Leak-site post naming paipharma.com, captured by ThreatCluster

paipharma.com

braincipher

Ransomware leak-site victim intelligence

Posted
Jun 30, 2026
Country
BR
Industry
Healthcare

Summary

Written by ThreatCluster from file listing, victim profile, leak post, screenshot

BrainCipher states that a paipharma.com data leak includes a published sample file: kxlw35vctxgbmwtz6474xwtkm2kywifg4efs6ixmvgdgbgi2uaurenid.onion (one onion file). The page identifies the victim domain as paipharma.com and is described by the group as "paipharma.com - Brain Cipher DataLeak." Publication status is listed as published.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Domains
paipharma.com

What was taken

Download: kxlw35vctxgbmwtz6474xwtkm2kywifg4efs6ixmvgdgbgi2uaurenid.onion If you think you are here by mistake, please contact us at [email protected]

File types seen
onion × 1
Sample files (1)
kxlw35vctxgbmwtz6474xwtkm2kywifg4efs6ixmvgdgbgi2uaurenid.onion

Leak-site images (2)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture
Logo of PAI Pharma, featuring the name in blue with a red circular accent.
onion leak page 10 KB

Negotiation