GLOBALMalwareHealthcareHealthcareRansomwareLapsus$LapsusRansom DemandedActor NamedMedium
Astrazeneca Corp
bd_99f931040d6c14c0 · schema v1 · pii pii-v1
Full breach record for Astrazeneca Corp →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lapsus$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: HealthcareDiscovered: 2026-04-05
Source: Ransomware.live
Post text · scraped from the leak site
Source Code, Employee DB, API Keys, MongoDB/MySQL Creds
Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident
No regulatory filing corroborates this yet. If an SEC 8-K, state-AG notice, or victim statement lands, DisclosureLens will merge it into an incident and link it here.
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2026
- Raw hash
- 7530981f973ce013322f5276176728abf9bcefefdfcae3e18fe6c499c1b753fe
Reporting entity
- Name
- lapsus$
Victim entity
- Name
- Astrazeneca Corpnorm: astrazeneca
- Domain
- astrazeneca.co.uk
- Industry
- Healthcare
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· lapsus$
- Threat actor
- Lapsus$ExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.