Drug research firm Inotiv reported to the U.S. Securities and Exchange Commission that it is still assessing the full financial and operational impact of a ransomware attack attributed to the Qilin group. The August incident resulted in the encryption of certain company systems and the alleged theft of data belonging to nearly 10,000 individuals. Inotiv has since restored access to affected IT systems and is in the process of notifying breach victims.
The company disclosed that it incurred approximately $2.48 million in costs related to the cyber incident and associated legal matters during the most recent quarter, with total costs for the fiscal year reaching nearly $5.93 million. The SEC filings did not specify the exact breakdown of these costs, and Inotiv continues to evaluate the ongoing repercussions of the attack.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
By December 2025, Inotiv said it was still assessing the full financial impact of the ransomware attack and had incurred significant costs. The company was also facing at least three class action lawsuits alleging it failed to adequately protect sensitive information.
After the attack, Inotiv restored its systems and began notifying affected individuals about the breach. The company said the incident affected 9,542 people, including employees, their families, and other associated individuals.
The Qilin ransomware group claimed responsibility for the attack, alleging it exfiltrated 176 GB of data from Inotiv. Reported stolen information included personal, financial, and other sensitive data, and the group allegedly published the data on its dark web leak site.
Inotiv experienced a ransomware attack in August 2025 that encrypted company systems, disrupted business operations, and led to a data breach. The incident affected the company and data tied to employees, family members, and others associated with Inotiv or its acquisitions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehipaajournal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.