Desk live·
ForensicPost
Breaches/Pharma/File 25-0819b

Inotiv Says August Attack Exposed Employee and Partner Data

Inotiv confirmed that an August 2025 cyberattack exposed company data including employee and partner information. A contract research organisation holds other companies’ pipelines.

Constructed geometry · not a chart of case data
TargetInotiv
ActorUnattributed
D. Kennedy12 min readConfidence: medium2 sources reviewed

Inotiv, a drug research company, confirmed that a cyberattack in August 2025 exposed data including employee and partner information, while stating that the full operational and financial impact was still being evaluated.

Partner Data Means Somebody Else’s Research Programme

A contract research organisation runs studies on behalf of pharmaceutical and biotechnology companies. Its records describe what those companies are developing, at what stage, with what results.

This desk filed at 25-1204 that a manufacturer can lose the accumulated engineering knowledge constituting its competitive position and have no disclosure obligation, because the material belongs to no individual.

Pharmaceutical research is that argument with the highest stakes in this corpus. A compound in development represents a decade of investment, and its status is material information about a listed company that is not yet public.

And The Affected Sponsors Were Not Breached

This is the concentration structure at 25-1219b, where the organisation holding the largest population is the one with no relationship to any of them — restated for corporate rather than personal data.

A pharmaceutical company that outsourced a study has its programme detail in a third party’s systems, chose that third party on cost and capability, and has no visibility into its security. It is the vendor assessment problem at 25-0814.

Employee Data Appears Again

The corpus filed at 25-0704 that workforce exposure has no public register in any sector, and at 25-0923b that a listed company’s employee incident reached the record only through a securities filing.

Graded medium: the disclosure is confirmed, the affected volume is not established, and the corpus has no detail on what partner information was involved.

How we reported this

Compiled from public reporting of company statements, listed below. Affected volume and the nature of the partner data are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Major drug research company confirms cyberattack compromised employee and partner dataCybersecurity Dive
  2. Attackers are coming for drug formulas and patient dataHelp Net Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary