportedly includes:

  • Corporate and financial information
  • Product and supply chain data
  • Quality control and certification records
  • Drug testing and related documentation
  • Employee personal data
  • Counterparty and partner information

If accurate, this would represent a significant exposure spanning operational, financial, and personal data categories. However, none of this has been independently verified. Yazoul Security has not reviewed the data, cannot confirm its existence, and will not link to or reproduce any leaked material. The claim of “employee personal data” is particularly sensitive and, if genuine, could carry regulatory implications under Moroccan law and, depending on business relationships, GDPR.

Potential Impact

For a healthcare and pharmaceutical organization, the alleged exposure of drug testing, quality control, and certification data could affect regulatory standing, partner trust, and supply chain continuity. Financial and counterparty data could enable fraud or competitive harm. Employee personal data exposure could trigger notification obligations and regulatory scrutiny.

That said, the practical impact depends entirely on whether the data is real, current, and as sensitive as claimed. Many leak site posts overstate both volume and content.

What to Watch For

  • Publication of samples or full archives on the leak site
  • Follow-on extortion or direct outreach to employees, partners, or regulators
  • Regulatory notifications from Moroccan authorities or EU counterparts
  • Reuse of leaked data in phishing or business email compromise campaigns
  • Any official statement from Pharma5 confirming or denying the claim

Organizations in the pharmaceutical and healthcare supply chain should review third-party risk exposure and monitor for credential reuse.

Disclaimer

This report is based solely on an unverified claim published by a ransomware group. Yazoul Security has NOT independently confirmed the breach, the data volume, the data categories, or the involvement of incransom. Ransomware groups routinely exaggerate claims to pressure victims into paying. Nothing here should be treated as fact. No leaked data, credentials, samples, or access instructions are included, and none will be provided. Readers should await official confirmation from Pharma5 or relevant authorities before drawing conclusions.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.