French pharmaceutical giant Pierre Fabre suffers a REvil ransomware attack

French pharmaceutical giant Pierre Fabre suffers a REvil ransomware attack

French pharmaceutical and cosmetics company Pierre Fabre has been hit with a REvil ransomware attack, with hackers demanding $25 million ransom from the manufacturer.

Last week, Pierre Fabre revealed it was the target of a cyberattack that the company brought under control in less than 24 hours. The incident took place on March 31. After learning about the cyberattack the company immediately put its IT system put into standby mode to prevent the infection from spreading. This led to the “temporary stoppage of most production activities (except for the production facility in Gaillac (in the Tarn in France), which manufactures active ingredients for pharmaceuticals and cosmetic products).”

In its announcement the company did not mention what kind of malware was used in the attack, however, according to Bleeping Computer, Pierre Fabre appears to be the victim of the REvil (Sodinokibi) ransomware operation.

According to the REvil’s Tor payment page, the group initially demanded $25 million ransom from the company, though the ransom had since been doubled to $50 million as Pierre Fabre had not contacted the attackers and the time limit expired.

The payment page does not indicate who the victim is, however, it contains a link to a currently hidden REvil data leak page for Pierre Fabre, which contains images of allegedly stolen passports, a company contact list, government identification cards, and immigration documents, according to Bleeping Computer.

In January 2021, massive pan-Asian retail chain operator Dairy Farm Group that operates numerous brands in the Asia market, was reportedly hit by the REvil ransomware operation, with attackers demanding $30 in ransom. Most recently, the gang attacked the world-leading French electronics manufacturing services (EMS) company Asteelflash. The company managed to contain the attack and said it has no evidence any data was stolen.

Back to the list

Latest Posts

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

LOSTKEYS is designed to steal sensitive files, harvest system information, and exfiltrate details about running processes.
8 May 2025
Russia-aligned operation manipulates audio and images to impersonate experts

Russia-aligned operation manipulates audio and images to impersonate experts

The operation primarily focused on undermining NATO support for Ukraine and spreading false narratives to disrupt domestic politics in EU member states.
7 May 2025
Global network of DDoS-for-hire services dismantled in international police op

Global network of DDoS-for-hire services dismantled in international police op

The suspects are believed to have administered six now-defunct websites, which operated as stresser or booter services.
7 May 2025