LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Inotiv, Inc Listed by qilin Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Inotiv, Inc Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 8, 2025
Inotiv, Inc Listed by qilin Ransomware Group

Reported August 8, 2025.

HIGH
Severity
August 8, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Inotiv, Inc was listed by the Qilin ransomware group on August 08, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; check official statements to see whether your information is involved.

Severity & verification
HIGH severity claimedUnverified claim
Exposes medical data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details sit inside a contract research organisation’s systems face real, everyday risks when those systems are compromised: identity misuse, targeted phishing, or exposure of sensitive health-related research records that can follow them for years. On 8 August 2025 the ransomware group qilin publicly listed Inotiv, Inc., a U.S. publicly traded contract research organisation, claiming it had stolen internal files. The number of individuals affected remains unknown, and the precise contents of the material have not been independently confirmed, yet the mere listing places anyone connected to the company—employees, research partners, study participants—on notice that their information may now circulate beyond its intended controls.

What is known so far is limited to the group’s own claim and the company’s public profile. No official confirmation of the breach’s full scope, method of entry, or exact data categories has been released in the available record. For ordinary people, that uncertainty itself is the practical stake: until more detail emerges, caution around unexpected communications and routine monitoring of financial and medical accounts is the prudent response.

What happened

According to the publicly available breach record, Inotiv, Inc. was listed by the qilin ransomware group on 8 August 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access vector, the duration of the intrusion, the volume of data taken, or any ransom demand—have been disclosed in the record. The number of people affected is listed as unknown. The incident is therefore known only through the group’s claim that it successfully stole internal files; independent verification of that claim is not part of the available facts.

The group behind it: qilin

qilin is a well-documented ransomware operation that functions as a ransomware-as-a-service (RaaS) group. It typically encrypts victims’ systems and simultaneously exfiltrates data, then threatens to publish the stolen material on a dedicated leak site if payment is not made—an approach commonly called double extortion. Public reporting on the group over recent years shows it has targeted organisations across multiple sectors, often posting sample files or full archives to pressure victims. In this case the group claims to have listed Inotiv, Inc. and to have removed internal files; that listing remains an unverified claim unless and until the company or independent investigators state it. No additional statements attributed specifically to qilin about Inotiv beyond the listing itself appear in the facts.

Who is Inotiv, Inc?

Inotiv, Inc. is a publicly traded United States contract research organisation (CRO). It supplies nonclinical and analytical drug-discovery and development services to pharmaceutical and medical-device companies. CROs of this type routinely handle proprietary research data, study protocols, laboratory results, and, in many cases, information linked to employees, contractors, and research subjects. Because the company sits inside the regulated drug-development pipeline, a compromise of its systems can affect not only its own workforce but also the confidentiality of partner companies’ intellectual property and any personal data collected during studies. The public nature of its listing on a ransomware leak site therefore carries consequences that extend beyond a single corporate network.

The information in question

The available facts state only that “internal files” were exfiltrated in a ransomware attack. No inventory of specific data types—such as names, addresses, Social Security numbers, health records, or research datasets—has been disclosed. Organisations operating as CROs typically maintain employee records, client contracts, laboratory notebooks, study subject identifiers, and regulatory correspondence. Whether any of those categories were among the files claimed by qilin remains unconfirmed. Until the company or a competent authority publishes a verified list, the exact contents must be treated as unknown.

Why it matters

For individuals, the practical risk is that any personal details present in the stolen files could be used for identity fraud, credential stuffing, or highly targeted social-engineering attempts. Research-related data, even if anonymised, can sometimes be re-identified or used to infer sensitive health information. For the organisation itself, the incident raises the possibility of regulatory scrutiny under data-protection and clinical-research rules, contractual disputes with pharmaceutical clients, and the operational cost of forensic investigation and system restoration. Because the number of people affected is unknown and the data types are not specified, the full scale of those risks cannot yet be measured; the uncertainty itself prolongs the period during which affected parties must remain vigilant.

Were you affected?

If you are a current or former employee, contractor, research partner, or study participant connected to Inotiv, Inc., treat any unexpected emails, calls, or account activity with caution. Change passwords on accounts that may have been linked to company systems, enable multi-factor authentication where available, and monitor financial and medical statements for unusual activity. You can also run a free exposure scan of your email address against known breach datasets to check whether your information has already appeared in public dumps. Keep records of any suspicious contact and consider placing fraud alerts with the major credit bureaus if you believe sensitive identifiers may have been involved. Further official notices from the company, if issued, should be read carefully for any additional guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyInotiv, Inc security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Inotiv, Inc’s full breach history →

More recent breaches

Georgia Dermatology & Skin Cancer Center Listed by qilin Ransomware GroupDecember 26, 2025Shore Gardens Rehabilitation & Nursing Center Listed by qilin Ransomware GroupDecember 24, 2025Lugiano Medical Listed by qilin Ransomware GroupDecember 22, 2025Oxford Rehabilitation Center Listed by qilin Ransomware GroupDecember 12, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Inotiv, Inc Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram