LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › mlderm.com Listed by safepay Ransomware Group

HIGH severityUnverified claimHow we verify

mlderm.com Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 10, 2025
mlderm.com Listed by safepay Ransomware Group

Reported May 10, 2025.

HIGH
Severity
May 10, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On May 10, 2025, the safepay ransomware group listed mlderm.com after internal files were taken during a ransomware attack. Individuals connected to the site should check whether their information was exposed and take steps to protect themselves.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For anyone who has shopped at mlderm.com for skincare products aimed at treating melasma, a listing by a ransomware group raises practical questions about whether account details, order history or contact information could have been taken. Public detail remains limited, yet the claim of internal files being removed is enough to warrant attention from customers and staff alike.

On 10 May 2025 the organisation was reported as listed by the safepay ransomware group. The number of people affected is unknown, and the precise contents of any stolen material have not been confirmed beyond a general reference to internal files. That uncertainty itself is the immediate concern for those whose data may be involved.

What happened

According to the available record, mlderm.com was listed by the safepay ransomware group on 10 May 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further public information has been released about the date the intrusion began, how the attackers gained access, the volume of data taken, or whether systems were encrypted. The number of individuals potentially affected remains unknown. The listing itself constitutes an unverified claim by the group; independent confirmation of the breach has not been supplied in the reported facts.

Who is safepay?

Safepay is a ransomware operation that follows the now-common double-extortion model: data is copied from the victim’s network before encryption is applied, after which the group demands payment to prevent public release of the stolen material. Like other contemporary ransomware crews, safepay maintains a leak site on which it posts the names of organisations it claims to have compromised, often accompanied by sample files or countdown timers. The group has previously targeted a range of mid-sized businesses across retail, professional services and manufacturing. Its public statements are promotional by nature and should be treated as assertions rather than verified fact. In this instance the only specific claim recorded is that internal files belonging to mlderm.com were exfiltrated.

mlderm.com and its sector

mlderm.com operates as an online beauty-product retailer specialising in skincare formulations designed to treat melasma. The company describes itself as relying on scientific research and a team of aesthetics professionals to develop and refine its product line. Businesses of this type typically maintain customer accounts, payment records, shipping addresses, order histories and, in some cases, limited health-related information supplied by shoppers seeking advice on skin conditions. They also hold internal operational files such as supplier contracts, inventory data and employee records. A compromise at an online retailer can therefore expose both commercial secrets and personal information belonging to customers who trusted the site with their details. Because the products address a visible dermatological concern, many buyers may have provided more personal context than they would for ordinary cosmetics purchases, increasing the sensitivity of any data that might have been taken.

What data was at risk

The reported facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data categories—customer names, email addresses, payment card numbers, medical notes or otherwise—has been published. Organisations operating online skincare stores commonly store account credentials, purchase histories, postal addresses and customer-service correspondence; they may also retain limited self-reported information about skin conditions. Whether any of those categories were among the files claimed by safepay is unconfirmed. Until more detail emerges, the exact contents of the material remain unknown.

What's at stake

If customer records were among the internal files, affected individuals could face phishing attempts that reference genuine past orders, attempts to reset account passwords, or the sale of contact details on criminal markets. Even purely commercial files can create secondary risks: leaked supplier pricing or product formulas may harm the business’s competitive position, while any employee data could expose staff to identity-related fraud. For the organisation itself, the listing can damage customer trust and invite regulatory scrutiny under data-protection rules, regardless of whether a ransom is paid. Because the scale of the incident is undisclosed, the full extent of these risks cannot yet be measured.

What to do if you're exposed

Anyone who has created an account or placed an order with mlderm.com should treat the possibility of exposure seriously until clearer information appears. Practical first steps include:

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Remaining cautious with unsolicited messages and keeping credentials unique remain the most reliable immediate protections while further details about this incident are awaited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companymlderm.com security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See mlderm.com’s full breach history →

More recent breaches

springersjewelers.com Listed by safepay Ransomware GroupDecember 19, 2025dynamichomerepair.com Listed by safepay Ransomware GroupNovember 19, 2025portofuneralhomes.net Listed by safepay Ransomware GroupOctober 10, 2025chamberlainhuckeriede.com Listed by safepay Ransomware GroupJuly 14, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the mlderm.com Listed by safepay Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by safepay — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram