naturesplus.com Listed by Settra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
naturesplus.com was listed by the Settra ransomware group on September 17, 2026. The group claims to hold data on an undisclosed number of people, and individuals are advised to check for any follow-up statements or unusual account activity.
Ransomware crews continue to pressure organisations by posting names on leak sites before any independent verification occurs. In that climate, a listing is a public claim, not a finished investigation: it can be accurate, inflated, recycled, or wrong, and readers should treat it accordingly.
On or about September 17, 2026, the group known as Settra listed naturesplus.com on its leak site. The listing points to Natural Organics, Inc. / NaturesPlus and includes fragmentary reference material in its summary. As of writing, naturesplus.com has not publicly confirmed the claim. How many people, if any, are affected remains unknown, and the listing does not set out a verified inventory of exposed data types.
Inside the listing
According to the Settra listing, the organisation named is naturesplus.com, associated in the group’s text with Natural Organics, Inc. / NaturesPlus. The reported summary on the listing refers to documents and includes a prologue-style mention of CEO Jim Gibbons and a period described as between 2015 and 2019, with the publicly captured text truncated (“pur…”). That wording is the group’s own presentation on its leak site, not a confirmation from the company, a regulator, or a breach index.
People affected are unknown. Data types named as exposed are not disclosed in the material provided for this report. Timing of any alleged intrusion, technical method, ransom demand, and scale of any files the group claims to hold are likewise undisclosed in those facts. Nothing in the available record establishes that a theft completed, that files were published, or that the fragmentary document description is complete or accurate.
A leak-site entry establishes only that a named crew chose to publish a claim about a named organisation on a given date. It does not, by itself, prove network compromise, the sensitivity of any holdings, or the current status of negotiations. Until the company or another authoritative source speaks, the public record on this matter is the listing and the limits of what it states.
The group behind it: Settra
Settra is known publicly as a ransomware and extortion-style actor that uses leak-site pressure: name a victim, threaten or stage release of material, and seek payment or leverage. Like other groups in this category, it typically relies on claims of stolen files, countdown-style pressure, and selective description of content to attract attention. Those patterns are characteristic of the broader extortion ecosystem; they are not proof that every named organisation was successfully compromised in the way advertised.
For this specific listing, only what appears in the Settra post should be attributed to the group. The group claims an association with naturesplus.com / Natural Organics, Inc. / NaturesPlus and presents document-oriented wording that references leadership and a multi-year window in the mid-to-late 2010s. No further victim-specific technical claims are included in the facts supplied here, and none should be inferred.
Readers should separate two layers: well-documented behaviour of extortion crews in general, and the narrow, unverified claim about this company. The former explains why listings appear; the latter is all that attaches to naturesplus.com until confirmed otherwise.
About naturesplus.com
NaturesPlus is the consumer-facing identity associated with Natural Organics, Inc., a firm long active in vitamins, minerals, and related dietary supplements. Companies in this sector typically operate e-commerce and wholesale channels, customer service and order systems, marketing lists, and corporate functions such as finance, HR, and vendor management. Leadership names and historical corporate documents can appear in ordinary business archives even when no cyber incident is involved.
A listing that names a supplements brand matters because the sector sits at the intersection of consumer trust, health-related purchasing, and routine holding of personal and commercial information. That does not mean any particular category of data left the organisation in this case. It means that if a claim were ever substantiated, the potential blast radius would involve customers, employees, partners, and brand reputation in a market where people already share contact and order details to buy products.
Public background on what such a firm does is not the same as evidence about this listing. The organisation’s products and corporate identity are widely known; the Settra post remains an unconfirmed accusation.
What data was at risk
The facts state that data types named as exposed are not disclosed. The listing summary gestures at “documents” and corporate naming (Natural Organics, Inc. / NaturesPlus) plus a prologue reference involving CEO Jim Gibbons and years between 2015 and 2019, but that is attacker-facing description, not a validated inventory.
If files were taken from an organisation of this kind, firms in supplements and natural-products manufacturing and retail typically hold some mix of customer account and order information, payment-related records handled through processors, employee and contractor records, supplier and distributor contracts, internal finance and operations files, and marketing or CRM data. Historical executive or corporate documents can also exist in email and file stores. None of that list is confirmed as involved here.
Exact contents, volume, and sensitivity remain unconfirmed. Treating the group’s marketing language as a catalogue would overstate what is known.
Why it matters
For individuals, the practical concern is conditional. If personal data from a customer, employee, or partner relationship with this organisation were ever shown to have been copied and circulated, risks could include targeted phishing that impersonates the brand, password reuse attacks on other sites, and misuse of contact or order history. Those outcomes depend on what, if anything, actually left controlled systems and whether it appears in broader breach corpora—points not established by the listing alone.
For the organisation, a public extortion claim can drive customer questions, partner scrutiny, and the cost of investigation whether or not the claim is fully accurate. Leak-site posts are designed to create urgency and doubt. What the listing does establish is reputational and operational pressure from a named crew. What it does not establish is negligence, the success of an intrusion, or a definitive data map.
Keeping those boundaries clear protects readers from false certainty and avoids treating an accusation as a completed forensic result.
If your data was involved
If you have a past relationship with NaturesPlus or Natural Organics, Inc. and you are concerned that your information might appear in extortion-related material, act on a precautionary basis rather than on the assumption that your records are already public. Use unique passwords on important accounts, enable multi-factor authentication where available, and treat unexpected messages that reference orders, refunds, or “breach assistance” with scepticism. Monitor bank and card statements for activity you do not recognise, and consider a fraud alert with major credit bureaus if you believe identity data could be in play.
Because people affected and data types are unconfirmed, there is no basis here to tell any individual that their file is out. You can still run a free exposure scan of your email address to check whether that address has already surfaced in known breach datasets elsewhere, and you can follow only official company or regulator notices if they appear later. Until naturesplus.com or another authoritative source confirms details, the responsible stance is cautious hygiene, not panic driven by an unverified leak-site claim.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
fchhotels.com Listed by Settra Ransomware Grouppacificabs.com Listed by Settra Ransomware Grouprottner-tresor.at Listed by Settra Ransomware Groupsym.com.mx Listed by Settra Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the naturesplus.com Listed by Settra Ransomware Group →
Publicly posted by settra — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.