
Case study Pharmaceuticals
A trusted provider became a path toward ransomware
A pharmaceutical company severed trusted SaaS access after Unit6 detected an attacker pivoting through a compromised provider toward ransomware staging.
Impact summary
A pharmaceutical company severed trusted SaaS access after Unit6 detected an attacker pivoting through a compromised provider toward ransomware staging.

01 / Observation
What Unit6 saw
Unit6 connected activity across the SaaS and customer environments and identified:
- 01
Authenticated access to pharmaceutical systems through the provider’s admin API
- 02
Scanning of internal shares, privileged directories, and user accounts
- 03
Attempts to escalate privileges and establish persistence with SaaS service accounts
- 04
Staging behavior consistent with known ransomware tradecraft
02 / Significance
Why it mattered
A global pharmaceutical company consumed services from a business intelligence platform whose privileged administrator access had been compromised.
The attacker began pivoting from the SaaS provider into multiple customers through legitimate, whitelisted integration links, bypassing traditional perimeter defenses.
Trusted credentials gave the actor privileged visibility into research environments. A ransomware event could have disrupted manufacturing or exposed regulated patient data.
03 / Confidence
How Unit6 established confidence
Trusted admin API access, internal enumeration, privilege escalation attempts, and ransomware pre-staging
Correlating the compromised provider with customer-side activity exposed the actor’s pre-ransomware sequence while it was still in progress.
04 / Response
What the customer could do
Unit6 and the response team acted across three access layers:
- Invalidated authentication tokens and API keys, and separated integrations from production
- Reset credentials and required fresh MFA enrollment for high-value identities
- Enabled endpoint response controls and isolated backups against encryption risk
05 / Documented outcome
Outcome
The ransomware attack was blocked in the staging phase, with zero payloads deployed.
The team gained visibility across the SaaS-to-customer attack chain and closed the trusted pathway the actor had used.



