LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › visufarma.com Listed by incransom Ransomware Group

HIGH severity claimedUnverified claimHow we verify

visufarma.com Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·November 14, 2024
visufarma.com Listed by incransom Ransomware Group

Reported November 14, 2024.

HIGH
Severity
November 14, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

visufarma.com was listed today, November 14, 2024, by the incransom ransomware group, which claims to have exfiltrated internal files. Anyone with an account or relationship with visufarma.com should check the company’s site or contact them directly to confirm whether their information was involved and follow any guidance provided.

Severity & verification
HIGH severity claimedUnverified claim
Exposes biometric data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On November 14, 2024, the ransomware group known as incransom listed visufarma.com on its leak site, claiming responsibility for a ransomware attack that involved the exfiltration of internal files. Public reporting indicates the group asserted it had obtained 200GB of data along with a figure noted as 50kk, though independent confirmation of the incident, its full scope, or the precise contents remains limited. The number of people affected is unknown.

This listing places the ophthalmology-focused company in the public view of a known ransomware actor. For individuals or partners who may have shared information with the organisation, the claim raises questions about potential exposure even while many operational details stay undisclosed.

Breaking down the breach

According to the available record, visufarma.com was named by the incransom group on November 14, 2024. The group’s leak-site entry describes the event as a ransomware attack in which internal files were allegedly exfiltrated. The listing includes references to 200GB of data and a notation of 50kk; these figures originate solely from the group’s claim and have not been independently verified in the public facts. No further technical details—such as the initial access method, the duration of any intrusion, encryption status of systems, or ransom demands—have been disclosed. The number of individuals or records involved is listed as unknown. At present the incident rests on the group’s public assertion rather than confirmed forensic reporting from the organisation itself.

Inside incransom

Incransom is a ransomware operation that has been active in recent years and is known for employing double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to publish it if payment is not made. Like many contemporary groups, it maintains a dedicated leak site where it posts victim names, sample files, and claimed data volumes to increase pressure. Public tracking of the group shows it has targeted organisations across multiple sectors, often advertising large data hauls to attract attention and potential buyers of the stolen material. The listing of visufarma.com follows this established pattern; the group claims the company as a victim and asserts possession of internal files, but such postings remain unverified claims until corroborated by the affected organisation or independent investigators. No additional statements from incransom specific to this case beyond the listing itself appear in the available facts.

About visufarma.com

Visufarma.com is the online presence of VISUfarma, a company formed in 2016 through the combination of the Italian firm Visufarma SpA and commercial activities of the French-headquartered Nicox SA. The organisation specialises in ophthalmic products, offering a portfolio that covers dry eye, eyelid hygiene, meibomian gland dysfunction, blepharitis and demodex management, retinal health, food supplements, and glaucoma treatments. As a pharmaceutical and medical-device company operating in Europe, it typically maintains relationships with healthcare professionals, distributors, patients, and regulatory bodies. A breach involving such an entity is consequential because the sector routinely handles commercial, clinical, and personal data that can be sensitive for both business continuity and individual privacy.

What data was at risk

The facts state that internal files were exfiltrated in the ransomware attack. The incransom listing further claims a volume of 200GB and a figure of 50kk, but does not itemise the exact file types or categories. Public detail on the precise contents is therefore limited and unconfirmed. Organisations of this kind commonly hold employee records, customer and healthcare-professional contact details, commercial contracts, product research, regulatory documentation, and financial information. Whether any of those categories were among the claimed internal files cannot be established from the available record; only the group’s assertion of exfiltrated internal material is known.

The real-world impact

For people whose information may have been held by VISUfarma, the primary risks include potential misuse of personal or professional contact details, targeted phishing that leverages knowledge of the company’s products or relationships, and longer-term identity or privacy concerns if sensitive records were included. Because the exact data types and the number of affected individuals remain unknown, the scale of personal exposure cannot be quantified. For the organisation itself, the listing creates reputational pressure, possible regulatory scrutiny under European data-protection rules, and operational disruption if systems were encrypted or if partners lose confidence. Recovery costs, legal notifications, and any subsequent sale or publication of the claimed data would add further consequences, though none of these outcomes have been confirmed in the public facts.

If your data was in this claimed breach

If you have had dealings with VISUfarma or its predecessor entities, treat the listing as a prompt for caution rather than confirmed personal compromise. Monitor financial and email accounts for unusual activity, enable multi-factor authentication where available, and be alert to phishing messages that reference eye-care products or company contacts. Change passwords for any accounts that may have been linked to the organisation. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets. Official statements from the company, if issued, should be followed for any specific guidance on notifications or support.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyvisufarma.com security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See visufarma.com’s full breach history →

More recent breaches

Community Connections Listed by incransom Ransomware GroupApril 4, 2026Inner City Family Health Team (ICFHT.local) Listed by incransom Ransomware GroupDecember 23, 2024Onecare Listed by incransom Ransomware GroupDecember 15, 2024falp.org Listed by incransom Ransomware GroupDecember 8, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the visufarma.com Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram