TaslyUS Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The TaslyUS Listed by alphv Ransomware Group (reported May 18, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continued through 2023 to pressure organisations by pairing encryption with data theft and public leak-site listings, turning internal files into leverage even when full details of an intrusion never surface. In that climate, a listing attributed to a well-known actor is often the first public signal that a company may have been hit.
On May 18, 2023, TaslyUS was reported as listed by the alphv ransomware group. Public reporting describes internal files as having been exfiltrated in a ransomware attack. The number of people affected remains unknown, and many operational details have not been disclosed. For patients, partners, and staff connected to a pharmaceutical firm, even a limited public claim matters because it raises the possibility that sensitive business or personal information left the organisation’s control.
What happened
According to the available record, TaslyUS—also identified as Tasly Pharmaceuticals, Inc., or Tasly U.S.—was listed by the alphv ransomware group on or about May 18, 2023. The reported summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for individuals affected has been published. Timing of the underlying intrusion, the initial access method, whether systems were encrypted, any ransom demand, and whether data was later released on a leak site are not detailed in the facts provided. The listing itself should be treated as a claim by the group rather than as independently verified confirmation of every asserted detail.
In short, the public picture is narrow: a named victim, a named threat actor, a report date, and a description of internal-file exfiltration tied to ransomware activity. Beyond that, specifics remain undisclosed.
Who is alphv?
Alphv, also widely known in security reporting as BlackCat, is a ransomware operation that emerged in the early 2020s and functioned as a ransomware-as-a-service (RaaS) brand. Affiliates typically gained access to victim networks, moved laterally, exfiltrated data, and deployed ransomware, after which the group or its partners threatened public release of stolen files if payment was not made. The operation was notable for a Rust-based encryptor, professionalised negotiation and leak infrastructure, and a pattern of naming victims on a dedicated site to increase pressure.
Like other double-extortion groups of that period, alphv’s public listings were a core part of its playbook: the appearance of an organisation’s name was meant to signal that data had been taken and could be published. Those listings are claims by the actors. They do not, by themselves, establish the full scope of what was taken from any single victim, including TaslyUS. Law-enforcement actions and disruptions later affected the brand’s continuity, but at the time of this reported listing the group was an active and widely tracked ransomware threat.
About TaslyUS
Tasly Pharmaceuticals, Inc. (Tasly U.S.) describes itself as dedicated to a healthier world and to changing how medicine is taken and understood. Founded in 2006 and based in Rockville, Maryland, the company positions itself in pharmaceuticals, biologics, and nutraceuticals. Public materials associated with the firm highlight research and development work, including T89 (Dantonic), described as an herbal medicine-derived compound that completed an FDA Phase III global trial with promising data.
Organisations in this sector commonly handle clinical and regulatory documentation, intellectual property, manufacturing and supply information, employee records, and correspondence with partners, investigators, and vendors. A ransomware incident affecting such an entity is consequential not only for corporate confidentiality and competitive position, but also because pharmaceutical and biotech environments often intersect with health-related and personally identifiable information, even when a public breach notice does not itemise every category.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No inventory of file types, no record counts, and no confirmation of customer, patient, or employee data elements have been provided in the material available for this account. Exact contents therefore remain unconfirmed.
Companies of this kind typically hold a mix of corporate and potentially sensitive records: internal email and memos, research and development files, regulatory submissions and trial-related documents, contracts, financial and vendor data, and human-resources information. Some of that material can include names, contact details, and other personal data. None of those categories should be read as verified contents of this incident. Only the broad description—internal files taken in connection with a ransomware attack—is stated in the record.
What's at stake
For individuals who may appear in a pharmaceutical company’s internal files, risks are practical rather than abstract. Exposed contact details or identity data can support phishing and social-engineering attempts that reference the company or a clinical or business relationship. If employment, contractor, or partner information was among the files, fraudsters may try to impersonate the organisation or its staff. Where research, regulatory, or commercial documents are involved, the organisation faces potential intellectual-property exposure, competitive harm, and disruption to ongoing development or partner trust.
Because the scale of affected people is unknown and the file-level contents are undisclosed, it is not possible to state who was touched or how widely. The absence of public detail does not eliminate risk; it simply means affected parties may not receive a clear notification path and must rely on general caution. For TaslyUS, the stakes include operational recovery, legal and regulatory review where applicable, and the longer task of restoring confidence among employees, partners, and the wider research community.
If your data was in this claimed breach
If you have a past or present connection to TaslyUS—as an employee, contractor, partner, or participant in related programs—treat unsolicited messages that invoke the company with extra care. Prefer official channels you already trust when verifying any request for personal information, credentials, or payment. Consider monitoring financial and account activity for unusual behaviour, and enable stronger authentication on email and other important accounts where you can.
Keep records of any notice you may later receive from the organisation or from regulators, and follow instructions from official sources rather than from third parties who cold-contact you about the incident. You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data sets, which can help you prioritise password changes and ongoing monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Viking Therapeutics Listed by alphv Ransomware GroupViking Therapeutics reported to the SEC following a breach Listed by alphv Ransomware GroupLeClair Group Listed by alphv Ransomware GroupHenry Schein Inc - Henry's " LOST SHINE " Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the TaslyUS Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.