Skip to content
Leak-site post naming Elixi International SA, captured by ThreatCluster

Elixi International SA

spacebears

Ransomware leak-site victim intelligence · EN

Views
15,528
Posted
Aug 10, 2026
Countdown
0 day 0 hour 0 minute
Country
Switzerland
Industry
Pharmaceutical distribution

Summary

Written by ThreatClusterfrom file listing, victim profile, leak post, screenshot

Spacebears claims it has exfiltrated SQL data, personal information of employees and clients, and financial documents from Elixi International SA, a Swiss pharmaceutical distributor. The leak post is published, with a countdown shown as 0 day 0 hour 0 minute. The leak page identifies the victim as Elixi International SA, headquartered in Chiasso, Switzerland.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Founded
2016
Domains
https://www.elixi-int.com/

What was taken

Elixi International SA is a Swiss pharmaceutical distributor (headquartered in Chiasso, founded in 2016) specializing in the global supply of both licensed and unlicensed medicinal products, including expanded access programs for patients. The company operates on a B2B model, serving hospitals, clinics, and pharmacies, ensuring quality through its Swissmedic license and robotic authenticity control systems, while prioritizing the rapid delivery of life-saving medicines. In addition to Switzerland, it has offices in Singapore.

Data categories
SQL DataPersonal information of employees and clientsFinancial documents

Leak-site images (2)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture
Logo featuring the word "ELIXI" in green and "International" in gray, with a stylized design element.
onion leak page49 KB