hiveleak attacks Supernus Pharmaceuticals, NASDAQ: SUPN

Incident Date:

February 25, 2022

World map

Overview

Title

hiveleak attacks Supernus Pharmaceuticals, NASDAQ: SUPN

Victim

Supernus Pharmaceuticals, NASDAQ: SUPN

Attacker

Hiveleak

Location

Rockville, USA

Marryland, USA

First Reported

February 25, 2022

Supernus Pharmaceuticals Targeted by Hive Ransomware Group

Supernus Pharmaceuticals, a biopharmaceutical company listed on NASDAQ under the ticker symbol SUPN, fell victim to a cyberattack orchestrated by the Hive ransomware group in mid-November 2021. Operating within the Healthcare Services sector, the company acknowledged the breach led to the exfiltration of a substantial volume of data from its network.

Despite the severity of the attack, Supernus Pharmaceuticals maintained that its operations continued without significant disruption. The company also indicated its decision against paying the ransom demanded by the attackers. Efforts were promptly initiated to recover the compromised files, alongside measures to fortify the security of its network and data repositories.

The Hive ransomware group took responsibility for the cyber intrusion, revealing that they had penetrated Supernus Pharmaceuticals’ network on November 14. They succeeded in exfiltrating approximately 1,268,906 files, which equates to 1.5 terabytes of data. The group also threatened to publish the stolen data online, criticizing the company for not disclosing the incident in their recent 8-K Form submission to the Securities and Exchange Commission (SEC).

The Healthcare Services sector, where Supernus Pharmaceuticals is a key player, is inherently sensitive and necessitates stringent cybersecurity protocols to safeguard critical patient and corporate information. Although specific vulnerabilities exploited by the attackers were not disclosed, the incident underscores the imperative for robust security measures to thwart such breaches.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.