A ransomware group called thegentlemen has claimed a cyberattack on Custom Rx Shoppe, a Washington pharmacy serving retail and long-term care patients, potentially exposing prescription, medical, and insurance data. The pharmacy has not confirmed the incident. Affected individuals should monitor credit reports, watch for phishing, and consider a credit freeze immediately.
| Company | The Custom Prescription Shoppe, LLC |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names and Contact Information, Prescription and Medication Records, Medication Administration Records, Health Insurance and Medicare/Medicaid Details, Compounding Lab Treatment Information, Billing and Payment Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Custom Rx Shoppe Data Breach?
A ransomware group calling itself thegentlemen has claimed responsibility for a cyberattack on Custom Rx Shoppe, an independent pharmacy based in Bellingham, Washington. The group posted the claim on its dark web leak site, stating it accessed the pharmacy’s systems and data. As of now, the pharmacy has not publicly confirmed the incident.
Because this report comes from the threat actor’s own listing rather than a statement from the company, many details remain unclear. The exact method of intrusion has not been disclosed. In addition, the specific timeline of the attack, including when unauthorized access may have first occurred, is not publicly known.
Ransomware groups like thegentlemen typically use extortion tactics that combine data theft with threats to publish stolen files. However, without an official statement from Custom Rx Shoppe, it is not yet possible to verify the scope of what was taken. Independent verification and forensic details will likely depend on future public disclosures or regulatory filings, if and when they occur.
Who was affected?
Custom Rx Shoppe serves patients across Whatcom, Skagit, and Island counties in Washington State. As a result, the population potentially affected by this claimed breach could include retail pharmacy customers as well as residents of nursing homes and assisted-living facilities that rely on the pharmacy’s long-term care services.
The exact number of individuals affected has not been publicly disclosed. Given the pharmacy’s dual role in retail and long-term care, both younger patients and elderly residents in managed care settings could be part of the affected group. Because the company also operates a compounding lab serving individualized patient needs, people receiving specialized medications, including hormone therapy, may also be included.
What Information Was Potentially Exposed?
Since Custom Rx Shoppe has not issued a public statement, the exact categories of compromised data are not confirmed. However, based on the nature of the business and the type of information a pharmacy typically stores, certain categories of personal and medical data are plausible targets.
- Full names and contact information
- Prescription and medication records
- Medication Administration Records (MAR) for long-term care patients
- Health insurance and Medicare/Medicaid enrollment details
- Compounding lab treatment information, including hormone therapy records
- Billing and payment information
If this information was indeed accessed, the risks to affected individuals could be significant. Medical identity theft is a serious concern when prescription and treatment records are exposed. Criminals could use this data to file fraudulent insurance claims or obtain medications under someone else’s identity.
In addition, exposed contact and billing information could be used for targeted phishing scams. Because some affected individuals may be elderly nursing home residents, they could be especially vulnerable to follow-up scams that impersonate healthcare providers or insurers. This makes vigilance particularly important for caregivers and family members managing accounts on behalf of others.
What is the company doing?
At this time, Custom Rx Shoppe has not publicly confirmed the ransomware claim. As a result, no official investigation, remediation, or notification process has been disclosed by the company itself.
Because the available information stems from the threat actor’s own claim, affected individuals should not assume that formal notifications have already gone out. If the company later confirms the breach, it would typically be expected to notify affected patients, offer guidance, and potentially provide credit or identity monitoring services. Until such a statement is made, individuals should rely on their own protective measures rather than wait for official word.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone who has used Custom Rx Shoppe’s pharmacy or long-term care services should consider checking their credit reports regularly. This is a simple, free way to spot suspicious activity early.
You can request free credit reports from each of the three major credit bureaus. Because fraud can take time to surface, checking reports periodically over the coming months is a smart precaution. Look closely for unfamiliar accounts, inquiries, or address changes.
Watch for Phishing and Scam Attempts
If personal or medical information was exposed, scammers may use it to craft convincing phishing emails, texts, or phone calls. For example, a scammer might pose as your pharmacy or insurance provider to extract more sensitive details.
Therefore, avoid clicking links or sharing personal information in response to unsolicited messages. Instead, contact the pharmacy or insurer directly using a verified phone number. This extra step can prevent scammers from gaining further access to your accounts.
Consider a Fraud Alert or Credit Freeze
Because prescription and billing data may include information tied to your identity, placing a fraud alert on your credit file can add a layer of protection. A fraud alert requires lenders to verify your identity before opening new credit in your name.
For even stronger protection, you could place a credit freeze with each bureau. This blocks new accounts from being opened without your explicit approval. While a freeze takes a few extra steps to lift when needed, it offers one of the most effective defenses against identity theft.
Protect Against Medical Identity Theft
If your medication history, insurance details, or treatment records were part of this claimed breach, review your insurance statements carefully. Look for services or prescriptions you did not receive.
In addition, request a copy of your medical records periodically to confirm accuracy. If you notice unfamiliar claims or diagnoses, report them to your insurer and healthcare provider right away. Catching medical identity theft early can prevent long-term complications with your health records and coverage.
Consult a Data Breach Attorney
Given the sensitive nature of pharmacy and health data, affected individuals may want to speak with a data breach attorney. An attorney can help you understand your legal options if the breach is later confirmed.
Many attorneys offer free case evaluations, so there is little downside to asking questions early. This is especially useful if you experience financial losses or identity theft linked to this incident.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
