LockBit claimed attack on Crinetics Pharmaceuticals and demanded $4 million

Organization
Crinetics Pharmaceuticals
Exploit
Ransomware
Industry
Pharmaceuticals

Crinetics Pharmaceuticals, a Nasdaq listed clinical stage drug developer based in San Diego, confirmed in March 2024 that it was investigating a cybersecurity incident after the LockBit ransomware operation added the company to its leak site.

Crinetics said it had identified suspicious activity in an employee's account and disabled it the same day. The company did not say what type of account it was, and no source identified how the attackers first got in. LockBit demanded $4 million and set a deadline of March 23, 2024.

Crinetics said it immediately activated its cybersecurity incident response process, opened an investigation, engaged third party cybersecurity experts and notified law enforcement. It implemented additional security measures and said the incident had not affected its operations or its discovery and study databases. The company did not confirm what data, if any, had been taken.

Negotiations did not succeed. Comparitech reported in May 2024 that LockBit published chat logs in which Crinetics offered $1.8 million and the group refused. In the same exchange, dated March 19, 2024, LockBit threatened to send files related to animal testing to the Humane Society of the United States and evidence of the stolen data to the SEC. The attack came weeks after an international law enforcement operation disrupted LockBit's infrastructure.

Sources