Farmatodo is listed as a victim of the Akira ransomware on its leak site
The Venezuelan pharmacy and convenience store chain Farmatodo (farmatodo.com) was listed as a victim by the Akira ransomware group on January 31, 2025. The entry was part of Akira’s mass publication titled “Taking Stock of 2024 | Part 1,” in which the group listed Farmatodo alongside dozens of other companies allegedly compromised. The list is categorized under Venezuela and the consumer services sector. There has been no public confirmation from the company, nor are there any official figures regarding the data exposed.
Overview
Missing evidence
Impact details
Akira included Farmatodo in its list of leak sites and trackers. Public evidence supports the claim that this is a case of ransomware or extortion and the context of third-party credentials, but no official statement, validated leaked files, evidence of encryption, or service disruption has been found.
Classification & severity
- Category
- Malicious code
- Subtype
- Ransomware
- Confidence
- Medium
Ransomware.live supports Akira’s claim against Farmatodo regarding the ransomware attack and data breach. Public evidence does not confirm the encryption, the service disruption, or the authenticity of the data.
Severity assessment
Medium- Information impact
- Suspected
- Affected scope
- Organization-wide
- Critical service
- Potential
- Public confidence
- Limited
- Recoverability
- Extended
Akira’s allegation against a major private pharmacy and retail company could be significant if proven true, but the exposure of data, the encryption, and the impact on service remain unconfirmed.
Timeline
The Akira ransomware group published Farmatodo (farmatodo.com) on its leak site as part of the massive release titled “Taking Stock of 2024 | Part 1,” categorized under Venezuela and the consumer services sector.
The Ransomware.live tracker indexes the Farmatodo entry, recording the date of discovery and the attack on January 31, 2025.