CorePharma Data Breach

Alleged

Ransomware claim involving CorePharma.

Published: Jul 8, 2026 Chaos
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
CorePharma
Industry
Business Services
Threat Actor
Chaos
Date of Incident
Jul 8, 2026

Executive Summary

CorePharma, a healthcare and pharmaceutical company based in the United States, was identified on July 8, 2026, as a victim of the Chaos ransomware group. This listing was discovered via SOCRadar’s Dark Web Monitoring service. While Chaos has predominantly targeted the Business Services, Manufacturing, and Technology sectors, with a focus on victims in the United States, Germany, and Canada, CorePharma’s inclusion marks a diversification for the group into the healthcare sector. Notable recent victims of Chaos with overlapping profiles (US-based organizations) include Opportune LLP, Grand Isle Shipyard Inc., AireSpring, and Challenge Manufacturing.

Technical Analysis

An analysis of SOCRadar’s stealer-log telemetry revealed that the listing for CorePharma was linked to a third-party business directory page on ZoomInfo, rather than a direct corporate domain. A query against zoominfo.com returned 25 records, primarily consisting of external consumer, academic, or third-party accounts, with no employee credentials associated with CorePharma’s domains. This suggests a risk of account takeover on the ZoomInfo platform rather than a confirmed corporate intrusion at CorePharma. The log freshness data clustered around July 7–8, 2026, with some logs dating back to early 2024. This evidence does not provide direct insights into potential credential exposure on CorePharma’s actual corporate infrastructure. Threat intelligence teams are advised to continue monitoring CorePharma’s real domain footprint and conduct credential hygiene checks, as the current data is insufficient to confirm a breach within the company’s internal systems. The typical initial access vector for ransomware groups like Chaos involves the use of credentials harvested from stealer logs, which are then used for unauthorized access to corporate networks. However, the indirect nature of this listing limits its direct applicability to CorePharma’s corporate environment.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.