Active Cosmetic Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Active Cosmetic was listed by the safepay ransomware group on September 17, 2024, after internal files were exfiltrated. Individuals connected to the company should check their accounts and consider protective steps.
Ransomware groups continue to target mid-sized companies across consumer sectors, using data theft and public leak-site pressure as leverage even when encryption alone might not force payment. In this climate, listings of firms that hold customer, supplier, or internal operational records have become routine, leaving individuals and partners to assess risk with incomplete public information.
On 17 September 2024, the ransomware group safepay listed Active Cosmetic on its leak site, claiming to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail beyond the listing itself is limited. The claim matters because organisations of this type routinely store personal and commercial data whose exposure can create lasting practical problems for those connected to them.
What happened
According to the public report dated 17 September 2024, Active Cosmetic was listed by the safepay ransomware group. The group claims that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access method, the precise date of intrusion, the volume of data taken, or confirmation that systems were encrypted—have been disclosed in the available record. The number of individuals whose information may be involved is listed as unknown. A reported revenue figure of $26.7 million is associated with the organisation in the same summary, but this does not itself confirm the scale of any data loss. At present the incident rests on the group’s leak-site claim; independent verification of the breach’s full scope has not been made public.
The group behind it: safepay
Safepay is a ransomware operation that became publicly visible in 2024 and follows the now-common double-extortion model: operators claim to steal data before or during encryption and then threaten to publish it if a ransom is not paid. Like many contemporary groups, safepay maintains a dark-web leak site where it posts victim names and, in some cases, sample files to increase pressure. Public reporting on the group indicates it has targeted organisations across multiple sectors and geographies, typically focusing on entities large enough to possess valuable data yet potentially less resourced than major corporations. The group’s listings are claims made by the actors themselves; they do not automatically constitute independent confirmation that every asserted detail is accurate. In the case of Active Cosmetic, the only specific assertion available is that internal files were exfiltrated. No additional statements attributed to safepay about this particular victim appear in the public facts.
About Active Cosmetic
Active Cosmetic is identified as a commercial organisation with a reported revenue of $26.7 million. Companies operating under similar names typically sit within the cosmetics, personal-care, or beauty-products sector—manufacturing, distributing, or retailing skincare, makeup, or related goods. Such businesses commonly maintain customer databases, loyalty or order histories, supplier contracts, employee records, product formulations, and financial or logistics files. Even without a full public profile of Active Cosmetic, the combination of consumer-facing activity and mid-sized revenue suggests it would hold both personal data belonging to customers or staff and commercially sensitive internal material. A ransomware claim against any organisation in this sector therefore raises questions about the possible exposure of those categories of information, regardless of whether the precise contents have been confirmed.
What was likely exposed
The available facts state only that internal files were exfiltrated in a ransomware attack. No specific data types—such as names, contact details, payment information, health-related records, or intellectual property—are named beyond that general description. Organisations in the cosmetics and personal-care field typically store customer account data, purchase histories, marketing lists, employee personnel files, supplier agreements, and internal operational documents. It is therefore plausible that some combination of these categories could be among the material claimed by the group, yet the exact contents remain unconfirmed. Public detail is limited; readers should treat any assumption about particular fields of data as speculative until further verified information appears.
What's at stake
For individuals whose details may have been among the internal files, the practical risks include unwanted contact, phishing attempts that reference genuine order or account information, and the longer-term possibility of identity-related fraud if identifiers such as addresses or dates of birth were present. Employees or contractors could face similar exposure of payroll or personnel records. For the organisation itself, the consequences can include operational disruption, regulatory scrutiny where personal data is involved, reputational damage among customers and partners, and the cost of investigation and remediation. Because the number of people affected is unknown and the precise data types are undisclosed, the scale of these risks cannot yet be quantified. The claim alone is sufficient to warrant caution on the part of anyone who has had a commercial or employment relationship with Active Cosmetic.
What to do if you're exposed
If you have been a customer, employee, or supplier of Active Cosmetic, treat the listing as a reason to increase vigilance rather than as proof that your own data is confirmed stolen. Monitor financial and email accounts for unexpected activity, enable multi-factor authentication where available, and be sceptical of unsolicited messages that reference the company or recent purchases. Consider placing fraud alerts with credit-reporting agencies if you believe sensitive identifiers may have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a check provides one practical way to assess whether your information has surfaced publicly. Keep records of any communications you receive that appear linked to the incident, and follow official guidance issued by the organisation or relevant data-protection authorities if further notifications are released.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
etplaw.com Listed by safepay Ransomware Grouproyalinsignia.com Listed by safepay Ransomware Groupbellandgraham.co.nz Listed by safepay Ransomware Groupmulticoasia.com Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Active Cosmetic Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.