Fattore Cosméticos Ltda Listed by spacebears Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Fattore Cosméticos Ltda has been listed by the spacebears ransomware group after internal files were exfiltrated in an attack, with the incident disclosed on 6 September 2025. Anyone who may have had data held by the company should review their accounts for unusual activity and follow official guidance on protective steps.
Ransomware groups continue to target mid-sized manufacturers and consumer-goods firms across Latin America, often listing victims on public leak sites after claiming to have stolen internal files. In this environment, even companies outside the technology sector face pressure when their names appear on such sites.
On 6 September 2025, the ransomware group spacebears listed Fattore Cosméticos Ltda, a Brazilian manufacturer of hygiene and beauty products. Public detail remains limited: the number of people affected is unknown, and the precise method and full scope of any intrusion have not been independently confirmed. The listing itself is a claim by the group that internal files were exfiltrated.
What happened
According to the reported listing, spacebears claimed to have conducted a ransomware attack against Fattore Cosméticos Ltda and to have exfiltrated internal files. The incident was reported on 6 September 2025. No public confirmation of the attack’s success, the volume of data taken, or any ransom demand has been released by the company or by independent investigators. The number of individuals potentially affected remains unknown. Timing of the alleged intrusion, the initial access vector, and whether systems were encrypted are all undisclosed.
The group behind it: spacebears
Spacebears is a ransomware operation that has appeared on public leak sites in recent years. Like many such groups, it typically follows a double-extortion model: encrypting systems while also claiming to steal data, then threatening to publish the material if a ransom is not paid. The group posts victim names and sometimes sample files on its leak site to increase pressure. Public reporting has linked spacebears to attacks on organisations in multiple countries, though its exact size, membership and technical infrastructure remain only partially documented. In the present case, the group’s listing of Fattore Cosméticos Ltda constitutes an unverified claim; no independent verification of the data or the attack has been published.
About Fattore Cosméticos Ltda
Fattore Cosméticos Ltda is a Brazilian company founded in 2002. It manufactures hygiene and beauty products and states that it focuses on customer satisfaction. Organisations of this type typically maintain databases of product formulations, supply-chain records, financial documents, and personal information relating to employees and clients—data that can include names, contact details, and commercial records. A breach at such a firm can therefore affect both internal operations and the privacy of individuals who have dealt with the company. The company’s website is publicly listed as https://www.fattorecosmeticos.com.br/.
What data was at risk
The spacebears listing states that internal files were exfiltrated in a ransomware attack. The reported summary associated with the listing names databases, financial documents, and personal information of employees and clients. Exact file counts, the full contents of any databases, and whether the data have been published remain unconfirmed. Organisations in the cosmetics and personal-care manufacturing sector commonly hold customer and employee contact details, order histories, payroll records and commercial contracts; whether any of these categories were among the files claimed by the group has not been independently verified.
Why it matters
If personal information of employees or clients was taken, those individuals face ordinary but real risks: targeted phishing, identity-related fraud, or unwanted contact. Financial documents, if genuine and complete, could expose commercial relationships or payment details that third parties might misuse. For the company itself, the listing creates reputational pressure and potential regulatory scrutiny under Brazilian data-protection rules, regardless of whether the full extent of the claim is later confirmed. Because the number of people affected is unknown, the practical impact cannot yet be quantified; the absence of confirmed figures does not eliminate the need for caution among anyone who has shared data with the firm.
What to do if you're exposed
Anyone who has been an employee, client or supplier of Fattore Cosméticos Ltda should treat the listing as a prompt to review their own exposure rather than as proof of compromise. Practical first steps include:
- Monitor bank and credit-card statements for unfamiliar transactions and enable transaction alerts where available.
- Change passwords on accounts that may have used the same credentials or email address associated with the company, and enable multi-factor authentication.
- Be alert to phishing messages that reference the company, cosmetics orders or employment details; verify any unexpected requests through official channels.
- If you are an employee, contact the company’s human-resources or security team for any official guidance they may issue.
- Run a free exposure scan of your email address against known breach data sets to check whether your information has already appeared in other incidents.
Public detail on this specific incident remains limited; further confirmation from the company or independent researchers would be required before the full scope can be assessed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Autohaus Elstermann Listed by spacebears Ransomware GroupDOVERN Import Listed by spacebears Ransomware GroupNorthland Auto Solutions Listed by spacebears Ransomware GroupSmiles By Steedman Listed by spacebears Ransomware GroupLatest breaches
Publicly posted by spacebears — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.