phitoformulas.com.br Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The phitoformulas.com.br Listed by lockbit3 Ransomware Group (reported August 19, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On August 19, 2023, the Brazilian compounded-medicines company phitoformulas.com.br appeared on a leak site operated by the ransomware group known as lockbit3. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people whose information may be involved remains unknown, and the precise contents of those files have not been detailed in available accounts.
For anyone who has filled prescriptions, placed orders, or shared personal or health-related details with a compounding pharmacy, a listing of this kind raises immediate practical questions: what was taken, who might see it, and what steps reduce further harm. Because Reported Details are limited, the prudent response is careful attention rather than assumption.
Inside the incident
According to the public record, phitoformulas.com.br was listed by lockbit3 on or around August 19, 2023. The available summary describes the event as a ransomware attack in which internal files were allegedly exfiltrated. No figure has been published for the number of individuals affected, no technical description of the intrusion method has been released in the cited material, and no confirmation of data publication or ransom payment appears in the facts provided. The listing itself constitutes a claim by the group; independent verification of the full scope is not contained in the reported information.
In short, the incident is known principally through the group's leak-site entry and the accompanying characterization that internal files left the organization. Timing beyond the report date, exact volume of data, and any subsequent release remain undisclosed.
Who is lockbit3?
Lockbit3 is the name associated with a prolific ransomware operation that has been active for years in the cyber-criminal underground. Groups operating under the LockBit banner typically gain access to an organization's networks, encrypt systems to disrupt operations, and exfiltrate copies of data beforehand. They then threaten to publish the stolen material on a dedicated leak site unless a ransom is paid. This double-extortion model—encryption plus the threat of public exposure—has been their standard approach across many victims in multiple countries and sectors.
LockBit affiliates have historically targeted a wide range of organizations, from manufacturers and professional services firms to healthcare-related entities. The group has been observed using automated tools, living-off-the-land techniques, and pressure campaigns that include countdown timers on leak sites. Law-enforcement actions and infrastructure disruptions have affected LockBit operations at various points, yet listings under the lockbit3 name have continued to appear. In this case, the appearance of phitoformulas.com.br on such a site is a claim by the actors; it does not by itself prove every asserted detail of the intrusion.
Who is phitoformulas.com.br?
Phitoformulas.com.br presents itself as a Brazilian compounding pharmacy focused on customized medications. Its own public description emphasizes dedication to health, the production of compounded drugs, and compliance with standards set by ANVISA, Brazil's health regulatory agency. Compounding pharmacies prepare individualized formulations—adjusting dosages, removing allergens, or combining ingredients—that are not available as standard commercial products. They routinely interact with patients, prescribing clinicians, and suppliers.
Organizations of this type typically maintain records that can include patient names and contact details, prescription histories, medical justifications for compounded preparations, payment or insurance information, and internal operational documents. A breach affecting such an entity is consequential because the data often mixes ordinary personal identifiers with sensitive health-related information, and because trust in the confidentiality of medical services is central to how patients and doctors use these services.
The information in question
The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of file types, record counts, or specific data categories has been disclosed in the available reporting. It is therefore not possible to state as fact which exact fields or documents left the organization.
In general, a compounding pharmacy may hold customer and patient contact data, prescription and formulation records, communications with healthcare providers, financial or billing details, and internal business files such as supplier lists or operational procedures. Whether any or all of those categories were present among the exfiltrated files remains unconfirmed. Readers should treat claims about precise contents with caution until corroborated by the organization or by independent analysis of released material.
What's at stake
For individuals, the primary risks are misuse of personal identifiers and exposure of health-related details. Even limited contact information can enable targeted phishing or social-engineering attempts that reference a real pharmacy relationship. If prescription or medical notes were among the files, the sensitivity increases: such data can be used for embarrassment, discrimination, or more convincing fraud. Because the number of affected people is unknown and the exact data types are unconfirmed, the practical level of risk for any single person cannot be quantified from public facts alone.
For the organization, the stakes include operational disruption from ransomware, potential regulatory scrutiny under Brazilian data-protection and health-privacy rules, reputational damage with patients and prescribing clinicians, and the cost of investigation and remediation. A leak-site listing also creates ongoing uncertainty until the status of the data—whether published, sold, or retained—is clarified.
If your data was in this claimed breach
If you have been a customer or patient of phitoformulas.com.br, begin by treating unsolicited messages that reference the pharmacy or your prescriptions with skepticism; verify any request through official channels you already trust. Monitor financial and email accounts for unusual activity, and consider placing fraud alerts if you believe sensitive identifiers may have been involved. Change passwords on related accounts and enable multi-factor authentication where available. Keep records of any suspicious contact.
Because Reported Details about this incident remain limited, checking whether your email address has appeared in other known breach data sets can provide additional context. Free exposure-scan tools let you see whether your address surfaces in previously compiled collections; a positive result does not prove involvement in this specific event, but it can highlight accounts that deserve tighter security. Stay alert for official statements from the company or Brazilian authorities that may clarify the scope of the exfiltrated files.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
grupohospitalarvidas.com.br Listed by lockbit3 Ransomware Groupunimed.coop.br Listed by lockbit3 Ransomware Groupcoastalplainsctr.org Listed by lockbit3 Ransomware Groupolea.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the phitoformulas.com.br Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.