Zydus Pharmaceuticals
bd_3daf3b16ccf7adb2 · schema v1 · pii pii-v1
Full breach record for Zydus Pharmaceuticals →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Data Breach Notification. Zydus Pharmaceuticals: Zydus Pharmaceuticals notified affected individuals that their personal information may have been exposed and offered twelve months of free TransUnion credit monitoring, identity restoration services, and up to $1,000,000 in identity theft insurance. The letter also provided instructions on placing fraud alerts, credit freezes, and obtaining free annual credit reports from the three major bureaus. Additional guidance included contacting law enforcement, the FTC, and state Attorneys General if misuse of personal information is suspected. The cyberattack was claimed by meow on 2024-08-15. Linked ransomware group: meow.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jul 28, 2024
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitemeowbd_f715a8900baa1f742024-08-15 · +18dVerified by operator
Regulatory filings (3) · sorted by filing gap
- Vermont State AGbd_62f37f953213f45d2024-10-29 · +93dCandidate
- New Hampshire State AGbd_b1ad3decdb93ac832024-10-29 · +93dVerified
- Indiana State AGbd_fb38cdeda0996f4d2024-10-29 · +93dVerified
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Jul 28, last Oct 29 (IN) — a 93-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
meow
According to ransomware.live, Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning to a data-extortion-only model — selling stolen data rather than encrypting files — with a heavy focus on US healthcare and medical research organizations.