nanolive.ch 2.0 Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
nanolive.ch 2.0 was listed by the apt73 ransomware group on November 13, 2024, after internal files were exfiltrated in a ransomware attack; the date of the actual breach has not been established. Individuals are advised to check whether their data may have been exposed and to take protective steps.
On November 13, 2024, the organisation listed as nanolive.ch 2.0 appeared on a leak site operated by the ransomware group apt73. Public reporting indicates that internal files were claimed to have been exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical details about the incident have not been disclosed.
The listing itself constitutes a claim by the group rather than independent confirmation. For an organisation working in live-cell imaging and analysis, any unauthorised access to internal material raises practical questions about the security of research data, operational records and related business information, even while the precise scope stays unconfirmed.
What happened
According to the available record, nanolive.ch 2.0 was listed by the apt73 ransomware group on November 13, 2024. The report states that internal files were exfiltrated in a ransomware attack. No public information has been released about the initial intrusion method, the duration of any unauthorised access, the volume of data involved, or whether systems were encrypted in addition to the claimed exfiltration. The number of individuals potentially affected is listed as unknown. Beyond the leak-site claim and the description of internal files, no further verified timeline or forensic findings have been made public.
Who is apt73?
apt73 is identified in public reporting as a ransomware group. Like other actors in this category, such groups typically gain access to networks, move laterally to locate valuable data, exfiltrate files, and then demand payment under threat of publication or further disruption. Many maintain dedicated leak sites where they post victim names and sample data as pressure tactics. Public knowledge of apt73 centres on this general pattern of double-extortion ransomware activity rather than on any unique technical signature that has been independently verified in open sources. In the present case the group claims to have listed nanolive.ch 2.0 after an attack involving exfiltration of internal files; that claim has not been corroborated by the organisation or by independent investigators in the material available here. Attribution therefore rests solely on the group’s own listing.
Who is nanolive.ch 2.0?
Nanolive develops label-free live-cell imaging and analysis platforms, together with associated consumables and services. The technology is described as 100 percent non-invasive, allowing researchers to observe living cells over time without the use of fluorescent labels or other invasive markers. Organisations of this type typically operate at the intersection of biotechnology, microscopy hardware, software analytics and life-science research support. They commonly hold proprietary technical documentation, research datasets, customer and partner records, intellectual-property materials, and internal operational files. A breach affecting such an entity is consequential because the data involved can include sensitive scientific results, commercial agreements and personal information of employees or collaborators, any of which may have value to competitors or other unauthorised parties. The “2.0” designation appears in the listing title and may simply reflect how the group chose to identify the victim; no additional public clarification has been provided.
What was likely exposed
The only data type named in the available facts is “internal files” said to have been exfiltrated in a ransomware attack. No inventory of specific file categories, no sample documents, and no confirmation of personal data, financial records or research datasets have been released. Organisations engaged in live-cell imaging and analysis platforms ordinarily maintain technical design files, experimental protocols, customer lists, employee records, contracts and intellectual-property documentation. Whether any of those categories were among the files claimed by apt73 remains unconfirmed. Public detail is limited to the group’s assertion of exfiltration; the exact contents and sensitivity of the material have not been independently verified.
The real-world impact
For individuals whose information may have been present in internal files, the primary risks include potential misuse of contact details, credentials or other personal data if such material was included. Employees, research partners or customers could face phishing attempts that reference legitimate internal context, or longer-term concerns about identity-related fraud if identifiers were exposed. Because the number of people affected is unknown and the precise data types remain undisclosed, the scale of personal impact cannot be quantified from public sources.
For the organisation itself, the consequences of a claimed ransomware incident typically include operational disruption, the cost of investigation and remediation, possible regulatory notification obligations, and reputational questions among research clients and partners. Intellectual property or unpublished scientific material, if present among the internal files, could also create competitive or collaborative risks. None of these outcomes has been confirmed in the present case; they represent the ordinary range of effects observed after similar claims rather than verified results of this listing.
What to do if you're exposed
Anyone who has had a professional or commercial relationship with Nanolive should treat the possibility of exposure as a prompt for basic hygiene rather than confirmed compromise. Change passwords on any accounts that may have been used in connection with the organisation, enable multi-factor authentication where available, and remain alert to unsolicited messages that appear to reference internal projects or contacts. Monitor financial and identity accounts for unusual activity. Because the exact contents of the claimed files are unconfirmed, these steps are precautionary. Readers can also run a free exposure scan of their email address against known breach datasets to check whether their information has already appeared in publicly catalogued incidents; such a scan provides an additional data point but does not replace vigilance regarding this specific claim.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
nanolive.ch Listed by apt73 Ransomware Groupwww.polleninformation.at Listed by apt73 Ransomware Groupwww.baldinger-ag.ch Listed by apt73 Ransomware GroupSusan Fischgrund Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the nanolive.ch 2.0 Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.