ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

ExecuPharm is the North American clinical operations business of Parexel FSP. 10+ years of Experience Meeting Client Needs 10,000+ Global Clinical Operational Specialists In Network 80% of Recruiting Staff with >15 Years of Experience Talent Acquisition, Deployment Rates, and Employee Retention above 90% Management Staff with Tangible Industry Experience Greater Than 95% Repeat Business Average Turnaround Time of 14 Days To Deploy Project Team Resources

ExecuPharm A.I CyberSecurity Scoring

ExecuPharm

Company Details

Linkedin ID:

parexelfsp

Employees number:

297

Number of followers:

42,482

NAICS:

3254

Industry Type:

Pharmaceutical Manufacturing

Homepage:

execupharm.com

IP Addresses:

0

Company ID:

EXE_2822297

Scan Status:

In-progress

AI scoreExecuPharm Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/parexelfsp.jpeg
ExecuPharm Pharmaceutical Manufacturing
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreExecuPharm Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/parexelfsp.jpeg
ExecuPharm Pharmaceutical Manufacturing
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

ExecuPharm Company CyberSecurity News & History

Past Incidents
2
Attack Types
2
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Oracle and Parexel: Parexel Data Breach InvestigationVulnerability25110/2025
Rankiteo Explanation :
Attack without any consequences

Description: **Parexel Reports Data Breach Impacting Sensitive Employee Information** Parexel, a global clinical research organization, disclosed a data breach affecting sensitive personal information stored in its Oracle OCI E-Business Suite (Oracle EBS) environment. On **October 4, 2025**, the company detected suspicious activity within the system, prompting an investigation. The breach, confirmed through forensic analysis, revealed that an unauthorized third party accessed employee-related data. Exposed information may include **names, Social Security numbers, dates of birth, financial account numbers, payment card details (excluding CVVs), and national ID numbers**, though the exact data varies by individual. On **December 17, 2025**, Parexel began notifying affected individuals via mail, detailing the compromised information and offering **24 months of complimentary credit monitoring services**. The breach notice was filed with the **Attorney General of Massachusetts**, where impacted residents were among the first to be informed. The full scope of affected individuals and additional details remain under review.

ExecuPharmRansomware8536/1994
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Clop ransomware leaked files stolen from U.S pharmaceutical company ExecuPharm after ransom negotiations failed. ExecuPharm is a contract research organization (CRO) that provides clinical research support services to companies from the pharmaceutical industry. It is one largest privately-owned global diversity suppliers of clinical development services since 1994. The attackers were able to steal almost 19,000 ExecuPharm and Parexel employees' emails, as well as further email correspondence including more than 80,000 emails. They also stole 163GB worth of financial, accounting, and employee documents, as well as SQL backups of the company's document management system.

Oracle and Parexel: Parexel Data Breach Investigation
Vulnerability
Severity: 25
Impact: 1
Seen: 10/2025
Blog:
Rankiteo Explanation
Attack without any consequences

Description: **Parexel Reports Data Breach Impacting Sensitive Employee Information** Parexel, a global clinical research organization, disclosed a data breach affecting sensitive personal information stored in its Oracle OCI E-Business Suite (Oracle EBS) environment. On **October 4, 2025**, the company detected suspicious activity within the system, prompting an investigation. The breach, confirmed through forensic analysis, revealed that an unauthorized third party accessed employee-related data. Exposed information may include **names, Social Security numbers, dates of birth, financial account numbers, payment card details (excluding CVVs), and national ID numbers**, though the exact data varies by individual. On **December 17, 2025**, Parexel began notifying affected individuals via mail, detailing the compromised information and offering **24 months of complimentary credit monitoring services**. The breach notice was filed with the **Attorney General of Massachusetts**, where impacted residents were among the first to be informed. The full scope of affected individuals and additional details remain under review.

ExecuPharm
Ransomware
Severity: 85
Impact: 3
Seen: 6/1994
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Clop ransomware leaked files stolen from U.S pharmaceutical company ExecuPharm after ransom negotiations failed. ExecuPharm is a contract research organization (CRO) that provides clinical research support services to companies from the pharmaceutical industry. It is one largest privately-owned global diversity suppliers of clinical development services since 1994. The attackers were able to steal almost 19,000 ExecuPharm and Parexel employees' emails, as well as further email correspondence including more than 80,000 emails. They also stole 163GB worth of financial, accounting, and employee documents, as well as SQL backups of the company's document management system.

Ailogo

ExecuPharm Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for ExecuPharm

Incidents vs Pharmaceutical Manufacturing Industry Average (This Year)

No incidents recorded for ExecuPharm in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for ExecuPharm in 2025.

Incident Types ExecuPharm vs Pharmaceutical Manufacturing Industry Avg (This Year)

No incidents recorded for ExecuPharm in 2025.

Incident History — ExecuPharm (X = Date, Y = Severity)

ExecuPharm cyber incidents detection timeline including parent company and subsidiaries

ExecuPharm Company Subsidiaries

SubsidiaryImage

ExecuPharm is the North American clinical operations business of Parexel FSP. 10+ years of Experience Meeting Client Needs 10,000+ Global Clinical Operational Specialists In Network 80% of Recruiting Staff with >15 Years of Experience Talent Acquisition, Deployment Rates, and Employee Retention above 90% Management Staff with Tangible Industry Experience Greater Than 95% Repeat Business Average Turnaround Time of 14 Days To Deploy Project Team Resources

Loading...
similarCompanies

ExecuPharm Similar Companies

Zydus Group

The Zydus Group with an overarching purpose of empowering people with freedom to live healthier and more fulfilled lives, is an innovative, global life-sciences company that discovers, develops, manufactures, and markets a broad range of healthcare therapies. The group employs over 27000 people worl

Alkem Laboratories Ltd.

A single idea, which sprouts from a human mind, contains the potential to create marvels that can influence generations. It can redefine rules, it can transform the world. Back in the year 1973, a team of individuals came with such an idea – The idea called Alkem. It was highly potent and resilient,

Glenmark Pharmaceuticals

Glenmark Pharmaceuticals Limited is a research-led, global organization committed to enriching lives. Innovation is deeply embedded in Glenmark’s culture; it is how we differentiate ourselves in our key markets and create greater value for our stakeholders. In our journey of innovation over the pa

Merck KGaA, Darmstadt, Germany

We are Merck KGaA, Darmstadt, Germany and its global affiliates. We are a leading global science and technology company headquartered in Germany. We are curious explorers, courageous pioneers, and ingenious inventors. Our colleagues across the globe love innovating with science and technology to e

EMS is the leading pharmaceutical company in Brazil. Established since 45 years and with 100% national capital, the company has two industrial plants strategically placed in São Bernardo do Campo and Hortolândia, in the state of São Paulo. With a work based on daring, simplicity, excellence and res

Dr. Reddy's Laboratories

Established in 1984, we are a global pharmaceutical company headquartered in Hyderabad, India. Driven by our purpose of ‘Good Health Can’t Wait’, we work to provide access to affordable and innovative medicines. We offer a portfolio of products and services including APIs, generics, branded generics

Viatris

Viatris Inc. (NASDAQ: VTRS) is a global healthcare company uniquely positioned to bridge the traditional divide between generics and brands, combining the best of both to more holistically address healthcare needs globally. With a mission to empower people worldwide to live healthier at every stage

Lupin

Lupin Limited is a global pharmaceutical leader headquartered in Mumbai, India, with products distributed in over 100 markets. Lupin specializes in pharmaceutical products, including branded and generic formulations, complex generics, biotechnology products, and active pharmaceutical ingredients. Tr

CVS Pharmacy

CVS Pharmacy is America’s leading retail pharmacy with more than 9,600 locations nationwide. For more than 50 years, CVS Pharmacy has offered customers the products and services they need to stay on their path to better health. In addition to our pharmacies, our stores feature on-trend beauty depart

newsone

ExecuPharm CyberSecurity News

November 08, 2024 03:28 AM
Cybercriminals Leak ExecuPharm Internal Documents After Ransomware Attack

A successful ransomware attack was deployed on March 13 against ExecuPharm, a subsidiary of the US Biopharmaceutical giant Parexel.

September 20, 2022 07:00 AM
Data breach, but no identity theft: Can employee still sue?

An important new ruling says an employee can sue her employer even though a data breach did not lead to identity theft or fraud.

February 25, 2021 08:00 AM
Steris Touted as Latest Accellion Hack Victim

Data belonging to a client of recently hacked California-based private cloud solutions company Accellion is being advertised for sale online by cyber-criminals.

November 02, 2020 08:00 AM
Maze, a notorious ransomware group, says it’s shutting down

One of the most active and notorious data-stealing ransomware groups, Maze, says it is “officially closed.”

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

ExecuPharm CyberSecurity History Information

Official Website of ExecuPharm

The official website of ExecuPharm is http://www.execupharm.com.

ExecuPharm’s AI-Generated Cybersecurity Score

According to Rankiteo, ExecuPharm’s AI-generated cybersecurity score is 757, reflecting their Fair security posture.

How many security badges does ExecuPharm’ have ?

According to Rankiteo, ExecuPharm currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does ExecuPharm have SOC 2 Type 1 certification ?

According to Rankiteo, ExecuPharm is not certified under SOC 2 Type 1.

Does ExecuPharm have SOC 2 Type 2 certification ?

According to Rankiteo, ExecuPharm does not hold a SOC 2 Type 2 certification.

Does ExecuPharm comply with GDPR ?

According to Rankiteo, ExecuPharm is not listed as GDPR compliant.

Does ExecuPharm have PCI DSS certification ?

According to Rankiteo, ExecuPharm does not currently maintain PCI DSS compliance.

Does ExecuPharm comply with HIPAA ?

According to Rankiteo, ExecuPharm is not compliant with HIPAA regulations.

Does ExecuPharm have ISO 27001 certification ?

According to Rankiteo,ExecuPharm is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of ExecuPharm

ExecuPharm operates primarily in the Pharmaceutical Manufacturing industry.

Number of Employees at ExecuPharm

ExecuPharm employs approximately 297 people worldwide.

Subsidiaries Owned by ExecuPharm

ExecuPharm presently has no subsidiaries across any sectors.

ExecuPharm’s LinkedIn Followers

ExecuPharm’s official LinkedIn profile has approximately 42,482 followers.

NAICS Classification of ExecuPharm

ExecuPharm is classified under the NAICS code 3254, which corresponds to Pharmaceutical and Medicine Manufacturing.

ExecuPharm’s Presence on Crunchbase

No, ExecuPharm does not have a profile on Crunchbase.

ExecuPharm’s Presence on LinkedIn

Yes, ExecuPharm maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/parexelfsp.

Cybersecurity Incidents Involving ExecuPharm

As of December 22, 2025, Rankiteo reports that ExecuPharm has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

ExecuPharm has an estimated 5,459 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at ExecuPharm ?

Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability and Ransomware.

How does ExecuPharm detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with data breach notification letters mailed to impacted individuals..

Incident Details

Can you provide details on each incident ?

Incident : Ransomware

Title: Clop Ransomware Attack on ExecuPharm

Description: Clop ransomware leaked files stolen from U.S pharmaceutical company ExecuPharm after ransom negotiations failed. ExecuPharm is a contract research organization (CRO) that provides clinical research support services to companies from the pharmaceutical industry. It is one largest privately-owned global diversity suppliers of clinical development services since 1994. The attackers were able to steal almost 19,000 ExecuPharm and Parexel employees' emails, as well as further email correspondence including more than 80,000 emails. They also stole 163GB worth of financial, accounting, and employee documents, as well as SQL backups of the company's document management system.

Type: Ransomware

Threat Actor: Clop Ransomware

Motivation: Financial

Incident : Data Breach

Title: Parexel Data Breach Involving Sensitive Personal Information

Description: Parexel reported a data breach where sensitive personal identifiable information in its Oracle OCI E-Business Suite environment may have been compromised. An unauthorized third party accessed the data, leading to the exposure of personal and financial information of employees.

Date Detected: 2025-10-04

Date Publicly Disclosed: 2025-12-17

Type: Data Breach

Threat Actor: Unauthorized third party

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Vulnerability.

Impact of the Incidents

What was the impact of each incident ?

Incident : Ransomware EXE2046291222

Data Compromised: Employee emails, Email correspondence, Financial documents, Accounting documents, Employee documents, Sql backups of document management system

Incident : Data Breach ORAPAR1766015901

Data Compromised: Sensitive personal identifiable information

Systems Affected: Oracle OCI E-Business Suite (Oracle EBS)

Identity Theft Risk: High

Payment Information Risk: High

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Employee Emails, Email Correspondence, Financial Documents, Accounting Documents, Employee Documents, Sql Backups Of Document Management System, , Name, Social Security Number, Date Of Birth, Financial Account Number, Payment Card Number (Without Cvv), National Id Number and .

Which entities were affected by each incident ?

Incident : Ransomware EXE2046291222

Entity Name: ExecuPharm

Entity Type: Contract Research Organization

Industry: Pharmaceutical

Location: United States

Incident : Data Breach ORAPAR1766015901

Entity Name: Parexel

Entity Type: Company

Industry: Clinical Research, Pharmaceutical

Customers Affected: Employees

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach ORAPAR1766015901

Communication Strategy: Data breach notification letters mailed to impacted individuals

Data Breach Information

What type of data was compromised in each breach ?

Incident : Ransomware EXE2046291222

Type of Data Compromised: Employee emails, Email correspondence, Financial documents, Accounting documents, Employee documents, Sql backups of document management system

Number of Records Exposed: 19,000 employee emails, 80,000 email correspondence

File Types Exposed: EmailsFinancial documentsAccounting documentsEmployee documentsSQL backups

Incident : Data Breach ORAPAR1766015901

Type of Data Compromised: Name, Social security number, Date of birth, Financial account number, Payment card number (without cvv), National id number

Sensitivity of Data: High

Personally Identifiable Information: Yes

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Ransomware EXE2046291222

Ransomware Strain: Clop

Data Exfiltration: True

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Breach ORAPAR1766015901

Regulatory Notifications: Reported to the Attorney General of the Commonwealth of Massachusetts

References

Where can I find more information about each incident ?

Incident : Data Breach ORAPAR1766015901

Source: Attorney General of the Commonwealth of Massachusetts

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Attorney General of the Commonwealth of Massachusetts.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach ORAPAR1766015901

Investigation Status: Completed

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Data breach notification letters mailed to impacted individuals.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Breach ORAPAR1766015901

Customer Advisories: 24 months of complimentary credit monitoring services provided to affected individuals

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was 24 months of complimentary credit monitoring services provided to affected individuals.

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident were an Clop Ransomware and Unauthorized third party.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2025-10-04.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-12-17.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Employee emails, Email correspondence, Financial documents, Accounting documents, Employee documents, SQL backups of document management system, and Sensitive personal identifiable information.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Accounting documents, Sensitive personal identifiable information, Email correspondence, SQL backups of document management system, Employee documents, Employee emails and Financial documents.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 99.0K.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Attorney General of the Commonwealth of Massachusetts.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Completed.

Stakeholder and Customer Advisories

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an 24 months of complimentary credit monitoring services provided to affected individuals.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 9.0
Severity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=parexelfsp' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge