nanolive.ch Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
A ransomware group known as apt73 listed nanolive.ch on October 21, 2024, claiming to have stolen internal files from the organization. The number of individuals affected remains undisclosed, so anyone connected to nanolive.ch should check for official notices and change any exposed credentials as a precaution.
On 21 October 2024, the ransomware group known as apt73 listed nanolive.ch on its leak site, claiming to have carried out a ransomware attack that involved the exfiltration of internal files. The number of people whose information may be involved remains unknown, and public detail about the precise contents of those files is limited. For anyone who has dealt with the company—whether as an employee, research partner, customer, or supplier—the practical stakes are straightforward: internal business records can contain names, contact details, contractual information, and other material that, once outside the organisation’s control, can be misused for fraud, phishing, or further intrusion.
Because the listing is a claim by the group rather than an independently confirmed disclosure by the organisation, the full scope of what happened is still unclear. What is known is enough to warrant careful attention from those who may be affected.
Inside the incident
According to the available record, nanolive.ch was listed by the apt73 ransomware group on 21 October 2024. The group asserts that internal files were exfiltrated during a ransomware attack. No public figure has been given for the volume of data taken, the number of individuals whose records appear in the material, or the exact date the intrusion began. The method of initial access and the duration of the attackers’ presence inside the network have not been disclosed in the facts available. As with many ransomware listings, the claim itself is the primary public signal; independent verification of the full extent of the compromise has not been published in the material provided.
Who is apt73?
apt73 is a ransomware operation that follows the now-familiar double-extortion model used by many such groups. After gaining access to a network, operators typically encrypt systems and simultaneously copy data, then threaten to publish the stolen material on a dedicated leak site if a ransom is not paid. The group’s public listings serve both as pressure on the victim and as advertising of its activity. Well-documented patterns associated with this class of actor include the use of phishing or exploited remote-access services for initial entry, lateral movement inside the network, and the staged exfiltration of files before encryption. Specific claims made by apt73 about nanolive.ch beyond the listing itself and the assertion that internal files were taken are not detailed in the public facts; those assertions should therefore be treated as the group’s claims rather than established fact.
Who is nanolive.ch?
Nanolive is a company whose public description centres on label-free live-cell imaging and analysis platforms, together with related consumables and services. Its technology is presented as non-invasive, allowing researchers to observe living cells over time without the need for dyes or other labels that can alter cellular behaviour. Organisations of this kind typically operate in the life-sciences and biotechnology sector, serving academic laboratories, pharmaceutical research groups, and industrial R&D teams. They routinely hold technical documentation, customer and partner contact information, contractual records, research-related correspondence, and internal operational files. A breach affecting such an organisation is consequential because the data often mixes commercial sensitivity with personal identifiers of scientists, procurement staff, and collaborators, creating both intellectual-property and privacy risks.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases, or categories of personal data has been publicly named. Organisations that develop and sell specialised scientific instruments commonly retain employee records, customer lists, sales and support correspondence, technical specifications, and partnership agreements. Whether any of those categories appear in the material claimed by apt73 remains unconfirmed. Until the organisation or independent investigators publish a more detailed inventory, the exact contents of the exfiltrated files cannot be stated as fact.
The real-world impact
For individuals whose details may sit inside the taken files, the most immediate risks are targeted phishing and social-engineering attempts that reference genuine business relationships or technical projects. Stolen contact lists and internal correspondence give attackers plausible context that can make fraudulent messages harder to dismiss. For the organisation itself, the consequences include potential disruption of research collaborations, loss of commercial confidentiality, regulatory notification obligations where personal data is involved, and the longer-term cost of forensic investigation and system hardening. Because the number of people affected is listed as unknown, the scale of personal exposure cannot yet be quantified; the prudent assumption is that anyone who has exchanged documents or account details with nanolive.ch could be within the affected set until proven otherwise.
If your data was in this claimed breach
If you have reason to believe your information may have been among the internal files claimed by apt73, a small number of concrete steps reduce immediate risk:
- Treat unexpected emails or messages that reference Nanolive projects, invoices, or technical support as potentially fraudulent until verified through a separate, known channel.
- Change passwords on any accounts that used the same credentials as those shared with the company, and enable multi-factor authentication where it is available.
- Monitor financial and professional accounts for unusual activity, especially if you have ever supplied banking or procurement details.
- Request a free exposure scan of your email address against known breach data sets so you can see whether the same address has already appeared in other public dumps.
Public detail remains limited; further clarity will depend on any official statements the organisation chooses to release and on independent analysis of the material if it is published. Until then, measured caution is the most useful response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
nanolive.ch 2.0 Listed by apt73 Ransomware Groupwww.polleninformation.at Listed by apt73 Ransomware Groupwww.baldinger-ag.ch Listed by apt73 Ransomware GroupSusan Fischgrund Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the nanolive.ch Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.