Pharmerica.com & BrightSpring Health Services Listed by moneymessage Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Pharmerica.com & BrightSpring Health Services Listed by moneymessage Ransomware Group (reported April 8, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On April 08, 2023, PharMerica and BrightSpring Health Services were listed by the moneymessage ransomware group, which claimed that internal files had been exfiltrated in a ransomware attack. The number of people affected remains unknown, and public detail on the incident is limited to the group’s listing and the description of internal files as the exposed material.
Both organisations operate in healthcare-related services at significant scale. A claimed ransomware incident involving internal files therefore raises practical questions for patients, residents, employees and partners about what may have left their systems and what steps are warranted while fuller confirmation is absent.
Breaking down the breach
According to the available record, the incident was reported on April 08, 2023. The moneymessage ransomware group listed Pharmerica.com and BrightSpring Health Services and claimed that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published in the material provided. Timing of the intrusion, the initial access method, the duration of any unauthorised presence, and the precise volume or categories of files taken beyond the general description of “internal files” are undisclosed.
The listing itself constitutes a claim by the threat actor. Independent verification of the full scope, the success of any encryption, or whether negotiations or recovery actions occurred is not contained in the public facts given here. Organisations named on ransomware leak sites sometimes later confirm, dispute, or remain silent on the details; in this case the record simply notes the listing and the stated exfiltration of internal files.
Inside moneymessage
Moneymessage is a ransomware operation that has appeared in public reporting as a double-extortion group: actors associated with it typically claim to encrypt systems and to steal data, then threaten to publish or sell the material if a ransom is not paid. Like other groups in this category, it has used dedicated leak sites to name victims and, in some cases, to release samples or larger archives as pressure. Public tracking of such groups shows that listings are assertions by the criminals and are not, by themselves, official confirmations from the named organisations.
Tactics commonly associated with this style of activity include phishing or exploitation of remote access services for initial entry, lateral movement inside networks, theft of data prior to or alongside encryption, and public naming of the victim. Specific technical indicators, ransom demands, or statements that moneymessage may have made solely about PharMerica or BrightSpring beyond the fact of the listing and the claim of internal-file exfiltration are not detailed in the facts at hand. Readers should treat the group’s claims as unverified until corroborated by the organisations or by independent investigation.
About Pharmerica.com & BrightSpring Health Services Listed by moneymessage Ransomware Group
PharMerica, headquartered in Louisville, Kentucky, is described as one of the largest institutional pharmacy companies in the United States, operating more than 180 long-term care pharmacies across nearly every state and reporting revenue on the order of $3 billion. It supplies pharmacy services with a national footprint while emphasising local delivery. BrightSpring Health Services is characterised as a leading provider of home- and community-based health services for complex populations that need specialised or chronic care, with reported revenue of approximately $5.4 billion, and a focus on outcomes supported by service and technology capabilities.
Organisations of this type sit at the intersection of pharmacy fulfilment, long-term care, and home health. They routinely handle clinical, demographic, billing, and operational information for vulnerable populations, as well as employee and contractor records and the internal documents required to run multi-state operations. A ransomware claim against entities of this scale is consequential because disruption can affect medication supply chains and care coordination, and because any exposure of internal files may touch sensitive personal or health-related material even when the exact contents remain unconfirmed.
The information in question
The facts state that the data types named as exposed are internal files exfiltrated in a ransomware attack. No further inventory—such as specific document types, databases, patient lists, or employee files—is provided. The number of individuals potentially implicated is unknown.
Companies in institutional pharmacy and home- and community-based health services typically hold patient and resident identifiers, prescription and clinical data, insurance and billing records, employee personnel files, contracts, and operational documents. It is reasonable to expect that internal files could include some mixture of those categories, yet it is not established which of them, if any, were actually taken in this incident. Exact contents remain unconfirmed; the public record does not itemise the exfiltrated material beyond the general label of internal files.
The real-world impact
For individuals whose information may have been among internal files, the concrete risks depend on what was actually present. If clinical, demographic or financial details were included, possible outcomes include targeted phishing, identity misuse, or exposure of sensitive health circumstances. If the material was limited to operational or non-personal documents, direct personal harm may be lower, though business partners and staff could still face secondary effects such as fraud attempts that reference internal knowledge. Because the affected population size and precise data types are undisclosed, the scale of personal risk cannot be quantified from the available facts.
For the organisations, a ransomware incident can mean operational disruption, costs of investigation and recovery, regulatory notification obligations under health-privacy and breach laws, and reputational damage. Long-term care pharmacies and home-health providers also face continuity pressures: delays in dispensing or care coordination can affect patients who rely on timely medication and services. None of these impacts are asserted here as proven outcomes of this specific event; they are the ordinary consequences that follow when ransomware groups claim to have taken internal files from healthcare-adjacent operators.
If your data was in this claimed breach
If you are a patient, resident, employee or partner of PharMerica or BrightSpring Health Services, treat the listing as a signal to increase caution rather than as proof that your records were taken. Monitor financial and insurance statements for unfamiliar activity, be sceptical of unexpected emails or calls that reference the companies or your care, and consider placing fraud alerts with major credit bureaus if you have reason to believe sensitive identifiers were involved. Obtain any official notices the organisations may issue; those notices, when published, remain the authoritative source for what was affected and what remedies they offer.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or deny inclusion in this particular incident, but it can show whether your address appears in other publicly tracked breaches and help you prioritise password changes and monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Anna Jaques Hospital Listed by moneymessage Ransomware GroupFirst Baptist Medical Center Listed by moneymessage Ransomware GroupMicro Star International Listed by moneymessage Ransomware GroupX-Copper Professional Listed by moneymessage Ransomware GroupLatest breaches
Publicly posted by moneymessage — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.