A public victim post naming the biopharma firm shows how ransomware operators use data-leak pressure even when the underlying compromise remains unverified.