Incident Score: Analysis & Impact (KOPGLE1777473227)
The details regarding individual company incidents & reports gives you full view from every side.
Rankiteo Score Impact Analysis
Key Highlights From The Incident Analysis
- Timeline of Glenmark Pharmaceuticals's Ransomware and lateral movement inside company's environment.
- Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
- How Rankiteo’s incident engine converts technical details into a normalized incident score.
- How this cyber incident impacts Glenmark Pharmaceuticals Rankiteo cyber scoring and cyber rating.
- Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.
Full Incident Analysis Transcript
In this Rankiteo incident briefing, we review the Glenmark Pharmaceuticals breach identified under incident ID KOPGLE1777473227.
The analysis begins with a detailed overview of Glenmark Pharmaceuticals's information like the linkedin page: https://www.linkedin.com/company/glenmark-pharmaceuticals, the number of followers: 1091425, the industry type: Pharmaceutical Manufacturing and the number of employees: 14777 employees
After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 774 and after the incident was 636 with a difference of -138 which is could be a good indicator of the severity and impact of the incident.
In the next step of the video, we will analyze in more details the incident and the impact it had on Glenmark Pharmaceuticals and their customers.
University of Mississippi Medical Center recently reported "Ransomware Surge in Healthcare: Q1 2026 Attacks Highlight Persistent Threats", a noteworthy cybersecurity incident.
The first quarter of 2026 saw 201 ransomware attacks targeting the healthcare sector, with 120 directed at hospitals, clinics, and providers, and 81 at related businesses including pharmaceutical manufacturers, medical billing firms, and healthcare tech companies.
The disruption is felt across the environment, affecting Healthcare systems, billing systems, medical devices, recruitment platforms, pharmaceutical data, and exposing 237,747 records breached in confirmed attacks (providers); 29 TB allegedly stolen from businesses, 13 TB from providers, with nearly 237,747 (confirmed providers); 131,700 (Nippon Medical School); 92,000 (Hospital Caribbean Medical Center) records at risk.
Formal response steps have not been shared publicly yet.
The case underscores how teams are taking away lessons such as Healthcare sector remains a prime target due to high-value data and operational vulnerabilities. Disparities in reporting due to national disclosure laws may skew attack figures.
Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.
The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.
MITRE ATT&CK® Correlation Analysis
Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Exploit Public-Facing Application (T1190) with moderate confidence (60%), supported by evidence indicating sector remains a prime target due to...operational vulnerabilities, External Remote Services (T1133) with moderate confidence (50%), supported by evidence indicating billing and shipment delays after a Payouts King attack, and Valid Accounts (T1078) with moderate to high confidence (70%), supported by evidence indicating high-value data and operational vulnerabilities suggest account abuse. Under the Execution tactic, the analysis identified User Execution: Malicious File (T1204.002) with moderate to high confidence (80%), supported by evidence indicating ransomware strains encrypted data; likely user-triggered execution and Command and Scripting Interpreter (T1059) with moderate confidence (60%), supported by evidence indicating ransomware attacks often use scripts for propagation. Under the Persistence tactic, the analysis identified Account Manipulation (T1098) with moderate confidence (50%), supported by evidence indicating high-value data suggests prolonged access via compromised accounts. Under the Privilege Escalation tactic, the analysis identified Exploitation for Privilege Escalation (T1068) with moderate confidence (60%), supported by evidence indicating operational vulnerabilities imply privilege escalation for data access. Under the Defense Evasion tactic, the analysis identified Obfuscated Files or Information (T1027) with moderate to high confidence (80%), supported by evidence indicating ransomware strains (e.g., Qilin, LockBit) use encryption/obfuscation and Impair Defenses: Disable or Modify Tools (T1562.001) with moderate to high confidence (70%), supported by evidence indicating systems crippled for weeks; likely defense impairment. Under the Credential Access tactic, the analysis identified OS Credential Dumping (T1003) with moderate to high confidence (70%), supported by evidence indicating 237,747 records breached; likely credential harvesting and Credentials from Password Stores (T1555) with moderate confidence (60%), supported by evidence indicating high-value data access suggests credential theft. Under the Discovery tactic, the analysis identified Account Discovery (T1087) with moderate to high confidence (70%), supported by evidence indicating targeted attacks on billing, medical devices imply account discovery and File and Directory Discovery (T1083) with moderate to high confidence (80%), supported by evidence indicating 29 TB of data exfiltrated; file discovery required. Under the Lateral Movement tactic, the analysis identified Exploitation of Remote Services (T1210) with moderate to high confidence (70%), supported by evidence indicating clinic closures, billing delays suggest lateral movement and Remote Services: Remote Desktop Protocol (T1021.001) with moderate confidence (60%), supported by evidence indicating healthcare systems often use RDP; likely exploited. Under the Collection tactic, the analysis identified Data from Local System (T1005) with high confidence (90%), supported by evidence indicating 29 TB of data allegedly stolen from businesses and Data from Network Shared Drive (T1039) with moderate to high confidence (80%), supported by evidence indicating 13 TB stolen from providers; shared drives likely targeted. Under the Command and Control tactic, the analysis identified Application Layer Protocol (T1071) with moderate to high confidence (80%), supported by evidence indicating ransomware strains require C2 for encryption/exfiltration and Ingress Tool Transfer (T1105) with moderate to high confidence (70%), supported by evidence indicating malicious payloads delivered for ransomware execution. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with high confidence (90%), supported by evidence indicating 29 TB of data allegedly stolen from businesses and Exfiltration Over Web Service (T1567) with moderate to high confidence (70%), supported by evidence indicating data exfiltration via web services common in ransomware. Under the Impact tactic, the analysis identified Data Encrypted for Impact (T1486) with high confidence (90%), supported by evidence indicating ransomware strains encrypted data; primary impact tactic, Inhibit System Recovery (T1490) with moderate to high confidence (80%), supported by evidence indicating systems crippled for weeks; recovery inhibited, and Service Stop (T1489) with moderate to high confidence (70%), supported by evidence indicating clinic closures, billing delays imply service disruption. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.
Sources & References
- Glenmark Pharmaceuticals Rankiteo Cyber Incident Details: https://www.rankiteo.com/company/glenmark-pharmaceuticals/incident/KOPGLE1777473227
- Glenmark Pharmaceuticals CyberSecurity Rating page: https://www.rankiteo.com/company/glenmark-pharmaceuticals
- Glenmark Pharmaceuticals Rankiteo Cyber Incident Blog Article: https://blog.rankiteo.com/kopgle1777473227-kopran-ltd-glenmark-pharmaceuticals-ransomware-april-2026/
- Glenmark Pharmaceuticals CyberSecurity Score History: https://www.rankiteo.com/company/glenmark-pharmaceuticals/history
- Glenmark Pharmaceuticals CyberSecurity Incident Source: https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/
- Rankiteo A.I CyberSecurity Rating methodology: https://www.rankiteo.com/Images/rankiteo_algo.pdf
- Rankiteo TPRM Scoring methodology: https://static.rankiteo.com/model/rankiteo_tprm_methodology.pdf