Octapharma

Octapharma

The BlackSuit ransomware gang targeted Octapharma, a blood plasma collection organization, leading to the temporary closure of nearly 200 blood plasma collection centers across the U.S. This disruption severely impacted the healthcare system by limiting the availability of critical blood plasma supplies, which are essential for medical treatments. The attack underscored the vulnerability of healthcare infrastructure to cyber threats and highlighted the broader implications of ransomware on public health and safety.

Source: https://therecord.media/us-confirms-blacksuit-takedown

TPRM report: https://www.rankiteo.com/company/octapharma-plasma-inc.

"id": "oct410080825",
"linkid": "octapharma-plasma-inc.",
"type": "Ransomware",
"date": "8/2025",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Public Sector',
                        'location': 'Dallas, Texas',
                        'name': 'City of Dallas',
                        'type': 'Government'},
                       {'industry': 'Media',
                        'location': 'Japan',
                        'name': 'Kadokawa',
                        'type': 'Company'},
                       {'industry': 'Entertainment',
                        'location': 'Tampa Bay, Florida',
                        'name': 'Tampa Bay Zoo',
                        'type': 'Organization'},
                       {'industry': 'Healthcare',
                        'name': 'Octapharma',
                        'type': 'Company'}],
 'description': 'U.S. law enforcement agencies dismantled critical '
                'infrastructure used by the BlackSuit ransomware gang, seizing '
                'servers, domains, and digital assets used to deploy '
                'ransomware, extort victims, and launder proceeds.',
 'impact': {'financial_loss': '$370 million in ransom payments',
            'operational_impact': 'Temporary closure of almost 200 blood '
                                  'plasma collection centers'},
 'investigation_status': 'Ongoing analysis of secured data',
 'motivation': 'Financial gain through ransom payments',
 'ransomware': {'data_encryption': True,
                'ransom_demanded': '$60 million in some cases',
                'ransom_paid': '$370 million in total',
                'ransomware_strain': 'BlackSuit'},
 'references': [{'source': 'U.S. Department of Justice'},
                {'source': 'German Law Enforcement'},
                {'source': 'Cisco Talos'}],
 'response': {'containment_measures': 'Seizure of servers, domains, and '
                                      'digital assets',
              'incident_response_plan_activated': 'Operation Checkmate',
              'law_enforcement_notified': True,
              'third_party_assistance': 'Bitdefender'},
 'threat_actor': 'BlackSuit Ransomware Gang',
 'title': 'Takedown of BlackSuit Ransomware Infrastructure',
 'type': 'Ransomware Takedown'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.