Ransomware shut Octapharma Plasma donation centers across 35 US states
- Organization
- Octapharma Plasma
- Exploit
- Ransomware
- Industry
- Healthcare
Octapharma Plasma, the US arm of the Swiss biopharmaceutical group Octapharma, detected unauthorized activity on its network on April 17, 2024 and responded by taking systems offline. Because staff could not reach the IT systems used to screen donors and process collections, the company closed its donation centers the same day.
Reported center counts varied. The Record put the figure at more than 180 sites, while HIPAA Journal reported roughly 190 locations across 35 states, and The Register described more than 150 closures in an April 18 report. Centers began reopening on April 22 with reduced hours, and the company advised donors to call ahead.
The BlackSuit ransomware group, a rebrand of the Royal operation, claimed the intrusion on April 24 and said it had taken business and laboratory data along with information on living and deceased donors. Octapharma said it had begun an investigation with outside experts, and it reported the incident to the FBI.
The company later confirmed that names, dates of birth, Social Security numbers, health and donor eligibility information and some employee records were involved. Notification letters went out in September 2024, and Octapharma agreed to a $2.55 million settlement of the resulting consolidated class action in 2025.