LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lifesum Listed by Direwolf Ransomware Group

HIGH severityUnverified claimHow we verify

Lifesum Listed by Direwolf Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 19, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Lifesum Listed by Direwolf Ransomware Group

Reported August 19, 2026.

HIGH
Severity
August 19, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Lifesum was listed by the Direwolf ransomware group on August 19, 2026, with the breach affecting an undisclosed number of people and exposing personal data. Individuals should check whether their information has been compromised and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to use public leak sites as pressure tools, posting company names and asserting they hold stolen files even when those claims have not been verified by the organisations named, by regulators, or by independent breach trackers. In that setting, a listing is best read as an allegation that requires careful handling, not as a settled account of what occurred.

On August 19, 2026, Lifesum appeared on a leak site associated with the Direwolf ransomware group. Direwolf claims to have stolen internal data. Lifesum has not publicly confirmed the incident as of writing. How many people might be affected, what systems were involved, and what files—if any—were taken remain undisclosed in the available record. For users of a health- and nutrition-focused service, the practical question is what to do if personal information were later shown to have been involved, not an assumption that it already has been.

What is being claimed

According to the listing, Direwolf has named Lifesum on its ransomware leak site and claims to have stolen internal data. The public facts supplied for this report do not include a claimed intrusion date, a ransom demand, a file count, a sample of alleged data, a description of how access was obtained, or any statement from Lifesum accepting or rejecting the claim. The number of people affected is unknown. Data types supposedly exposed are not disclosed.

A leak-site entry establishes that a group chose to publish a company name and a brief assertion. It does not, by itself, prove that a breach succeeded, that the volume or sensitivity of material matches the group’s marketing language, or that the material is new rather than recycled or misattributed. Until the company, a regulator, or another authoritative source confirms details, the responsible description is that Direwolf has listed Lifesum and claims theft of internal data—nothing more.

The group behind it: Direwolf

Direwolf is known publicly as a ransomware and extortion-oriented actor that, like others in this category, has used dedicated leak sites to name alleged victims and threaten publication of data as leverage. Such groups typically combine encryption or data theft claims with timed disclosure pressure. Their posts are advocacy for payment, not audited inventories.

Well-documented patterns across this class of actors include naming organisations, asserting that internal files were taken, and sometimes releasing purported samples. None of that general background converts Direwolf’s listing of Lifesum into confirmed fact about this case. For this incident, only the group’s claim—that it stole internal data from Lifesum—is on the record in the facts provided. Method, timeline, and proof package specifics for Lifesum are not included in those facts.

Who is Lifesum?

Lifesum is a consumer-facing organisation in the digital health and wellness sector, known for nutrition, diet, and lifestyle tracking products. Companies in this space ordinarily operate apps and backend services that process account credentials, profile information, and user-generated health or food-related logs, and they may hold payment or support records depending on how the product is sold.

A credible compromise at such a firm would matter because the data involved can be personal and, in some cases, sensitive in a health-adjacent sense. That consequence is why unverified leak-site claims attract attention. It does not mean the claim has been proven. The listing does not establish Lifesum’s security posture, detection capability, or internal priorities; those topics are outside what an unconfirmed extortion post can support.

What data was at risk

The facts state that data types named as exposed are not disclosed. Direwolf’s claim refers only to “internal data” in general terms. No inventory of fields, databases, or document categories has been confirmed in the material provided for this article.

If files were taken from an organisation of this kind, firms in the consumer nutrition and wellness sector typically hold account identifiers such as email addresses, names, and profile settings; app usage and goal-related content; and possibly billing or customer-support records. Some may also process more detailed dietary or body-metric information users choose to enter. Whether any of that—or something else entirely—was involved here is unconfirmed. Readers should treat specific field-level risk as conditional until a verified disclosure appears.

The real-world impact

For individuals, the impact of an unverified listing is mainly uncertainty and the need for proportionate caution. If personal data from a health-oriented app were later confirmed as exposed, risks could include phishing that references diet or fitness habits, credential stuffing if passwords were reused, and unwanted contact using email or other identifiers. Health-adjacent details, if present, can make social-engineering messages more convincing. None of that should be read as a statement that Lifesum users’ data is already circulating from this incident.

For the organisation, a public extortion listing can create reputational pressure, customer concern, and the operational burden of investigating and communicating—whether or not the underlying claim is accurate. Extortion crews rely on that pressure. What the listing does establish is that Direwolf chose to name Lifesum. What it does not establish is the scope of any intrusion, the accuracy of the “internal data” claim, or fault on the company’s part.

What to do now

If you use Lifesum or similar services, act on a conditional basis. Use a unique password for the account and enable multi-factor authentication where available. Be wary of unexpected messages that cite a breach, demand urgent payment, or ask you to open attachments or enter credentials on unfamiliar pages. If you reuse passwords elsewhere, change them on important accounts. Monitor financial statements if you have payment methods tied to the service. Official updates, if any, should come from Lifesum through its normal channels—not from a ransomware blog.

You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach datasets from other incidents. That check does not prove or disprove Direwolf’s claim about Lifesum, but it can help you see whether your address appears in previously documented leaks and prioritise password and account hygiene accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLifesum security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Lifesum’s full breach history →

More recent breaches

InfoFlo CRM Listed by Direwolf Ransomware GroupAugust 19, 2026Photon Health, Inc. Listed by Direwolf Ransomware GroupAugust 19, 2026PayUp Listed by Direwolf Ransomware GroupAugust 19, 2026Arizona State University (ASU) Listed by Direwolf Ransomware GroupAugust 17, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Lifesum Listed by Direwolf Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by direwolf — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram