🛒 Consumer & Retail¶
Retail, e-commerce, food & beverage, hospitality, consumer goods · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed
Victims L30D1▼ −8
Prior 30D9
Active actor L90DQilin · 6
Active actor L90DThe Gentlemen · 6
Active actor L90DSETTRA · 6
Today — 12 Sep 2026¶
No industry-tagged items in today's briefing — see recent activity below.
Last 14 days¶
Recent victim claims¶
Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.
September 2026
Sep 08
GT Distributors
Play
Austin, Texas-based national distributor of tactical gear, firearms accessories and uniforms for law enforcement, military and public-safety agencies; listed on Play's leak site Sep 8 claiming internal data theft. Play uses double extortion (no upfront ransom demand in the leak note); data scope and impact unconfirmed. · Sources: RedPacketSecurity
August 2026
Aug 13
D&J Beverage Service
Qilin
Qilin DLS claim August 13, 2026; scope unconfirmed. · Sources: https://www.ransomware.live/group/qilin
Aug 07
Levi Strauss
Unknown
Social engineering of employee computers; attacker accessed corporate files; consumer data not affected; breach contained · Sources: https://therecord.media/levis-data-breach-social-engineering
Aug 03
Winn-Dixie
Anubis
Anubis ransomware DLS claim August 3 2026; major US Southeast grocery chain; no statement from Winn-Dixie; data scope and impact unconfirmed · Sources: https://www.ransomware.live/
Aug 01
The Butcher Brothers
Play
Play DLS claim August 1 2026; US food processing/distribution. No victim statement; no data published; no data volume disclosed. · Sources: https://www.ransomware.live/id/VGhlIEJ1dGNoZXIgQnJvdGhlcnNAcGxheQ==
July 2026
Jul 22
Estee Lauder
Clop
Clop exploited Oracle E-Business Suite zero-day CVE-2025-61882 to access EL HR systems (attack Aug 9 2025, discovered Jun 19 2026, disclosed via CA AG filing Jul 22 2026); exposed SSNs, passport numbers, bank account details, health info, payroll and performance data for employees; 24 months Kroll identity monitoring offered · Sources: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
Jul 21
Fairlife (Coca-Cola subsidiary)
Anubis
Anubis RaaS (emerged Dec 2024) claimed the July 16 Fairlife ransomware attack on its DLS July 21, 2026; claims ~1TB exfiltrated corporate data with ransom deadline end of week; Coca-Cola confirmed attack via SEC filing (third-party access to Fairlife IT environment); US dairy production suspended; Canadian operations unaffected; 🟥 data scope and exfiltration volume unverified · Sources: BleepingComputer · Cybernews · Coca-Cola SEC filing
Jul 18
Salina Supply
Qilin
Qilin DLS posting July 18; data claimed exfiltrated; unverified — no public statement from Salina Supply · Sources: https://www.ransomware.live
Jul 17
Danone
Qilin
Qilin DLS claim July 17: 221 GB claimed (91,558 files) including year-end financial summaries, customer account database, NDAs, and quarterly sales reports 2023-2025. Danone has not confirmed; treat as claim only. · Sources: https://cybernews.com/news/danone-evian-silk-international-delight-qilin-ransomware-attack/ · https://www.ransomware.live/group/qilin
Jul 16
Fairlife LLC (Coca-Cola subsidiary)
Unattributed
Coca-Cola subsidiary Fairlife detected unauthorised third-party access to production-related systems on July 16 2026; ransomware event halted all US dairy production including Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan; Canada operations unaffected; no actor claimed responsibility; no data theft confirmed; investigation ongoing with outside advisors; law enforcement notified · Sources: https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/ · https://www.theregister.com/cyber-crime/2026/07/17/ransomware-curdles-production-at-coca-colas-fairlife-dairy-biz/5274157 · https://www.helpnetsecurity.com/2026/07/17/coca-cola-fairlife-ransomware-attack/
Jul 13
Nichirei Corporation
RansomHouse
Ransomware attack disrupted 140 cold-chain distribution centers; impact on KFC Japan (1,300+ restaurants), Aeon, Kura Sushi supply chains. DLS claim posted Jul 22-23; data theft scope unverified. · Sources: https://www.japantimes.co.jp/business/2026/07/22/companies/nichirei-cyberattack-ransomhouse/
Jul 11
Carita
The Gentlemen
French luxury skincare and cosmetics brand claimed on The Gentlemen data leak site July 11; data type and volume unconfirmed; company has not issued a public statement · Sources: ransomware.live · breachsense.com
Jul 10
Lidl
Unattributed
Third-party IT service provider breach; customer data from Lidl online shops in Germany, Belgium, and Netherlands exfiltrated; names, phone numbers, email addresses, dates of birth, customer numbers, and salutations exposed; passwords, billing/delivery addresses, bank details, and payment information potentially compromised; Lidl notified affected customers July 10; Dutch and Belgian data protection authorities notified; forensic investigation ongoing · Sources: BleepingComputer · Help Net Security · SC Media
Jul 08
Wade's Dairy
Akira
Akira DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/akira · Sources: [SharkStriker] · [ransomware.live]
Jul 07
Mercado Libre
The Gentlemen
Latin America's largest e-commerce and fintech platform; The Gentlemen DLS claim July 7, 2026; approximately 118,244 users reportedly affected; company has not issued a public statement; data scope and impact unconfirmed; 🟥 unverified — verify before treating as breach · https://www.escudodigital.com/en/cybersecurity/mercado-libre-hit-by-ransomware-attack.html · https://blog.rankiteo.com/mer1783492030-mercado-libre-ransomware-july-2026/ · https://www.ransomware.live/id/TWVyY2FkbyBMaWJyZUB0aGVnZW50bGVtZW4= · Sources: [EscudoDigital] · [Rankiteo] · [ransomware.live]
Jul 06
AC Beverage
Unattributed
PEAR DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/pear · Sources: [ransomware.live]
Jul 02
Dixie Beverage West
Qilin
Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 02
Pennant Hills Golf Club
Qilin
Qilin DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · https://www.hendryadrian.com/ransom-pennant-hills-golf-club-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02
Tofutown
Payload
traditional organic food manufacturer (est. 1981; vegan spreads, tofu, seitan products); Payload DLS claim July 2, 2026 (07:26 UTC); data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · https://www.hendryadrian.com/ransom-tofutown-jul-2026/ · Sources: [ransomware.live] · [hendryadrian.com]
Jul 02
JS Hotels
LockBit
Spanish hospitality group (jshotels.com) operating 10 hotel properties in Majorca; listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://www.ransomware.live/id/anNob3RlbHMuY29tQGxvY2tiaXQ1
Jul 01
Refinery Hotel
Akira
luxury boutique hotel near Bryant Park (197 rooms, Parker & Quinn restaurant, Refinery Rooftop bar); Akira DLS claim July 1, 2026; 15 GB claimed including employee PII (passports, driver's licenses, SSNs, W-9 forms), guest information, financials, contracts and agreements, and NDAs; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.redpacketsecurity.com/akira-ransomware-victim-refinery-hotel/ · https://www.hookphish.com/blog/ransomware-group-akira-hits-refinery-hotel/ · https://ransomware.live/id/UmVmaW5lcnkgSG90ZWxAYWtpcmE= · Sources: [RedPacket Security] · [HookPhish] · [ransomware.live]
Jul 01
Starpool
WorldLeaks
Italian designer and manufacturer of premium wellness cabins, saunas, steam rooms, and hydromassage systems; WorldLeaks DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jul 01
B'Laofood Joint Stock Company
KRYBIT
KRYBIT DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/krybit-ransomware-attack-on-blaofood-joint-stock-company/ · https://www.ransomware.live/id/Ymxhb2Zvb2QuY29tQGtyeWJpdA · Sources: [DeXpose] · [ransomware.live]
Jul 01
Hotel de la Bourse
LockBit
Hotel in Mulhouse, France (hotel-bourse.com) listed on LockBit 5.0 DLS approximately July 1 2026, discovered July 11 2026. DLS claim unverified. · Sources: https://ransomware.live/id/aG90ZWwtYm91cnNlLmNvbUBsb2NrYml0NQ==
June 2026
Jun 30
Hwa Seng Water Resources Biotech Co., Ltd.
DragonForce
DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
Pou Sheng International Holdings
The Gentlemen
China-based athletic footwear retailer and Yue Yuen Group subsidiary; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jun 30
SDEZ
The Gentlemen
historic French family-owned company (est. 1816) specialising in industrial rental and maintenance of professional linen, workwear, and hygiene equipment; national network of industrial laundries across France and Belgium; 700+ employees; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/U0RFWkB0aGVnZW50bGVtZW4= · Sources: [ransomware.live]
Jun 30
Mondottica
The Gentlemen
global luxury eyewear company specialising in design, production, and worldwide distribution of premium sunglasses and optical frames under licensed brand names; international operations across Europe and APAC; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-mondottica/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Arkın Group
BlackNevas
diversified hospitality and gaming conglomerate in Northern Cyprus (casino resorts, hotels); BlackNevas DLS claim June 30, 2026; 1.4 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/blacknevas · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30
Tour Edge
SETTRA
US-based golf equipment manufacturer producing irons, woods, hybrids, and wedges across multiple premium lines; SETTRA DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-targets-golf-manufacturer-tour-edge/ · https://www.ransomware.live/group/settra · Sources: [DeXpose] · [ransomware.live]
Jun 30
VCNY Home
SETTRA
US-based home textiles company (bedding, bath, and decorative products; distributed through major US retail chains); SETTRA DLS claim June 30, 2026; estimated attack date June 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/id/dmNueWhvbWUuY29tQHNldHRyYQ== · Sources: [FalconFeeds] · [ransomware.live]
Jun 29
GDN AR
INC Ransom
Argentine grocery store operator headquartered in Ciudad Autónoma de Buenos Aires; INC Ransom DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/R0ROIEFSKERvcmlua2EpQGluY3JhbnNvbQ · Sources: [ransomware.live]
Jun 29
Canopy Brands
SETTRA
SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/Y2Fub3B5YnJhbmRzLnVzQHNldHRyYQ== · https://x.com/FalconFeedsio/status/2070588706558550063 · Sources: [ransomware.live] · [FalconFeeds]
Jun 29
Quality Dining Inc.
SETTRA
one of the largest US Burger King and Chili's franchise operators (Indiana-based); SETTRA DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/settra · Sources: [ransomware.live]
Jun 28
1-800-Dentist
Qilin
US national dental referral and appointment-scheduling service (connects patients with 25,000+ dentist offices nationwide); Qilin DLS claim June 28, 2026; estimated attack date June 28; data scope and impact unconfirmed; 🟥 unverified — verify before treating as a breach · https://www.redpacketsecurity.com/qilin-ransomware-victim-1-800-dentist/ · https://www.ransomware.live/id/MS04MDAtZGVudGlzdEBxaWxpbg== · Sources: [RedPacket Security] · [ransomware.live]
Jun 28
ESHA Research/ESHA Cloud Services
Stormous
food and beverage nutrition database and regulatory compliance software company (Salem, Oregon); core product development databases allegedly accessed; Stormous DLS claim June 28, 2026; 🟥 unverified — no vendor statement · https://www.hookphish.com/blog/ransomware-group-stormous-hits-eshacloudqa-com/ · https://socradar.io/free-tools/ransomware-intelligence/victims/eshacloudqa-com-352c7808 · Sources: [HookPhish] · [SOCRadar]
Jun 28
Monoprix.tn
Stormous
Tunisian supermarket and retail chain (monoprix.tn); Stormous DLS claim June 28, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/bW9ub3ByaXgudG5Ac3Rvcm1vdXM · Sources: [ransomware.live]
Jun 28
LifeVantage Corporation
SETTRA
publicly traded direct-sales nutritional supplement company (NASDAQ: LFVN); SETTRA DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-hits-lifevantage-corporation/ · https://ransomware.live/id/bGlmZXZhbnRhZ2UuY29tQHNldHRyYQ== · Sources: [DeXpose] · [ransomware.live]
Jun 28
PChome Online Inc.
SETTRA
one of Taiwan's largest online retail and e-commerce platforms; breach estimated June 10, 2026 via infostealer malware compromising employee and customer accounts; 35,000+ users and employees' credentials and personal data exposed; SETTRA DLS claim June 28, 2026; 🟥 unverified — no PChome public statement · https://www.dexpose.io/settra-ransomware-attack-on-pchome-online-inc/ · https://www.galaxywarden.com/blog/breach/pchome-settra-ransomware-june-2026 · https://socradar.io/free-tools/ransomware-intelligence/victims/pchome-com-tw-bcdbab3d · Sources: [DeXpose] · [GalaxyWarden] · [SOCRadar]
Jun 25
impulso-store.com
Stormous
Italian online retail platform; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.breachsense.com/breaches/ · Sources: [ransomware.live] · [Breachsense]
Jun 25
Au Vieux Campeur
The Gentlemen
French outdoor gear chain (24 stores, 180,000+ members); company confirmed cyberattack June 2, 2026 and mobilised incident response; DLS claim appeared June 25 after 23-day negotiation window closed without ransom payment; data scope unconfirmed · https://frenchbreaches.com/alertes/au-vieux-campeur-mq5ponk61juevh4e5fj · https://www.cyberattaque.org/au-vieux-campeur-victime-dune-cyberattaque-une-enquete-est-en-cours/ · https://www.ransomware.live/ · Sources: [FrenchBreaches] · [Cyberattaque.org] · [ransomware.live]
Jun 25
Frosty Acres Brands
Booba
US-based national foodservice cooperative and purchasing organisation (member-owned, c.5,000+ restaurants and foodservice operators); Booba DLS claim June 25, 2026; data scope unconfirmed; group warned full data leak unless negotiations initiated; no victim statement · https://www.dexpose.io/booba-ransomware-strikes-frosty-acres-brands/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 24
montechiaro-store.com
Stormous
DLS claim June 24, 2026; "complete customer and buyer data" claimed; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-montechiaro-store-com/ · Sources: [RedPacket Security]
Jun 24
lorenzoni-store.com
Stormous
Lorenzoni brand of Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969; Italian family-run knitwear manufacturer with three brands: Lorenzoni, Montechiaro, Impulso); DLS claim June 24, 2026; "complete data" belonging to customers and buyers claimed; part of the same parent-company incident as montechiaro-store.com (June 24) and impulso-store.com (June 25) · https://www.redpacketsecurity.com/stormous-ransomware-victim-lorenzoni-store-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [RedPacket Security] · [FalconFeeds]
Jun 24
maglificioliliana.com
Stormous
parent company Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969, Montichiari; specialises in high-quality knitwear, operates three brands: Lorenzoni, Montechiaro, Impulso); 400+ GB of sensitive data claimed exfiltrated, including product designs, orders, and customer and operational records; DLS claim June 24, 2026; scope of all four brand/domain listings suggests a full-group compromise · https://www.hookphish.com/blog/ransomware-group-stormous-hits-maglificioliliana-com/ · https://x.com/FalconFeedsio/status/2069899152281207018 · Sources: [HookPhish] · [FalconFeeds]
Jun 24
Sapporo Holdings
Unattributed
Sapporo Holdings Ltd. disclosed June 24, 2026 that two overseas subsidiaries sustained suspected unauthorized access: Pokka Corporation Singapore (regional food and beverage company) and Sleeman Breweries (Canadian craft brewer); suspicious network activity detected, affected systems shut down pending investigation; no confirmed data exfiltration as of initial disclosure; no confirmed domestic (Japan) impact; actor unattributed; part of broader wave of cyberattacks against Japanese multinationals in June 2026 (alongside Aflac Japan, KDDI, Nidec) · https://therecord.media/japan-cyber-breaches-aflac-sapporo-nidec-kddi · https://www.ppln.co/en/post/japan-cyber-incidents-june-2026-eng · Sources: [The Record] · [Pipeline.co]
Jun 23
Nike, Inc.
WorldLeaks
1.4TB claimed; 188,347 files alleged to include R&D technical packs, bill-of-materials (BoMs), product prototypes, manufacturing schematics, and internal documents; WorldLeaks DLS claim June 23, 2026; full data dump published live; Nike confirmed it is investigating the incident and has engaged external cybersecurity experts; scope and authenticity not independently verified; 🟨 breach under investigation · https://www.infosecurity-magazine.com/news/worldleaks-ransomware-14tb-nike/ · https://www.darkreading.com/cyberattacks-data-breaches/worldeaks-extortion-group-stole-1-4tb-nike-data · https://www.computing.co.uk/news/2026/security/nike-confirms-investigation-of-1-4tb-nike-data · Sources: [Infosecurity Magazine] · [Dark Reading] · [Computing]
Jun 23
Randa Apparel & Accessories
Chaos
global apparel and accessories manufacturer (Dockers, Tommy Hilfiger, PGA TOUR licensed brands); DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/chaos-ransomware-strikes-randa-apparel-accessories/ · https://www.ransomware.live/group/chaos · Sources: [DeXpose] · [ransomware.live]
Jun 23
KliknKlik.com
APT73
online retailer and distributor of computer hardware; APT73 DLS claim June 23; data exposure scope unconfirmed; APT73 (aka Bashe) noted for fabricating some high-profile claims — treat as 🟥 unverified pending confirmation · https://www.ransomware.live/group/apt73 · https://www.dexpose.io/apt73-bashe-ransomware-attack-on-medika-plaza/ · https://www.cloudsek.com/blog/unmasking-media-hungry-ransomware-groups-bashe-apt73 · Sources: [ransomware.live] · [DeXpose] · [CloudSEK]
Jun 21
Artistic Smiles
NightSpire
https://www.redpacketsecurity.com/nightspire-ransomware-victim-artistic-smiles/ · Sources: ransomware.live DLS / [RedPacket Security]
Jun 15
Kawai Musical Instruments Mfg. Co., Ltd.
SafePay
renowned Japanese manufacturer of pianos, digital keyboards, and band/orchestral instruments; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-kawai-musical-instruments/ · https://www.ransomware.live/id/a2F3YWl1cy5jb21Ac2FmZXBheQ== · https://www.hendryadrian.com/ransom-kawaius-com-jun-2026/ · Sources: [DeXpose] · [ransomware.live] · [hendryadrian.com]
Jun 15
Sysco
ShinyHunters
61M Salesforce records claimed; ShinyHunters listed June 15, weeks after Sysco was separately targeted by Qilin ransomware (two distinct threat actors targeting the same org); Sysco has not publicly confirmed this incident; 🟥 unverified — treat as claimed only · https://cybernews.com/news/sysco-shinyhunters-61-million-salesforce-records/ · Sources: [Cybernews]
Jun 12
JCPenney / Catalyst Brands / Authentic Brands Group
ShinyHunters
hundreds of thousands of records claimed (SSNs, DOBs, W-2 tax forms, payroll records, driver's licenses, government-issued IDs); ShinyHunters claimed June 12; threatened to publish by June 15; no JCPenney/Catalyst/Authentic public statement; class action investigation launched (Edelson Lechtzin LLP, June 18); no data samples published; 🟥 unverified — treat as claimed only · https://www.redpacketsecurity.com/shinyhunters-ransomware-victim-jcpenney-several-other-subsdiaries-under-catalyst-brands-authentic-brands-group/ · https://cybernews.com/security/shinyhunters-jcpenney-retail-data-leak-claim/ · https://www.dexpose.io/shinyhunters-breaches-jcpenney-and-catalyst-brands/ · Sources: [RedPacket Security] · [Cybernews] · [DeXpose]
Jun 09
Spratley's of Mortimer
PrinzEugen
posted twice on DLS; de-duped · Sources: ransomware.live DLS