Skip to content
Ransomware News

Ransomware Group aurora Hits: Laboratorios Roemmers SAICF

Admin
HookPhish team
Target organization Laboratorios Roemmers SAICF roemmers.com.ar Healthcare

Summary

In the latest cybersecurity news, Laboratorios Roemmers SAICF — an organization based in AR — has fallen victim to a ransomware attack conducted by the group aurora. This data breach, discovered on 2026-10-01T06:55:01.164223+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization Laboratorios Roemmers SAICF
Threat Group aurora
Summary Laboratorios Roemmers SAICF — Argentina’s #1 pharmaceutical company by revenue, with €1.669 billion in consolidated turnover, 6,890 employees, and 69 subsidiaries across 11 countries.

The exposed material includes:

4,207 employees’ national identity numbers (CUIL) — Argentina’s equivalent of a Social Security Number — combined with dates of birth, health insurance affiliations, and employer identifiers. A complete identity-theft package for the entire Argentine workforce.
Psychotropic drug dispensing records — employee-by-employee tracking of who receives clonazepam, alprazolam, diazepam, and other psychiatric medications from the company nursing station. The most sensitive category: mental health data.
COVID-19 health tracking with clinical symptoms — individual symptom logs, doctor’s notes, quarantine dates, and return-to-work clearances for employees who tested positive.
Pre-employment medical exam results with full DNI (national identity document) numbers.

82 GB of drug formulations — the complete pharmaceutical IP portfolio covering every product Roemmers manufactures, from API synthesis methods to finished-form specifications.
193 MB of API supplier qualification dossiers for 30+ international suppliers including CERBIOS (Switzerland), revealing the entire supply chain.
14 GB of internal drug pricing strategy and competitive intelligence

Date of Breach 2026-10-01T00:00:00+00:00
Discovery Date 2026-10-01T06:55:01.164223+00:00
Region AR
Target Domain roemmers.com.ar
Business Sector Healthcare

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions