G-plans.com Listed by ransomhub Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
G-plans.com was listed by the RansomHub ransomware group on October 16, 2024, indicating that internal files had been exfiltrated during a ransomware attack. Individuals are advised to check whether their information may have been involved and to monitor accounts for any suspicious activity.
G-plans.com, a nutrition and wellness platform, was listed by the ransomware group ransomhub on or around October 16, 2024. Public reporting indicates that internal files were exfiltrated during a ransomware attack, though the number of people affected remains unknown and further details about the incident have not been disclosed.
The listing itself is a claim by the group rather than independent confirmation of the full scope or outcome. For users of a service that handles personal health and lifestyle information, any such claim raises legitimate questions about what may have been taken and how individuals should respond.
Inside the incident
According to available reports, G-plans.com was listed by ransomhub as a victim of a ransomware attack in which internal files were exfiltrated. The date associated with the public listing is October 16, 2024. No verified figures have been released for the volume of data involved, the precise method of initial access, or the total number of individuals whose information may have been exposed. The people-affected count is listed as unknown.
Public detail on whether a ransom demand was paid, whether systems were encrypted in addition to the claimed exfiltration, or whether the company has issued its own statement remains limited. As with many ransomware listings, the primary public signal is the group's claim on its leak site; independent corroboration of the full technical timeline has not been provided in the available facts.
The group behind it: ransomhub
Ransomhub is a ransomware operation that has been active in the public domain as a double-extortion group. It typically claims to steal data before encrypting systems and then pressures victims by threatening to publish the material on a dedicated leak site if payment is not made. The group has been observed listing organizations across multiple sectors and is known for operating in a ransomware-as-a-service model that allows affiliates to carry out attacks under its brand.
In this case, ransomhub has listed G-plans.com and claims that internal files were taken. No additional statements from the group specific to this victim—such as sample files, exact data volumes, or deadlines—are included in the reported facts. Listings of this kind should be treated as claims until independently verified.
About G-plans.com
G-plans.com is a nutrition and wellness company that offers personalized meal plans based on metabolic typing. Founded by Dr. Philip Goglia, the platform asks users to complete a questionnaire to determine their metabolic type and then delivers tailored diet and fitness recommendations intended to optimize metabolism and support overall well-being. Services of this kind typically collect personal details, health-related answers, contact information, and payment data in the ordinary course of business.
Because the company operates in the health and wellness sector and handles individualized plans, a breach claim carries particular weight: the data involved can be more sensitive than ordinary commercial records. Even without confirmed numbers, the nature of the service makes any unauthorized access to internal files potentially consequential for customers who trusted the platform with personal health information.
What data was at risk
The reported facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases, or specific categories of personal information has been publicly named. Exact contents therefore remain unconfirmed.
Organizations that provide personalized nutrition and wellness plans commonly hold account credentials, questionnaire responses about diet and health, contact details, and billing information. Whether any of those categories were among the internal files claimed by ransomhub has not been disclosed. Readers should treat the precise composition of the stolen material as unknown at this stage.
The real-world impact
For individuals, the primary risks center on the possible misuse of personal or health-related information that may have been contained in the exfiltrated files. Even if the exact data types are unconfirmed, exposure of contact details can lead to targeted phishing, while any health or lifestyle answers could be used for more convincing social-engineering attempts. Identity-related or financial data, if present, could increase the chance of fraud.
For the organization, a ransomware listing can disrupt operations, damage customer trust, and create regulatory or contractual obligations to investigate and notify affected parties. Because the number of people affected is unknown, the scale of any notification or remediation effort cannot yet be assessed from public information alone. The absence of Reported Details does not eliminate the need for caution; it simply means the full picture is still incomplete.
Were you affected?
If you have used G-plans.com, treat the situation as a potential exposure until more information becomes available. Change any passwords associated with the service, enable multi-factor authentication where possible, and monitor financial and email accounts for unusual activity. Be alert for phishing messages that reference nutrition plans, metabolic typing, or health goals, as attackers sometimes exploit timely news of breaches.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Keep records of any suspicious contact and consider placing fraud alerts with credit bureaus if you believe sensitive personal details may have been involved. Official updates from the company, if issued, will provide the most reliable guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
healthcarewithinreach.org Listed by ransomhub Ransomware Groupchoicemg.com Listed by ransomhub Ransomware Groupwomenscare.com Listed by ransomhub Ransomware Groupqualitybillingservice.com Listed by ransomhub Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the G-plans.com Listed by ransomhub Ransomware Group →
Publicly posted by ransomhub — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.