Custom Rx Shoppe Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Custom Rx Shoppe was listed by The Gentlemen ransomware group on September 29, 2026; the group claims to have obtained data on an undisclosed number of individuals. Anyone who may have received services from the pharmacy should review their accounts and monitor for suspicious activity.
Ransomware groups continue to pressure organisations by posting names on leak sites before any independent verification occurs. In that climate, a listing is a public claim, not a claimed breach record, and readers should treat it accordingly.
On September 29, 2026, the group known as The Gentlemen listed Custom Rx Shoppe on its leak site. Public detail is limited: the number of people who might be affected is unknown, and the listing does not disclose what data types, if any, were taken. Custom Rx Shoppe has not publicly confirmed the claim as of writing. What follows separates the group’s claim from established background on the actor and the pharmacy sector, and explains conditional steps people can take if their information were later shown to be involved.
What the listing says
According to the leak-site listing attributed to The Gentlemen, Custom Rx Shoppe appears among organisations the group names in connection with its activity. The reported headline frames the matter as Custom Rx Shoppe listed by The Gentlemen ransomware group. Beyond that naming and the report date of September 29, 2026, the available summary does not state a method of intrusion, a ransom demand, a file count, a volume of data, or a timeline of alleged access.
People affected are recorded as unknown. Data types named as exposed are not disclosed. References associated with the organisation in the material include customrxshoppe.com and a ZoomInfo-style company profile entry for Custom Rx Shoppe pharmacy, along with identifying detail that the business is The Custom Prescription Shoppe, LLC. None of those references, by themselves, prove that systems were compromised or that any particular records left the organisation. The listing is a claim by the group; independent confirmation from the company, a regulator, or a recognised breach index is not part of the facts provided here.
Inside The Gentlemen
The Gentlemen is known in public reporting as a ransomware and extortion-style actor that, like many peers, seeks leverage by encrypting systems or by threatening to publish material it says it obtained. Groups in this category often maintain dedicated leak sites where they post victim names, countdown-style pressure, and sometimes sample files as marketing for their claims. Typical tactics described across the industry include initial access through common weak points such as exposed remote services, stolen credentials, or phishing, followed by attempts at lateral movement and data staging before encryption or pure extortion. Those patterns are general to the ransomware ecosystem and are not a verified playbook for this specific listing.
Public coverage of The Gentlemen has treated it as one of several crews that use naming-and-shaming on leak portals to force negotiation. That reputation does not automatically validate any single post. Leak-site entries can be exaggerated, recycled from older incidents, mistargeted, or false. For Custom Rx Shoppe, the only incident-specific assertion in the facts is that the group has listed the organisation; the group claims association with the name, and nothing in the provided record confirms theft, encryption, or publication of the pharmacy’s files.
Custom Rx Shoppe and its sector
Custom Rx Shoppe, also identified as The Custom Prescription Shoppe, LLC, is described in the available material as a family-owned independent pharmacy founded in 2003 in the Bellingham and Ferndale area of Washington by pharmacist Kevin Faris with partners Jay Solomon and Rick Adelstein. It combines retail pharmacy services, long-term care pharmacy support for nursing homes and assisted-living facilities—including blister packaging, medication administration record (MAR) related work, and medication reviews—and a compounding lab that prepares custom medications for people and pets, including hormone replacement therapy. The company is associated with serving communities in Whatcom and surrounding areas, though the provided text cuts off mid-phrase on geographic scope.
Independent and specialty pharmacies sit at a sensitive intersection of healthcare delivery and regulated personal information. Even without any confirmed incident, the sector’s ordinary work involves prescriptions, patient contact details, insurance or billing identifiers, prescriber information, and—for long-term care and compounding—care-facility workflows and highly individualised formulations. A credible compromise in this sector would matter because health-related data can support fraud, targeted social engineering, or long-lived privacy harm. That sector context explains why a leak-site claim draws attention; it does not establish that Custom Rx Shoppe’s systems were actually entered or that any of those record types left its control.
What was likely exposed
The facts state that data types named as exposed are not disclosed. It is therefore not possible to inventory what, if anything, was taken. Asserting specific stolen fields would repeat the attacker’s marketing as if it were an audit.
If files from a pharmacy of this kind were ever taken, organisations in the same line of work typically hold some mix of patient names and contact data, prescription and fill history, insurance or payment-related identifiers, prescriber and facility contacts for long-term care accounts, compounding formulas and related clinical notes, and internal business records such as employee or vendor information. Long-term care support can also involve medication administration documentation and care-home operational details. Those are sector norms, not a confirmed contents list for this listing. Exact contents remain unconfirmed, and the number of people who might be affected remains unknown.
Why it matters
A ransomware group’s public listing creates uncertainty for customers, residents of care facilities served by the pharmacy, employees, and partners even when the underlying claim is unverified. If personal or health-related information were involved, real-world risks would include phishing that references real prescriptions or facility relationships, attempts to open fraudulent accounts, and misuse of identity details that are hard to change. For a compounding and long-term care pharmacy, sensitive clinical context could, in a confirmed case, amplify embarrassment or targeted scams. For the organisation, an unconfirmed listing still imposes reputational and operational cost: customers seek reassurance, partners ask questions, and leadership must decide how to investigate and communicate without treating an extortion page as proof.
Equally important is what a leak-site post does not establish. It does not prove negligence, does not document detection failures, and does not state that data is circulating. Readers and counterparties should wait for primary confirmation rather than treating the group’s page as a breach notice. Until the company or an authoritative body speaks with verified detail, the responsible framing remains: The Gentlemen has listed Custom Rx Shoppe; the company has not publicly confirmed the claim as of writing; scale and data types are undisclosed.
If your data was involved
If you are a customer, care-facility resident, employee, or partner and you later learn that your information was involved, treat the situation as conditional and practical. Prefer official notices from the pharmacy or regulators over screenshots from criminal sites. Watch for unexpected password-reset messages, calls that cite your prescriptions or facility, or bills you do not recognise. Where you use online accounts tied to the same email or phone number, enable strong unique passwords and multi-factor authentication. Consider credit or identity monitoring if financial identifiers were ever reportedly exposed, and follow guidance from your bank or insurer if fraudulent activity appears. Pharmacy-related identity issues may also warrant discussion with your clinician or facility about how refill and delivery contacts are verified.
You can run a free exposure scan of your email to check whether your information has already surfaced in known breach data sets unrelated to this claim. That check does not prove or disprove The Gentlemen’s listing about Custom Rx Shoppe; it only helps you see whether your address appears in previously catalogued incidents so you can prioritise password changes and vigilance. Remain guided by confirmed notices, not by unverified leak-site marketing.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Europrim Listed by The Gentlemen Ransomware GroupWilliamson Dacar Associates Listed by The Gentlemen Ransomware GroupVUS Listed by The Gentlemen Ransomware GroupNorthern NJ Eye Institute Listed by The Gentlemen Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Custom Rx Shoppe Listed by The Gentlemen Ransomware Group →
Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.