
Drug Research Firm Inotiv Reports Ransomware Attack to SEC
Indiana-based drug research firm Inotiv reported a ransomware attack to the SEC on August 19, 2025.
Key points
- Inotiv reported a ransomware attack to the SEC on August 19, 2025.
- Qilin ransomware group claimed responsibility.
- Encrypted critical systems and disrupted internal networks.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Aug 19, 2025
- Updated
- Jun 26, 2026
- Confidence
- Medium
- Evidence
- 2 sources
Structured assessment
Signal analysis
It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch ransomware, endpoint compromise and business interruption exposure.
Business impact
- Impact area
- Availability
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?+
Indiana-based drug research firm Inotiv reported a ransomware attack to the SEC on August 19, 2025. The Qilin ransomware group was responsible, encrypting critical systems, disrupting internal networks, and allegedly exfiltrating 176 GB of research data spanning the previous decade.
When was this signal reported?+
Shadow Tier lists Aug 19, 2025 as the signal date.
Which organization is connected to this signal?+
Inotiv is the organization connected to this public signal.
Explore InotivWhich attack pattern is relevant?+
This signal is connected to current ransomware incidents based on its reported incident context.
Explore current ransomware incidentsRelated signals
Compare shared topics, actors and incident patterns before opening the full signal.
Accenture Confirms Security Incident After 35GB Data Theft Claim
Accenture, a global professional services company, confirmed a security incident in July 2026 after a threat actor, identified as "888," claimed to have stolen approximately 35 GB of data from the company. The stolen data reportedly includes source code, RSA keys, SSH keys, Azure personal access tokens (PATs), Azure Storage access keys, and configuration files. The threat actor advertised the data for sale on a cybercrime forum and provided a screenshot as proof of exfiltration from a private Azure DevOps repository associated with accenture.com. Accenture stated that it is aware of the "isolated matter" and has remediated its source, asserting that there was no impact on Accenture's operations and service delivery. This incident follows previous security challenges for Accenture, including a 2017 exposure of sensitive data on unsecured AWS S3 buckets and a LockBit ransomware attack in 2021.
Related context
Tata Electronics Data Leak Exposes Apple iPhone 18 Pro Details
India probes Tata Electronics breach exposing iPhone secrets India is investigating a data breach at Tata Electronics that reportedly exposed confidential information linked to Apple’s unreleased iPhone 18 Pro, the country’s IT secretary said on Thursday (July 3), marking the government’s first public response to the incident. Sensitive documents, including component lists, supplier details and images of the iPhone 18 Pro, were allegedly posted on the dark web by a ransomware group that targeted Tata Electronics, an Apple supplier in India, Reuters reported. “We are investigating,” said S. Krishnan, secretary at the Ministry of Electronics and Information Technology, adding that the case has been referred to India’s Computer Emergency Response Team, the national cybersecurity agency. The breach raises concerns over Apple’s tightly controlled global supply chain, where production of iPhones relies on multiple international suppliers. Apple is expected to launch the iPhone 18 Pro and Pro Max in September. The leaked files are said to include at least six documents revealing supplier assignments for specific components—information Apple does not publicly disclose. Tata Electronics has reportedly hired a global consultancy firm to carry out a forensic audit following the leak, which also allegedly involved documents related to Tesla, Qualcomm and TSMC being published on the dark web, according to Reuters. (Newswire)
Related context
Singapore Land Authority Data Breach Exposes 70,000 Records via IBM Testing Environment
Singapore Land Authority data breach exposes 70,000 records after IBM testing environment compromised SINGAPORE, July 3 — Personal data belonging to about 70,000 individuals has been compromised in a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by IBM. SLA said the breach stemmed from unauthorised access to a dataset created for vendor development and systems integration testing, CNA reported. IBM oversees the testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), which are used to submit property transfer and caveat documents. Preliminary checks showed the dataset, first created in 1998 and updated periodically, was intended to contain only mock and anonymised records. It was later discovered to include real information such as names, NRIC numbers and past property addresses of around 70,000 people. SLA stressed that the affected environment is separate from its live operational systems, adding that property ownership and lodgment records in STARS and ELS remain secure. IBM has revoked access to the compromised system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on assistance measures. The authority said it is working with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident and implement remedial steps. According to CNA, a police report has been lodged and the Personal Data Protection Commission has been notified. SLA has not yet disclosed when the breach occurred or how many affected individuals have been contacted. Singapore’s first dedicated hospital for native wildlife opens at Mandai Singapore bookie aged 69 jailed for illegal betting on Hong Kong horse races Fatal dispute between Singapore Redhill flat neighbours leads to murder charge PDRM prepares security operations for Negeri Sembilan state election Defence weighs AGC appeal for driver in fatal Klang crash Amirudin: Pakatan banks on micro-campaign strategy to win over Negeri Sembilan voters ÑеÑгей ÑаÑанÑÑа - stock.adobe.com The Singapore Land Authority (SLA) has revealed that the personal information of about 70,000 individuals was exposed following unauthorised access to a cloud environment managed by IBM, its technology supplier. IBM was appointed to support and maintain SLA’s Singapore Titles Automated Registration System (Stars) and eLodgment System (ELS), which underpin property title registration and the lodgement of property documents in the city-state. As part of that work, the supplier managed the development and systems integration testing environment for the two systems. In a statement on 3 July 2026, SLA said it had been informed by IBM of the incident, with preliminary investigations indicating that a dataset created solely for development and testing purposes had been accessed without authorisation. The dataset, created in 1998 and updated periodically over the years, was meant to contain only mock and anonymised testing data based on property ownership and lodgement records. However, SLA said it has since uncovered that the dataset also contained the names, National Registration Identity Card (NRIC) numbers and property addresses of the affected individuals at the time. “This information should have been anonymised but was not,” the agency said, adding that investigations are ongoing to determine how this occurred. SLA noted that the affected environment is “distinct and separate” from its operational systems, with no connection to, or compromise of, the live systems that run Stars, ELS or any other SLA systems. Property ownership and lodgement records remain secure and unaffected, it added. IBM has revoked access associated with the affected environment to prevent further unauthorised access, while SLA has identified the individuals whose information was contained in the dataset, and has begun notifying them and advising them on how to seek further information and assistance. Singapore mobilised over 100 cyber defenders to neutralise a sophisticated APT actor which infiltrated Singtel, StarHub, M1 and Simba networks in the country’s largest coordinated cyber incident response to date . Japan’s Nikkei has confirmed a major data breach that potentially exposed the personal information of more than 17,000 employees and business partners after hackers infiltrated its internal Slack messaging platform. Australian privacy commissioner warns that the human factor is a growing threat as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high. Philippine bank BDO is shoring up its cyber security capabilities to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago. The agency is working with IBM, the Government Technology Agency and the Cyber Security Agency of Singapore (CSA) to establish the full facts and ensure remedial measures are taken. It has also lodged a police report and notified the Personal Data Protection Commission, and urged the public to remain vigilant against phishing emails, websites, text messages and phone calls from parties claiming to represent government agencies or other organisations. “We apologise for the concern and inconvenience this incident may cause,” the SLA said. The incident underscores the long-standing risk of real personal data finding its way into development and test environments , which are typically less closely guarded than production systems – a risk that is compounded when those environments are operated by third parties. It is also the latest in a series of supply chain security incidents in Singapore in recent years. In April 2025, Toppan Next Tech, a printing supplier for DBS Bank and the Singapore branch of Bank of China, was hit by a ransomware attack that saw customer data stolen by the threat actor . Some 8,200 DBS customers – mostly holders of DBS Vickers trading accounts and Cashline loans – and around 3,000 Bank of China customers were potentially affected. A year earlier, in August 2024, a hacker who gained unauthorised access to Mobile Guardian , a mobile device management platform then deployed across Singapore’s schools, remotely wiped the iPads and Chromebooks of about 13,000 students from 26 secondary schools. The Ministry of Education subsequently removed the software from all student devices and terminated its contract with the supplier.
Related context
FortiBleed gekoppeld aan ransomwaregroepen INC en Lynx
The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.
Related context
DyStar Group Hit by Settra Ransomware Attack, 1.3 TB of Internal Data Exfiltrated
Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks This page displays the 100 most recent victim disclosures attributed to ransomware groups, as detected by Ransomware.live . Our platform continuously monitors and scrapes ransomware group leak sites to identify and list newly published victims. Recent Breaches › dystar.com Listed by settra Ransomware Group dystar.com Listed by settra Ransomware Group: What Was Exposed & What To Do Occurred June 2026 · publicly disclosed June 28, 2026. Dystar.com was listed by the Settra ransomware group on June 28, 2026, with internal files reported exfiltrated in the attack. An undisclosed number of people may be affected; check the listing and monitor your accounts for signs of compromise. The incident was reported on 28 June 2026. dystar.com appears on a listing attributed to the settra ransomware group. The group claims to hold 1.3 terabytes of data described as the complete digital archive of DyStar. No independent confirmation of the volume, the date of access, or the method of entry has been released. The number of people affected remains undisclosed. Settra is a ransomware operator that lists victim organisations on a public site after encrypting systems and copying files. The group’s listings function as a claim that data has been taken and may be released if demands are not met. No additional statements from settra specific to dystar.com have been verified beyond the listing itself. dystar.com belongs to an organisation that operates in the specialty chemicals sector, supplying dyes and related products to industrial clients. Entities of this type routinely maintain records on production processes, customer accounts, supplier arrangements and internal communications. A breach that exposes such material can affect both commercial operations and any personal details contained in those records. The only category named in available reports is internal files exfiltrated during a ransomware attack. The precise contents of the 1.3 terabytes referenced in the listing have not been itemised by the organisation or independently verified. Organisations in this sector commonly store employee records, contractual documents and operational data, yet the exact composition of the material in this case stays unconfirmed. Internal files can contain identifying information, financial references or communications that retain value long after the initial incident. Individuals named in those files may encounter follow-on risks such as targeted fraud or unwanted contact. For the organisation, the exposure of proprietary material can complicate business relationships and regulatory compliance even if the number of personal records remains unknown. Begin by monitoring accounts linked to any email address you have used with dystar.com or its partners. Enable multi-factor authentication on those accounts and review recent login activity. Request a copy of any personal data the organisation holds about you under applicable data-protection rules. Readers can run a free exposure scan of their email address against known breach data to check for appearances in public listings. Change passwords for any accounts that may share credentials with dystar.com systems. Watch bank and credit statements for unusual activity over the next several months. Contact dystar.com directly to ask what categories of personal information were held and whether they have been notified of the listing. Read GalaxyWarden’s full analysis of the dystar.com Listed by settra Ransomware Group → Publicly posted by settra — unverified claim, pending independent verification Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated a
Related context
eogb.co.uk Hit by Stormous Ransomware Group
eogb.co.uk, a UK-based organization, was claimed as a victim by the Stormous ransomware group. The incident was discovered on June 28, 2026, at 21:29 UTC, with deep access to Microsoft Dynamics GP, internal legal documents, partnership agreements, customer contracts, operational spreadsheets, financial reports, and executive documents.
Related context