10x Genomics Listed by revil Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The 10x Genomics Listed by revil Ransomware Group (reported March 13, 2020) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
Public records show only that 10x Genomics appeared on the revil leak site on the reported date. The group asserted that internal files had been removed during a ransomware operation, but no further technical details, timelines, or evidence of the intrusion have been disclosed by either the company or investigators.
Neither the volume of data nor the number of people potentially referenced in the files has been stated. Subsequent confirmation or denial of the claims by 10x Genomics has not appeared in available reporting.
Who is revil?
Revill, also tracked publicly as REvil or Sodinokibi, operated a ransomware-as-a-service model in which affiliate groups deployed the malware and the core operators managed leak infrastructure. The group routinely used a double-extortion approach: encrypting systems and then threatening to publish stolen files if a ransom was not paid.
Its leak sites functioned as a public catalogue of claimed victims. Listings were presented by the operators as proof of access, though independent verification of the data’s authenticity or the circumstances of its acquisition was not provided by the group.
Who is 10x Genomics?
10x Genomics develops instruments and consumables used in single-cell and spatial genomics research. Its customers include academic laboratories, biotechnology firms, and pharmaceutical companies that generate large volumes of sequencing data tied to biological samples.
Organisations in this sector routinely process genomic sequences, experimental metadata, and associated research records. A breach that exposes such material can affect both the scientific integrity of ongoing projects and the privacy expectations of individuals whose samples contributed to the datasets.
What was likely exposed
The only data category named in connection with the listing is “internal files exfiltrated in ransomware attack.” No inventory of file types, no indication of whether personal identifiers were present, and no confirmation of the files’ scope have been released.
Companies of this kind commonly store proprietary research protocols, instrument logs, and genomic datasets. Without an official disclosure, it is not possible to determine whether any of these categories were among the material referenced by the listing.
What's at stake
Genomic information is difficult to change and can reveal sensitive details about individuals and their relatives. If such data were included in the exfiltrated files, affected people could face long-term privacy consequences even if the immediate operational impact on the company remains unclear.
For the organisation, the incident adds to the body of public claims about its security posture. Any subsequent regulatory or contractual reviews would depend on facts that have not yet been published.
Were you affected?
Because the number of individuals referenced in the files is unknown, anyone who has provided samples to research projects involving 10x Genomics technology should treat the possibility as open. The first practical step is to monitor official statements from the company and any notices issued through research institutions or biobanks.
Readers can also run a free exposure scan of their email address against known breach datasets to check whether their information has appeared in other publicly reported incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Managed[.]com (Web Hosting Provider for Columbus County, NC, Griffin Hospital in CT, Arizona Judicial Branch, and Jackson County, OR, among others) Listed by revil Ransomware GroupStandley Systems (vendor to Healthcare Sector) Listed by revil Ransomware GroupActuaries and Associates (retirement specialist) Listed by revil Ransomware GroupCrozer-Keystone Health System (Delaware County, PA) Listed by revil Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the 10x Genomics Listed by revil Ransomware Group →
Publicly posted by revil — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.