HackerFeeds
All ransomware incidents
mareshki.com

Ransomware group thegentlemen hits Apteki Mareshki

MEDIUM
·Healthcare·BG·2026-09-14

Apteki Mareshki — a healthcare target operating in BG has been listed by the thegentlemen ransomware group on 2026-09-14. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationApteki Mareshki
Threat Group
thegentlemen
Summarymareshki.com Apteki Mareshki Bulgaria's largest pharmacy chain by outlet count — 294 pharmacies in 120+ towns (2025), built since 1991–92 by Veselin Mareshki, the Varna businessman, founder of the Volya party and former deputy speaker of parliament. Because Bulgarian law caps one company at 4 pharmacies, the chain runs as dozens of legal entities (owned by his mother Veska, relatives and their children) under the MARESHKI HOLD AD umbrella, franchising the brand from Varnafarma-M and supplied through his own wholesaler Farmnet AD (bought from Actavis in 2010; 2016 revenue 494.8M leva, top-4 drug distributor — together with Sofarma Trading, Phoenix and Sting handling ~80% of national distribution)
Date of Breach2026-09-14
Discovery Date2026-09-15
RegionBG
Target Domainmareshki.com
Business SectorHealthcare
Severity
MEDIUM

Claim by thegentlemen

mareshki.com Apteki Mareshki Bulgaria's largest pharmacy chain by outlet count — 294 pharmacies in 120+ towns (2025), built since 1991–92 by Veselin Mareshki, the Varna businessman, founder of the Volya party and former deputy speaker of parliament. Because Bulgarian law caps one company at 4 pharmacies, the chain runs as dozens of legal entities (owned by his mother Veska, relatives and their children) under the MARESHKI HOLD AD umbrella, franchising the brand from Varnafarma-M and supplied through his own wholesaler Farmnet AD (bought from Actavis in 2010; 2016 revenue 494.8M leva, top-4 drug distributor — together with Sofarma Trading, Phoenix and Sting handling ~80% of national distribution)

Posted by the thegentlemen threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.