lipcare.de Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
lipcare.de has been listed by the safepay ransomware group, which claims to have exfiltrated internal files from the company. The listing was disclosed on 20 June 2025; the number of people affected is not stated, and anyone who may have interacted with lipcare.de should check for notices and consider changing credentials.
On 20 June 2025, the German cosmetics manufacturer lipcare.de appeared on a ransomware group's public listing, raising the possibility that internal company files were taken and could later be released. For anyone who has done business with the firm, worked there, or shared personal details with it, the practical concern is whether those records now sit outside the organisation's control and what that could mean for privacy and security.
Public information remains limited. The number of people affected is unknown, and the precise contents of any stolen material have not been independently verified. What is known is that a ransomware group claims to have exfiltrated internal files during an attack on the company.
What happened
According to the available record, lipcare.de was listed by the safepay ransomware group on 20 June 2025. The listing asserts that internal files were exfiltrated as part of a ransomware attack. No further Reported Details have been released about the timing of the intrusion, the technical method used, the volume of data involved, or whether systems were encrypted in addition to the claimed theft. The number of individuals potentially affected is listed as unknown. Independent confirmation of the group's claims has not been publicly established.
Who is safepay?
Safepay is a ransomware operation that became active in the public eye in 2024. Like many modern ransomware groups, it follows a double-extortion model: operators encrypt a victim's systems and simultaneously claim to have stolen data, then threaten to publish the material on a dedicated leak site if a ransom is not paid. The group maintains a dark-web portal where it posts victim names, sometimes accompanied by sample files or countdown timers. Its targets have included organisations across manufacturing, professional services and other sectors in Europe and elsewhere. In this case, the appearance of lipcare.de on the group's site constitutes a claim by safepay that it holds the company's data; the claim itself has not been independently verified in the public record.
Who is lipcare.de?
Lipcare.de is operated by KHK GmbH, a German company that specialises in the manufacture of natural and conventional cosmetics. Firms of this type typically produce lip balms, skincare products and related items for retail and wholesale markets. As a manufacturer, the organisation would normally hold commercial records, supplier and customer information, employee data, product formulations, quality-control documentation and internal operational files. A ransomware incident at such a company is consequential because it can disrupt production, supply chains and customer relationships while also placing any personal or proprietary data that may have been taken at risk of further misuse.
The information in question
The public listing states that internal files were exfiltrated. No more granular inventory of data types—such as customer names, payment details, employee records or product formulas—has been disclosed. Organisations in the cosmetics manufacturing sector commonly store a mix of business-to-business contact information, order histories, personnel files, research notes and regulatory compliance documents. Because the exact contents remain unconfirmed, it is not possible to state with certainty which categories of information, if any, left the company's control. Readers should treat any specific claims about particular data elements as unverified until corroborated by the organisation itself or by independent investigators.
What's at stake
For individuals whose details may appear in the company's files, the principal risks include unwanted contact, phishing attempts that reference genuine business relationships, or the reuse of personal information in identity-related fraud. Employees could face exposure of payroll or personnel records. For the organisation, the stakes include potential regulatory scrutiny under European data-protection rules, operational disruption, reputational damage with retail partners, and the cost of investigation and remediation. Because the scale of the incident and the precise data involved are still unknown, the full extent of these risks cannot yet be quantified. The listing itself, even if the data are never published, can create lasting uncertainty for customers and staff.
Were you affected?
If you have been a customer, supplier, employee or other contact of lipcare.de or KHK GmbH, consider taking a few measured steps. Monitor financial and email accounts for unexpected activity. Be cautious of unsolicited messages that claim to relate to the company or that request personal information. If you receive notification from the firm itself, follow the guidance it provides. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Keep records of any unusual contacts and, if you believe your information has been misused, report the matter to the relevant national data-protection authority or law-enforcement body. Further official statements from the company or from German authorities may clarify the situation as more information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
setex-textil.de Listed by safepay Ransomware Groupmeyer-lift.de Listed by safepay Ransomware Groupjuliuskoch.com Listed by safepay Ransomware Groupglatten.de Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the lipcare.de Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.