londondrugs.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The londondrugs.com Listed by lockbit3 Ransomware Group (reported April 28, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target retailers and pharmacy chains that hold both customer records and operational data, using double-extortion tactics that combine encryption with public leak-site pressure. In this landscape, the appearance of a well-known Canadian retailer on a ransomware group's site is a signal that internal material may have left the organisation's control.
On 28 April 2024, the ransomware group lockbit3 listed londondrugs.com on its leak site, claiming that internal files had been exfiltrated in a ransomware attack. The number of people affected remains unknown, and public detail beyond the listing itself is limited. The claim matters because London Drugs operates both physical stores and an online channel that handle pharmaceuticals, personal information and commercial records.
Breaking down the breach
According to the available record, lockbit3 publicly listed londondrugs.com on 28 April 2024. The group stated that internal files had been exfiltrated as part of a ransomware attack. No confirmed timeline of initial access, no verified count of systems or records, and no independent confirmation of the volume or precise contents of the material have been released in the facts provided. The people-affected figure is listed as unknown. The listing itself constitutes a claim by the group rather than a verified disclosure by the organisation.
Public reporting on the incident does not describe the initial intrusion vector, the encryption status of systems, or any ransom demand. What is known is confined to the leak-site entry and the characterisation of the data as internal files taken during a ransomware attack.
Who is lockbit3?
LockBit3 is a well-documented ransomware-as-a-service operation that has been active for several years. The group typically gains access through phishing, compromised credentials or unpatched remote services, then deploys ransomware that encrypts systems while simultaneously copying data for later publication. Its operators maintain a dark-web leak site where they post victim names and sample files to increase pressure for payment. Prior campaigns have targeted organisations across healthcare, retail, manufacturing and government sectors in multiple countries. The group frequently claims responsibility for breaches by listing victims and asserting that data has been stolen; such claims are not independently verified unless the victim or investigators confirm them.
In this case, the listing of londondrugs.com is presented as a claim by lockbit3. No additional statements attributed specifically to the group about this victim appear in the provided facts beyond the assertion that internal files were exfiltrated.
Who is londondrugs.com?
London Drugs is a Canadian retail chain that operates physical stores and an e-commerce site. It sells pharmaceuticals, cosmetics, electronics, cameras, housewares and related consumer goods, and regularly promotes weekly flyer deals, seasonal events and in-store promotions. As a pharmacy and multi-category retailer, the organisation typically processes prescription information, customer loyalty or account data, payment details, employee records and internal commercial documents. A ransomware incident affecting such an entity raises concerns because the same systems that support online and in-store sales often hold sensitive personal and health-related information alongside operational files.
The breach listing is therefore consequential for customers who have filled prescriptions, created online accounts or participated in loyalty programmes, as well as for staff whose workplace records may reside on the same infrastructure.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or record counts is provided, and the number of people affected is unknown. Organisations of this kind commonly hold customer names, contact details, prescription and health-related information, payment or loyalty-card data, employee personnel files, inventory and supplier records, and internal correspondence. Because the exact contents remain unconfirmed, it is not possible to state which of these categories, if any, were included in the material claimed by lockbit3.
The real-world impact
For individuals, the primary risks associated with an unconfirmed internal-file exfiltration are identity theft, targeted phishing that references real transactions or prescriptions, and potential misuse of any health or financial details that may have been present. Even without a confirmed list of exposed fields, the mere possibility that pharmacy or account data left the organisation can create lasting uncertainty for customers. For the organisation, a ransomware listing can disrupt operations, require forensic investigation and notification processes, and damage trust among shoppers who rely on the chain for both everyday goods and regulated medicines.
Because the scale and precise contents are undisclosed, the full extent of exposure cannot be quantified from public facts alone. The incident nonetheless illustrates how retail and pharmacy environments remain attractive targets for groups that combine encryption with data theft.
If your data was in this claimed breach
If you have shopped at London Drugs, filled prescriptions there, or held an online or loyalty account, treat the listing as a prompt to review your own exposure rather than as proof that your records were taken. Practical first steps include:
- Monitor bank and credit-card statements for unfamiliar charges and enable transaction alerts where available.
- Change passwords on any London Drugs-related accounts and on other sites that reused the same credentials; enable multi-factor authentication.
- Watch for phishing emails or calls that reference recent purchases, prescriptions or store events, and avoid clicking unexpected links.
- Request a free credit report or fraud alert if you are concerned about identity misuse, following the procedures available in your country.
- Run a free exposure scan of your email address against known breach data sets to see whether your information has already appeared in other incidents.
Public detail on this specific event remains limited to the lockbit3 listing of 28 April 2024 and the claim of internal-file exfiltration. Continued caution with personal and financial information is warranted until more definitive information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
fcl.crs Listed by lockbit3 Ransomware Groupnetspectrum.ca Listed by lockbit3 Ransomware Groupsierraconstruction.ca Listed by lockbit3 Ransomware Groupduttonbrock.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the londondrugs.com Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.