PT Ikapharmindo Putramas Listed by coinbasecartel Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
PT Ikapharmindo Putramas was listed by the coinbasecartel ransomware group on February 16, 2026, after internal files were exfiltrated in an attack whose timing remains unknown. Anyone who has shared personal or account information with the company should review their records and monitor for unusual activity.
What happened
The only confirmed information is the February 16, 2026 listing by coinbasecartel. The group claims internal files were exfiltrated in a ransomware attack. No independent confirmation of the claim, no count of records, and no description of the files have been released. It is not known when the intrusion began or how long the files were held before the listing appeared.
The group behind it: coinbasecartel
The group claims responsibility by placing PT Ikapharmindo Putramas on its leak site. Public records show coinbasecartel has previously listed other organisations in connection with ransomware activity, typically after encrypting systems and copying data. Specific statements or demands made in this case have not been published beyond the listing itself.
About PT Ikapharmindo Putramas
PT Ikapharmindo Putramas is a pharmaceutical company based in Jakarta, Indonesia. Founded in 1979, it operates as part of the Kalbe Farma Group and produces prescription drugs, over-the-counter medications, and health supplements. Companies in this sector routinely maintain records that include patient or customer details, employee information, supplier contracts, and internal research or manufacturing documentation.
The information in question
The listing refers only to “internal files exfiltrated in ransomware attack.” No inventory of data types has been released. Organisations of this kind commonly hold personal identifiers, medical or prescription records, financial details related to procurement, and employee files. The exact contents remain unconfirmed.
What's at stake
Individuals whose records appear in the exfiltrated material could face risks of identity misuse or targeted fraud if the files contain personal or financial information. The company may encounter regulatory scrutiny and operational disruption while addressing the incident. Because the precise data set is undisclosed, the full extent of potential harm cannot yet be assessed.
Were you affected?
Public information does not identify specific individuals. Those concerned can take the following steps to limit exposure:
- Review bank and medical account statements for unusual activity.
- Enable multi-factor authentication on any accounts that store personal or health data.
- Request a copy of personal data held by healthcare providers or insurers under applicable privacy rules.
- Run a free exposure scan of their email address against known breach data sets to check for prior appearances.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Kementerian Pertanian Listed by coinbasecartel Ransomware GroupPrecision Coating Listed by coinbasecartel Ransomware GroupMillenium Packaging Listed by coinbasecartel Ransomware GroupKemenpppa Listed by coinbasecartel Ransomware GroupLatest breaches
Publicly posted by coinbasecartel — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.