Hangzhou Qihan Biotech Data Breach

Alleged

Ransomware claim involving Hangzhou Qihan Biotech

Published: Aug 30, 2026 global
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Hangzhou Qihan Biotech
Industry
Healthcare
Threat Actor
global
Date of Incident
Aug 30, 2026

Executive Summary

A global ransomware group has claimed Hangzhou Qihan Biotech, a Chinese healthcare organization, as a victim. The claim was made on August 30, 2026, and appeared on the group’s leak site, alleging unauthorized access to the company’s systems and data. As of the report’s publication, no independent verification of the breach details has been completed. Hangzhou Qihan Biotech, operating under the domain qihanbiotech[.]com, is in the healthcare sector, an industry frequently targeted by ransomware actors. The ransomware group, referred to as “global,” has claimed four victims in the past 60 days. Their primary targeting concentration is in China (CN) and Singapore (SG), with a focus on the Technology and Healthcare industries. Hangzhou Qihan Biotech’s profile as a Chinese healthcare organization aligns with this established targeting pattern. global is characterized as a small-footprint ransomware actor with a relatively limited victim set.

Technical Analysis

SOCRadar CTI’s analysis of stealer-log data returned a “no_exposure_in_sample” verdict for Hangzhou Qihan Biotech. Specifically, no credential records linked to the domain qihanbiotech[.]com were identified within the current infostealer datasets that were queried. It is crucial to note that this null result does not definitively clear the organization of a compromise. Phishing attacks or the exploitation of public-facing services remain plausible initial-access vectors that may not be reflected in current stealer-log data. Continued dark web monitoring and proactive credential hygiene checks are recommended to further assess the security posture.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.