[INCRANSOM] – Ransomware Victim: Jordan Drug
![[INCRANSOM] - Ransomware Victim: Jordan Drug 1 image](https://www.redpacketsecurity.com/wp-content/uploads/2024/09/image.png)
Ransomware Group: INCRANSOM
VICTIM NAME: Jordan Drug
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating to the content of the files should be directed at the attackers directly, not RedPacket Security. This blog is simply posting an editorial news post informing that a company has fallen victim to a ransomware attack. RedPacket Security is in no way affiliated or aligned with any ransomware threat actors or groups and will not host infringing content. The information on this page is fully automated and redacted whilst being scraped directly from the INCRANSOM Onion Dark Web Tor Blog page.
AI Generated Summary of the Ransomware Leak Page
The ransomware leak page pertains to Jordan Drug, Inc., a healthcare provider operating multiple independent pharmacies and medical supply centers across eastern Kentucky, United States. The attack was discovered on May 30, 2025, with the breach being publicly disclosed shortly afterward. The leak appears to include compromised data related to the organization’s operations, including details about its various pharmacy locations and accompanying medical services. The presence of a screenshot suggests the release of internal documentation or ransom notes, indicating active data exfiltration and extortion efforts. While specific files or sensitive details are not explicitly listed, the leak underscores a significant breach within a healthcare infrastructure vulnerable to cyber threats.
The compromised data may contain information related to medical services, operational records, and internal communications, although personally identifiable or sensitive patient data is not explicitly disclosed. The leak page is part of a larger ransomware group’s campaign targeting healthcare organizations, emphasizing the persistent cybersecurity risks facing medical providers. The site includes a screenshot of the potential victim’s internal system, highlighting the extent of data exposure. No direct download links are provided publicly, but the nature of the leak indicates that attacker exfiltration likely involved substantial confidential healthcare and business information. The attack underscores the importance of robust cybersecurity measures for healthcare providers against evolving ransomware threats.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.