Ransomware group aurora hits Laboratorios Roemmers SAICF
Laboratorios Roemmers SAICF — a healthcare target operating in AR has been listed by the aurora ransomware group on 2026-10-01. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Laboratorios Roemmers SAICF |
|---|---|
| Threat Group | aurora |
| Summary | Laboratorios Roemmers SAICF — Argentina's #1 pharmaceutical company by revenue, with €1.669 billion in consolidated turnover, 6,890 employees, and 69 subsidiaries across 11 countries. The exposed material includes: 4,207 employees' national identity numbers (CUIL) — Argentina's equivalent of a Social Security Number — combined with dates of birth, health insurance affiliations, and employer identifiers. A complete identity-theft package for the entire Argentine workforce. Psychotropic drug dispensing records — employee-by-employee tracking of who receives clonazepam, alprazolam, diazepam, and other psychiatric medications from the company nursing station. The most sensitive category: mental health data. COVID-19 health tracking with clinical symptoms — individual symptom logs, doctor's notes, quarantine dates, and return-to-work clearances for employees who tested positive. Pre-employment medical exam results with full DNI (national identity document) numbers. <redacted> 82 GB of drug formulations — the complete pharmaceutical IP portfolio covering every product Roemmers manufactures, from API synthesis methods to finished-form specifications. 193 MB of API supplier qualification dossiers for 30+ international suppliers including CERBIOS (Switzerland), revealing the entire supply chain. 14 GB of internal drug pricing strategy and competitive intelligence |
| Date of Breach | 2026-10-01 |
| Discovery Date | 2026-10-01 |
| Region | AR |
| Target Domain | roemmers.com.ar |
| Business Sector | Healthcare |
| Severity | MEDIUM |
Claim by aurora
Laboratorios Roemmers SAICF — Argentina's #1 pharmaceutical company by revenue, with €1.669 billion in consolidated turnover, 6,890 employees, and 69 subsidiaries across 11 countries. The exposed material includes: 4,207 employees' national identity numbers (CUIL) — Argentina's equivalent of a Social Security Number — combined with dates of birth, health insurance affiliations, and employer identifiers. A complete identity-theft package for the entire Argentine workforce. Psychotropic drug dispensing records — employee-by-employee tracking of who receives clonazepam, alprazolam, diazepam, and other psychiatric medications from the company nursing station. The most sensitive category: mental health data. COVID-19 health tracking with clinical symptoms — individual symptom logs, doctor's notes, quarantine dates, and return-to-work clearances for employees who tested positive. Pre-employment medical exam results with full DNI (national identity document) numbers. <redacted> 82 GB of drug formulations — the complete pharmaceutical IP portfolio covering every product Roemmers manufactures, from API synthesis methods to finished-form specifications. 193 MB of API supplier qualification dossiers for 30+ international suppliers including CERBIOS (Switzerland), revealing the entire supply chain. 14 GB of internal drug pricing strategy and competitive intelligence
Posted by the aurora threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
roemmers.com.ar
Leak post (onion / Tor)
http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljovqbv7mxs6o2smgxixid.onion/blog/laboratorios-roemmers-saicf-e9b9df85
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

