On March 3, 2026, an AiLock ransomware attack on Lewis Drug, a US-based pharmacy chain, was reported. The attackers claimed to have infiltrated systems and extracted "valuable data," threatening to publish it if not contacted. As of current reports, there is no confirmation from Lewis Drug or regulatory bodies regarding the incident.
The specific types of data exposed, such as SSN, medical, or financial information, have not been detailed, though as a pharmacy, sensitive health data exposure is possible but unconfirmed. The number of affected individuals has not been specified, and no reports confirm any data exfiltration volume or notifications issued. There is no indication that this was a vendor or third-party breach.
Details can emerge later as investigations progress, and official notifications may be delayed.