
California-based Crinetics Pharmaceuticals has admitted to experiencing a cyber security incident not long after the LockBit ransomware group listed the company as a victim on its data leak site.
Headquartered in San Diego, California, Crinetics Pharmaceuticals develops therapies for people with endocrine diseases and endocrine-related tumours.
On March 18, the infamous LockBit ransomware group listed the company as a victim on its data leak site. The group said it infiltrated the pharma company’s internal network and stole sensitive and confidential data and that it had demanded the company to pay a ransom of $4 million within five days to get its data back.
NASDAQ listed Crinetics Pharmaceuticals is being extorted by LockBit
— Dominic Alvieri (@AlvieriD) March 18, 2024
“Those responsible for the exfiltration of data belonging to this victim have no association…with the LockBit Group.” pic.twitter.com/bdJrfTH28V
In another post on its dark web channel, the group extended the deadline till March 26 and gave the company an option to increase the deadline for 24 hours by paying $1,000. It also gave the option of “destroy all information” by paying $700,000 or download the stolen data anytime by paying the same amount.
#CyberAttack Unexpected Update ⚠️
— HackManac (@H4ckManac) March 20, 2024
LockBit vs Crinetics:
✴️Negotiations with Crinetics failed due to their public statement and "unscrupulous behavior."
✴️Crinetics violated an agreement by talking to the media about a data breach.
✴️LockBit is unhappy with the settlement… pic.twitter.com/0xSCOl2TRL
LockBit also shared snippets of the stolen data to support its claims of infiltrating Crinetics Pharmaceuticals internal network.
Acknowledging the ransomware group’s claims, a Crinetics Pharmaceuticals’ spokesperson said that the company has indeed identified “suspicious activity in an employee’s account.”
In a statement shared with the media, the spokesperson said, “Crinetics recently identified suspicious activity in an employee’s account and disabled it on the same day. Crinetics immediately activated its cybersecurity incident response process, initiated an investigation, engaged third-party cybersecurity experts to assist, and notified law enforcement. The company also implemented additional company-wide security measures and contained the incident.”
The spokesperson added that the cyber attack did not affect the company’s ability to continue daily operations.
“This incident has not affected the company’s operations or its discovery and study databases. Crinetics takes all security-related matters seriously and we are committed to conducting a full investigation, which is currently ongoing, and will provide any legal notifications required,” they added.
The U.S. healthcare industry has suffered frequent cyber attacks over the past year with leading healthcare operators facing long outages or encryption events emanating from ransomware attacks. In February, prominent pharmaceutical distributor Cencora disclosed a cyber security incident that forced the company to take immediate containment measures.
In September, Kansas-based pharmaceutical products and clinical services provider Amerita also experienced a cyber attack that compromised the sensitive personal information of almost 220,000 individuals. The compromised information included names, addresses, certain patient information including their medical history, diagnosis, medications, and health insurance information.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543