Zdrowit, a Polish pharmacy chain (PL) headquartered in Bytom and operating across 40+ cities, was targeted in a ransomware incident attributed to thegentlemen, with the claim involving disruption to operations. The threat is described as impacting the organization’s pharmacy network and supporting IT/data functions in #Poland
Incident Details
- Victim: Zdrowit
- Sector: Healthcare
- Country: PL
- Actor: thegentlemen
- Source:
- Discovered: 2026-09-05T18:30:11.287716+00:00
- Published: 2026-09-04T17:20:01+00:00
Information
- Zdrowit S.A. is a family-owned Polish pharmacy chain with 100% Polish capital, operating since 2004 and headquartered in Bytom, Silesia.
- The company employs over 1,000 people across more than 40 cities in southern and central Poland and aims to become the largest pharmacy network in the region.
- It is growing rapidly, with 2024 net sales revenue up 83.5%, although net profit margin fell 10.3% due to the costs of expansion.
- Zdrowit is structured as a holding company, with individual pharmacies operating as separate Sp. z o.o. entities under Zdrowit S.A.
- The company is registered under KRS 0000704305 with a share capital of 1,197,432.00 PLN.
- Its workforce is mainly made up of pharmacists and pharmacy technicians across multiple locations, supported by a small modern HQ team in Bytom covering data, IT, controlling, and marketing.
- A notable strength is its internship pipeline, offering a 2-year program for technicians and a 6-month program for pharmacists.
Disclaimer: This post is based on public claims made by the ransomware group "thegentlemen". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.