Biopharmaceutical company Diater has been listed on the dark-web leak site of the DeadLock ransomware group, in an incident that could expose highly sensitive information tied to patients and healthcare professionals. Reporting indicates the attackers are using a double-extortion model, combining data theft with encryption, and that records retained by Diater for up to 10 years may be at risk of public release.
The attackers reportedly claim to have stolen directories containing user folders, documents, QM files, and material linked to EDICOM, although the ransom demand, intrusion date, and full scope of exfiltration have not been disclosed. DeadLock, a ransomware operation first observed in mid-2025 and associated with Russian-origin actors, is known for appending the .dlock extension to encrypted files, adding to concerns that the Diater incident could affect both operational systems and long-term medical data confidentiality.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
The DeadLock ransomware group was first detected in mid-2025. Reporting describes it as a Russian-linked operation that uses double extortion tactics.
Biopharmaceutical company Diater appeared on the DeadLock ransomware group's dark web victim list. The group claimed to have stolen directories containing user folders, documents, QM files, and EDICOM-related material, raising concerns about exposure of sensitive patient and healthcare professional data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.