Embargo ransomware group claimed attack on American Associated Pharmacies

Organization
American Associated Pharmacies
Exploit
Ransomware
Industry
Pharmacy

On November 13, 2024, the Embargo ransomware operation added American Associated Pharmacies to its dark web leak site. AAP is a cooperative headquartered in Scottsboro, Alabama that represents more than 2,000 independent pharmacies across the United States and handles wholesale distribution through its Associated Pharmacies Inc. subsidiary.

Embargo claimed it had exfiltrated about 1.5 terabytes of data, listed on the leak site as 1.469 TB, before encrypting AAP systems. The group also asserted that AAP had already paid $1.3 million for decryption keys and was being asked for a further $1.3 million to stop the stolen files from being published, with a deadline of November 19, 2024. Those figures came only from the attackers and were not independently verified.

AAP did not publicly confirm the attack or the alleged payments. Its response was visible mainly through notices posted on its own sites, which said limited ordering capability for API Warehouse had been restored at APIRx.com and that all passwords for accounts at APIRx.com and RxAAP.com had been reset.

Embargo is a ransomware-as-a-service operation first observed in the spring of 2024 that uses double extortion, stealing data before encryption and charging separately for decryption and for suppression of the stolen files. HIPAA Journal noted that Embargo also listed Memorial Hospital and Manor in Georgia, attacked on November 1, 2024, and Weiser Memorial Hospital in Idaho. Comparitech reported that the Idaho attack dated to early September 2024, before the AAP listing. As of the reporting date, AAP had issued no breach notification and it was not clear whether patient or pharmacy records were among the files taken.

Sources