Quick Summary
AllegedExecutive Summary
CorePharma, a US-based healthcare company, has been listed as a victim by the Chaos ransomware group on July 8, 2026. SOCRadar’s Dark Web Monitoring service detected this listing. While Chaos has primarily targeted business services, manufacturing, and technology sectors, CorePharma’s inclusion diversifies their victimology. The group has predominantly targeted organizations in the United States, Germany, and Canada.
Technical Analysis
The listing for CorePharma was found on a third-party business directory page, not directly on CorePharma’s corporate domain. This indicates that the analyzed data pertains to credentials associated with zoominfo[.]com, which is not owned by CorePharma. The query returned 25 records, all of which were external consumer, academic, or third-party accounts on ZoomInfo’s platforms, with no employee credentials linked to CorePharma’s domain. This suggests a risk of customer account takeovers on ZoomInfo rather than a direct intrusion into CorePharma’s infrastructure. The data logs were mostly from July 7-8, 2026, with some dating back to early 2024. This evidence does not confirm whether infostealer-harvested credentials were used as an initial access vector for CorePharma, as the queried domain was not the victim’s own. Further investigation of CorePharma’s actual domains and continued monitoring are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.