Introduction

On April 28, 2024, London Drugs, a pharmacy and retail chain operating nearly 80 stores across British Columbia, Alberta, Saskatchewan, and Manitoba, closed every location after discovering a cybersecurity incident. The closure lasted until May 7, more than a week, during which pharmacists remained on standby for urgent needs but most services, including phone lines, were suspended while the company investigated.

The Attack

London Drugs confirmed weeks later that the incident was a ransomware attack. The Canadian Center for Cyber Security's National Cyber Threat Assessment later named the incident directly, attributing it to LockBit, a ransomware-as-a-service operation the agency describes as having been used against critical infrastructure entities including healthcare, energy, and government organizations. LockBit demanded 25 million dollars. London Drugs refused to pay.

The Fallout

The company's early statements said there was no evidence customer or employee data had been compromised. That changed. After the ransom went unpaid, LockBit published stolen corporate files on the dark web, including employee records such as immigration applications, sexual harassment complaints, termination letters, and performance assessments. London Drugs has said patient and customer databases were not affected, but confirmed the employee data breach and began notifying and offering credit monitoring to those affected.

Who's Behind It

LockBit had already been the target of a major international law enforcement operation before this attack. In February 2024, the UK's National Crime Agency, working with the FBI, Europol, and other partners, seized control of LockBit's infrastructure in an operation called Cronos. The NCA has since assessed that LockBit rebuilt at reduced capacity and credibility rather than shutting down, which is consistent with the group still being active enough to carry out the London Drugs attack two months later. In May 2024, the US, UK, and Australia jointly sanctioned and unmasked the group's administrator, Russian national Dmitry Khoroshev, alongside a US indictment and a 10 million dollar reward for information leading to his arrest.

Where It Stands

Healthcare and pharmacy operators remain frequent targets for ransomware groups because of the volume of sensitive personal and prescription data they hold, and because operational disruption creates direct pressure to pay quickly. London Drugs' decision not to pay, and LockBit's subsequent data leak, illustrates the tradeoff organizations face in these cases: refusing payment avoids funding the group directly but does not prevent the data from being exposed once it has already been taken.

Sources

Canadian Center for Cyber Security, "National Cyber Threat Assessment 2025-2026." cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026

UK National Crime Agency, "LockBit leader unmasked and sanctioned." nationalcrimeagency.gov.uk/news/lockbit-leader-unmasked-and-sanctioned

US Department of the Treasury, "United States Sanctions Senior Leader of the LockBit Ransomware Group." home.treasury.gov/news/press-releases/jy2326

CBC News, "London Drugs closes stores until further notice due to cyberattack" and "London Drugs confirms it was victim of ransomware attack." cbc.ca/news/canada/british-columbia/london-drugs-closure-western-canada-1.7187615

Global News, "London Drugs hackers seek millions in ransom on claims of stolen employee data." globalnews.ca/news/10516121/london-drugs-ransom-attack-employee