LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Mandom Corporation Listed by worldleaks Ransomware Group

HIGH severityUnverified claimHow we verify

Mandom Corporation Listed by worldleaks Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 21, 2025
Mandom Corporation Listed by worldleaks Ransomware Group

Reported August 21, 2025.

HIGH
Severity
August 21, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Mandom Corporation was listed by the worldleaks ransomware group on August 21, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals should check any breach notices from the company and monitor their accounts for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 21, 2025, Mandom Corporation, a Japanese firm known for personal care products, was listed by the worldleaks ransomware group. Public details indicate that internal files were exfiltrated in a ransomware attack, though the number of people affected remains unknown and further specifics about the incident have not been disclosed.

This listing raises questions about potential exposure of company data, which could include operational or personal information held by an organization of this type. As with many such claims on ransomware leak sites, the full scope and confirmation of the breach rest on limited public reporting so far.

Breaking down the breach

The core known fact is that Mandom Corporation appeared on a listing associated with the worldleaks ransomware group, reported on August 21, 2025. According to available information, the incident involved the exfiltration of internal files as part of a ransomware attack. No further details on the timing of the intrusion, the method of access, the volume of data taken, or any encryption of systems have been made public. The number of individuals potentially affected is listed as unknown, and no confirmation of ransom demands, payments, or data publication has been provided in the reported facts. In short, the public record consists of the group's listing and the statement that internal files were taken, with all other elements remaining undisclosed.

The group behind it: worldleaks

worldleaks is a ransomware operation that follows the common double-extortion model used by many modern groups. In this approach, attackers typically gain access to a network, steal data, and then encrypt systems or files, threatening to release the stolen material on a dedicated leak site if a ransom is not paid. The group has been observed listing victims publicly as a pressure tactic, often providing sample files or descriptions to substantiate claims. Public reporting on worldleaks has documented its activity against organizations across various sectors, with listings serving as the primary public signal of an alleged compromise. In this case, the appearance of Mandom Corporation on the group's site should be treated as a claim by worldleaks rather than independently verified confirmation of every detail. No specific statements from the group about this victim beyond the listing itself are recorded in the available facts.

Who is Mandom Corporation?

Mandom Corporation is a Japanese company specializing in the production and sale of cosmetics, perfume, and health products. Originating in Osaka, it is known for leading brands such as Gatsby and Lucido-L, with a particular focus on personal care items for men while also serving women's beauty needs. The firm emphasizes innovative, high-quality products aimed at comfort and style. As a manufacturer and seller in the consumer goods sector, Mandom operates in a competitive market where brand reputation and customer trust are central. Organizations of this kind typically maintain internal systems for product development, supply chain management, employee records, and customer-related data. A reported ransomware incident involving such a company is consequential because it can disrupt operations, affect supply chains, and raise concerns among employees, partners, and consumers who interact with its brands.

What data was at risk

The reported facts state that internal files were exfiltrated in the ransomware attack. No more precise categories—such as employee personal details, customer records, financial documents, or product formulas—have been named. Exact contents remain unconfirmed. Companies in the cosmetics and personal care sector commonly hold a range of internal materials, including research and development notes, manufacturing processes, marketing plans, human resources files, and business correspondence. Without disclosure of the specific files taken, it is not possible to state what was actually exposed. Public detail is limited to the general description of internal files, so any assessment of risk must remain provisional until more information emerges.

Why it matters

For individuals connected to Mandom Corporation—whether employees, contractors, or customers—the primary concern is the possibility that personal or professional information could surface if the exfiltrated files are released. Even without confirmed data types, internal corporate files can contain names, contact details, or other identifiers that enable phishing, identity misuse, or targeted scams. For the organization itself, the incident carries operational and reputational weight: recovery from ransomware often involves system restoration, potential downtime, and the need to reassure stakeholders. In the broader context of Japanese consumer brands, any association with data theft can affect public confidence in product safety and privacy practices. Because the number of people affected is unknown and the precise data remains undisclosed, the real-world impact cannot yet be quantified, but the listing alone signals a need for vigilance among those who may have had dealings with the company.

What to do if you're exposed

If you have a connection to Mandom Corporation and are concerned that your information may have been involved, begin with basic protective steps. Monitor financial accounts and credit reports for unusual activity, and be cautious of unsolicited emails or messages that reference the company or request personal details. Change passwords on any accounts that might share credentials with work or related services, and enable multi-factor authentication where available. Consider placing a fraud alert with credit bureaus if you believe sensitive identifiers could be at risk. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Stay informed through official company statements rather than unverified claims, and report any suspected misuse of personal data to the appropriate authorities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMandom Corporation security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Mandom Corporation’s full breach history →

More recent breaches

Nike, Inc. Listed by worldleaks Ransomware GroupDecember 16, 2025UNOde50 Listed by worldleaks Ransomware GroupNovember 14, 2025LTS Group Listed by worldleaks Ransomware GroupOctober 27, 2025Kobayashi Listed by worldleaks Ransomware GroupOctober 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Mandom Corporation Listed by worldleaks Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by worldleaks — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram