Ransom! Zdrowit (SEP-2026)
Zdrowit, a Polish pharmacy chain (PL) headquartered in Bytom and operating across 40+ cities, was targeted in a ransomware incident attributed to thegentlemen, with the claim involving disruption to operations. The threat is described as impacting the organization’s pharmacy network and supporting IT/data functions in #Poland

Incident Details

  • Victim: Zdrowit
  • Sector: Healthcare
  • Country: PL
  • Actor: thegentlemen
  • Source:
  • Discovered: 2026-09-05T18:30:11.287716+00:00
  • Published: 2026-09-04T17:20:01+00:00

Information

  • Zdrowit S.A. is a family-owned Polish pharmacy chain with 100% Polish capital, operating since 2004 and headquartered in Bytom, Silesia.
  • The company employs over 1,000 people across more than 40 cities in southern and central Poland and aims to become the largest pharmacy network in the region.
  • It is growing rapidly, with 2024 net sales revenue up 83.5%, although net profit margin fell 10.3% due to the costs of expansion.
  • Zdrowit is structured as a holding company, with individual pharmacies operating as separate Sp. z o.o. entities under Zdrowit S.A.
  • The company is registered under KRS 0000704305 with a share capital of 1,197,432.00 PLN.
  • Its workforce is mainly made up of pharmacists and pharmacy technicians across multiple locations, supported by a small modern HQ team in Bytom covering data, IT, controlling, and marketing.
  • A notable strength is its internship pipeline, offering a 2-year program for technicians and a 6-month program for pharmacists.

Disclaimer: This post is based on public claims made by the ransomware group "thegentlemen". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live