Ransomware

London Drugs ransomware attack (LockBit)

📅 2024-04-28 🏢 London Drugs (Canadian pharmacy/retail chain) 🦠 LockBit ransomware
Primary Source ↗

Incident Details

LockBit claimed the attack on London Drugs and demanded $25 million ransom (reportedly offered $8 million). All 79 Western Canada stores closed 28 April–7 May 2024. Corporate head office data exfiltrated including internal employee records, immigration applications, sexual harassment complaints, and termination letters. No patient or customer databases confirmed compromised. London Drugs refused to pay. LockBit published the data. 24 months of complimentary credit monitoring offered to all current employees. Attack came roughly 3 months after law enforcement disrupted LockBit’s infrastructure in Operation Cronos (Feb 2024).

Technical Details

Initial Attack Vector
unknown
Vendor / Product
London Drugs (Canadian pharmacy/retail chain)
Malware Family
LockBit ransomware

Timeline

  1. 2024-04-28 Breach occurred
  2. 2024-05-07 Publicly disclosed
  3. 2024-05-27 Customers notified