On the evening of August 24, Wuxi Apptec Co.,Ltd. (603259.SH) announced that its biology division's DNA-encoded library (DEL) platform recently experienced a cybersecurity incident. The company immediately activated its emergency response mechanism, bringing in external cybersecurity specialists and legal advisors to conduct a full investigation and manage the situation.
According to the announcement, all of the company's IT systems are operating normally, the DEL platform's security remains under control, and no evidence has been found suggesting any data was publicly disclosed, misused, or improperly accessed. The company has proactively reached out to clients in the affected biology division to provide thorough communication and clarification. Operations continue to run smoothly, and the company's ability to serve its customers has not been impacted.
The DEL platform involved in this incident is a specialized encoded chemical compound library used for early-stage discovery projects within the biology business. Based on the company's 2022 annual performance presentation, Wuxi Apptec Co.,Ltd. operates one of the world's leading DNA-encoded libraries, serving over 1,500 clients at the time, with more than 90 billion DEL compounds, 6,000 unique molecular scaffolds, and 35,000 building blocks.
By the close of trading on August 25, Wuxi Apptec Co.,Ltd. A-shares stood at 161 yuan, giving the company a total market capitalization of 480.4 billion yuan. Meanwhile, the H-shares were trading at 203.8 Hong Kong dollars, representing a total market cap of 604 billion Hong Kong dollars.
Where to begin
The disclosure of this cybersecurity event by Wuxi Apptec Co.,Ltd. has once again put the spotlight on the cybersecurity risks facing A-share listed companies. In fact, over the past few years, multiple A-share firms have suffered hacker attacks or network intrusions.
For instance, in April of this year, Longping High-Tech (000998.SZ) revealed that an overseas operating entity of its controlling subsidiary, Longping Agriculture Development Co., Ltd., was hit by an organized, professional hacker attack, which led to a payment of funds to a U.S. bank account at the end of 2025. Following the incident, the listed company immediately reported the matter to police authorities in Brazil, the United States, and relevant domestic provincial and municipal public security agencies, and initiated a cross-border recovery process based on the intelligence gathered. By April, some progress had been made in the case.
However, given the uncertainty surrounding the recovery of the stranded 6.0178 million U.S. dollars overseas, the listed company has made a full provision for the amount, which will impact its net profit attributable to shareholders for fiscal year 2025 by 21.243 million yuan. Additionally, Longping High-Tech stated that the incident was an isolated event and would not cause significant adverse effects on the normal production and operations of the company or Longping Development.
In July 2024, Sungo Integration (603163.SH) saw its servers suddenly attacked by hackers. In response, the company acted quickly, with its IT department immediately initiating information security defense and recovery protocols, including engaging external professional IT security consultants. At the time, the listed company stated that there was no evidence that the cyberattack resulted in any data breach or disclosure, and that it did not have a significant adverse impact on operations.
Why this wave of attacks matters
Notably, several global pharmaceutical companies have recently been targeted by cyberattacks. On June 11, 2026, Novo Nordisk issued a statement confirming a security vulnerability in its internal IT systems, classifying the event as a cybersecurity intrusion where unauthorized parties copied some data to external locations. On July 31, 2026, U.S. pharmaceutical giant Amgen disclosed a major cybersecurity incident in which a cloud storage system operated by a third-party service provider was hacked, leading to the theft of substantial internal corporate data and patient health information. According to regulatory filings submitted by Amgen, the company completed a comprehensive assessment of the event on July 29 and determined that the network intrusion qualified as a significant security incident. On May 7, 2026, U.S.-based West Pharmaceutical Services reported that it had suffered a significant cybersecurity attack during which unauthorized third parties stole some data and encrypted parts of its systems. The company discovered the attack on May 4, immediately took its systems offline, notified law enforcement, and engaged external cybersecurity experts.