DisclosureLens
GLOBALMalwareHealthcareHealthcareRansomwareInsaneRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh

JspPharma

bd_fe52dc5bd139f07d · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Jan 17, 2024

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for JspPharma

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Insane on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: HealthcareDiscovered: 2024-01-17

Source: Ransomware.live

Post text · scraped from the leak site

A few words about the breached company: JSP Pharmaceutical Manufacturing (Thailand) PCL is engaged in Researching, Developing and producing drugs, dietary supplements, cosmetics, herbs, and dietary supplements in the form of vitamins including healthy coffee Ready.Its segments include Manufacturing and distribution of products under the customer's Brand name and Own Brand name.The majority of the revenue comes from the manufacturing and distribution of products under the customer's brand name.The Group is managed and operates principally in Thailand.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Jan 17, 2024

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2024-01-17

insane

According to ransomware.live, Insane is a short-lived ransomware group that briefly surfaced in early 2024, claiming a single victim in Thailand before going quiet, with minimal documented activity or technical details available.

1 victims claimed globally1 tracked hereFull profile →