AMHWA Biopharm Co., Ltd. Data Breach

Alleged

Ransomware claim involving AMHWA Biopharm Co., Ltd.

Published: Jul 9, 2026 CRPxO
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
AMHWA Biopharm Co., Ltd.
Industry
Biopharmaceuticals
Threat Actor
CRPxO
Date of Incident
Jul 9, 2026

Executive Summary

AMHWA Biopharm Co., Ltd., a biopharmaceutical company based in China, has been listed as a victim on the dark web portal of the CRPxO ransomware group. The listing, published on July 9, 2026, was identified by SOCRadar’s Dark Web Monitoring service. This case is notable as AMHWA is a larger healthcare enterprise and CRPxO’s only non-US victim in a recent string of attacks that predominantly targeted small US dental practices. CP melakukannya’s recent activity has heavily focused on the US healthcare sector, specifically dental clinics, making AMHWA Biopharm a divergence in terms of both its location and its scale within the industry.

Technical Analysis

SOCRadar’s initial analysis did not find AMHWA Biopharm’s corporate domain, amhwabio.com, in its queried stealer-log telemetry, suggesting no direct evidence of compromised credentials from that specific source. However, this absence of evidence is not conclusive proof of security, as credentials could have been exposed through alternate domains, personal email aliases on work devices, or logs that were not yet indexed. Given the uneven coverage of China-based corporate domains in Western stealer-log feeds, continued monitoring and proactive credential hygiene are recommended. CP melakukannya is known to use credentials harvested by infostealers as an initial access vector. Attackers acquire these credentials from underground marketplaces, validate them, and use them to access corporate systems via platforms like Microsoft 365 or VPNs before deploying ransomware. The null result from the stealer-log query does not negate this possibility, as credentials could have been used and rotated before indexing, or harvested through other means not covered by the analyzed dataset.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.