www.bms.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
www.bms.com was listed by the apt73 ransomware group on 24 February 2025, with the attackers claiming to have exfiltrated internal files. Anyone connected to the organisation should check their accounts and monitor for unusual activity.
When a major pharmaceutical company appears on a ransomware group's leak site, the immediate concern for patients, employees and partners is whether personal or sensitive health-related information has left the organisation's control. On 24 February 2025, www.bms.com was listed by the group known as apt73, which claims to have exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and public detail about the precise contents of the material is limited, yet the mere listing raises practical questions for anyone whose data the company may hold.
Ransomware incidents of this kind typically involve both encryption of systems and the theft of files that can later be published or sold if a ransom is not paid. For individuals connected to a pharmaceutical firm, that can mean exposure of personal details that are difficult to change and that carry lasting risk of misuse.
Inside the incident
According to the available record, www.bms.com was listed by the apt73 ransomware group on 24 February 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No confirmed figure has been released for the number of people affected, and the exact method of initial access, the duration of the intrusion, and the full scale of the data taken have not been publicly disclosed. The only concrete description provided is that internal files were removed and that the material includes personal data amounting to 302 lines. Beyond that listing and summary, further operational details remain unconfirmed.
The group behind it: apt73
apt73 is a ransomware operation that follows the now-familiar double-extortion model used by many contemporary groups: systems are encrypted and data is stolen, after which the operators threaten to publish the material on a dedicated leak site unless payment is made. Public reporting on apt73 describes a group that targets organisations across multiple sectors, often using commodity tools for initial access and then moving laterally to locate high-value file shares and databases. Like other ransomware actors, it typically posts victim names and sample files to pressure payment and to demonstrate that exfiltration has occurred. In this case the group claims to have listed www.bms.com and to have taken internal files; those assertions have not been independently verified in the public record and should be treated as claims rather than established fact.
Who is www.bms.com?
www.bms.com is the public web presence of Bristol Myers Squibb, a large multinational pharmaceutical company that researches, develops and markets medicines for a range of serious conditions. Organisations of this type routinely hold extensive internal records: employee information, clinical-trial data, supplier contracts, research files and, in some cases, patient or healthcare-provider details collected in the course of business. Because pharmaceutical firms sit at the intersection of personal health information, intellectual property and regulated manufacturing, a breach that reaches internal files can affect both individuals and the company's ability to operate securely. The listing therefore carries weight beyond a routine corporate incident.
What data was at risk
The public summary states that internal files were exfiltrated and that the material includes personal data described as 302 lines. No further breakdown of data types—such as names, contact details, medical identifiers, financial records or research documents—has been released. Pharmaceutical companies typically maintain employee records, partner and vendor information, clinical and regulatory files, and various categories of personal data collected under privacy and health-information rules. Whether any of those categories were among the 302 lines remains unconfirmed. Readers should therefore treat the exact contents as undisclosed rather than assume specific fields may have been exposed.
Why it matters
For individuals, the practical risk is that personal data, once outside the organisation, can be used for targeted phishing, identity fraud or social-engineering attacks that reference real employment or medical relationships. Even a modest volume of personal data can be enough to craft convincing messages. For the company itself, the incident raises questions of operational disruption, potential regulatory scrutiny under health-privacy and data-protection regimes, and the longer-term cost of restoring trust with patients, employees and partners. Because the number of people affected is unknown and the full data set is unconfirmed, the precise scope of harm cannot yet be measured, but the combination of ransomware encryption and claimed exfiltration is sufficient to warrant attention from anyone who has dealt with the organisation.
What to do if you're exposed
If you have a past or present relationship with Bristol Myers Squibb—whether as an employee, contractor, clinical-trial participant or business partner—monitor financial and email accounts for unexpected activity and treat any unsolicited messages that reference the company with caution. Consider placing fraud alerts with credit bureaus if you believe sensitive identifiers may have been involved, and keep records of any communications you receive. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; that step provides a quick, concrete way to assess whether your information has surfaced elsewhere. Official notifications, if any are issued by the company, will remain the most authoritative source of guidance for those directly affected.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
bms.com Listed by apt73 Ransomware GroupSusan Fischgrund Listed by apt73 Ransomware Groupwesternint.com Listed by apt73 Ransomware Groupalkaloid.com.mk Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the www.bms.com Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.