AbelZeta Listed by spacebears Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
AbelZeta was listed by the spacebears ransomware group on March 12, 2026, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone connected to the company should check for signs of compromise and take appropriate protective steps.
Inside the incident
The available information states that spacebears listed AbelZeta and asserted that internal files had been taken during a ransomware operation. No confirmed date of the intrusion, exact volume of data accessed, or method of entry has been made public beyond the group’s listing. The number of individuals whose information may be involved remains unknown.
Inside spacebears
Spacebears is a ransomware group that conducts operations involving system encryption and data exfiltration, followed by listings on a dedicated leak site. Such groups typically use the public posting of victim names to apply pressure during ransom negotiations. The listing of AbelZeta constitutes the group’s claim; independent confirmation of the intrusion details has not been reported.
Who is AbelZeta?
AbelZeta is a biotechnology company focused on the discovery, development, and manufacturing of cell therapies for hematologic malignancies, inflammatory and immunological diseases, and solid tumors. It maintains partnerships with established pharmaceutical firms including AstraZeneca, Janssen, and Novartis, and has received investment from multiple venture and institutional sources. Organizations in this sector routinely generate and store large volumes of proprietary research records.
The information in question
The facts provided indicate that internal files were exfiltrated. The group claims the material includes more than 170,000 files organized in over 670 archives and references studies such as CAR032, CAR39, CAR66, CAR168, TIL, CD, and T-cell programs. The precise contents, sensitivity levels, and whether any personal data of patients or employees are present have not been independently verified or disclosed by the company.
What's at stake
For individuals, the primary concern is the potential exposure of any personal or medical information that may have been stored among the research files, though the presence of such data has not been confirmed. For the organization, the loss of control over proprietary study records could affect ongoing research programs, regulatory filings, and collaborative agreements. The long-term consequences depend on the actual data involved and any subsequent use of the material.
What to do if you're exposed
Individuals who believe their information may be involved should monitor their financial and medical accounts for unusual activity and consider placing fraud alerts with credit reporting agencies. Changing passwords for any associated online accounts and enabling multi-factor authentication are standard initial steps. Readers can also run a free exposure scan of their email address against known breach data to check for prior appearances in public breach records.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
SmilePoint Dental Group Listed by spacebears Ransomware GroupJohnson & Johnson Innovative Medicine Listed by spacebears Ransomware GroupElixi International SA Listed by spacebears Ransomware GroupSpaceBears Ransomware Hits Italian Manufacturer BiesSseLatest breaches
Read GalaxyWarden’s full analysis of the AbelZeta Listed by spacebears Ransomware Group →
Publicly posted by spacebears — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.