naturesplus.com Listed by Settra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
naturesplus.com was listed by the Settra ransomware group on September 17, 2026, with the group claiming to hold data belonging to an undisclosed number of people. Individuals are advised to check with the organisation and monitor their accounts for any signs of misuse.
On September 17, 2026, the ransomware group Settra listed naturesplus.com on its leak site, presenting the entry as evidence of a cyber incident involving Natural Organics, Inc., the company behind the NaturesPlus brand. The listing is an unverified claim by the group. As of writing, naturesplus.com and Natural Organics, Inc. have not publicly confirmed that any breach occurred, that systems were accessed, or that any data was taken.
Public detail is limited. The number of people who might be affected is unknown, and the listing does not provide a clear, confirmed inventory of exposed records. Because leak-site posts are often used for pressure and publicity, readers should treat the claims as allegations until independent confirmation appears from the company, a regulator, or another authoritative source.
What the listing says
According to the Settra listing, naturesplus.com appears as a named victim entry dated September 17, 2026. The group’s reported summary refers to documents associated with Natural Organics, Inc. / NaturesPlus and includes a fragmentary reference to a “PROLOGUE” involving CEO Jim Gibbons and a period between 2015 and 2019. The publicly available fragment ends mid-phrase and does not spell out a full narrative, a complete file list, or a verified description of what, if anything, was copied.
The listing does not disclose how many people might be affected. It does not name specific categories of personal or commercial data as reportedly stolen. Method of access, ransomware deployment details, encryption events, ransom demands, and timelines beyond the listing date are undisclosed in the material provided. In short, the leak-site entry asserts involvement and points to document-related material; it does not constitute independent proof that a breach took place or that particular files left the company’s control.
The group behind it: Settra
Settra is known publicly as a ransomware and extortion-style actor that uses leak sites to name organizations and threaten publication of material it claims to hold. Groups in this category typically combine system intrusion claims with countdown-style pressure, partial file samples, and public shaming aimed at forcing negotiation. Their postings are marketing and leverage tools as much as technical disclosures: they may exaggerate scope, recycle older material, or list entities before any independent verification.
For this specific entry, only what appears on the listing should be attributed to Settra. The group claims naturesplus.com belongs on its victim roster and references documents tied to Natural Organics, Inc. / NaturesPlus and a CEO-related prologue spanning 2015–2019. No further Settra statements about this victim are established in the facts at hand. Readers should separate general knowledge of how such groups operate from the unproven status of any single claim.
naturesplus.com and its sector
naturesplus.com is the public web presence for NaturesPlus, a brand associated with Natural Organics, Inc., which operates in the dietary supplements and natural products space. Companies in this sector commonly manage consumer-facing e-commerce, wholesale and retail partner relationships, product formulation and labeling information, quality and regulatory documentation, and ordinary corporate records such as HR, finance, and executive correspondence.
A claimed incident involving a supplements brand matters because the sector sits at the intersection of consumer trust, health-related marketing, and supply-chain partnerships. Customers, employees, clinicians who recommend products, and business partners all have reason to care whether corporate or personal information might surface. That consequence flows from the nature of the business, not from any confirmed theft in this case. The Settra listing names the organization; it does not by itself establish what systems were involved or whether customer or partner data was touched.
What was likely exposed
The facts state that data types named as exposed are not disclosed. The listing’s summary fragment points to “Documents” connected with Natural Organics, Inc. / NaturesPlus and a CEO prologue spanning 2015 to 2019, but that is the attacker’s description, not a verified inventory. It is not established which files, if any, were taken, nor whether they included personal data, commercial contracts, internal memos, or something else.
If files were taken from an organization of this kind, firms in the supplements and natural-products sector typically hold combinations of customer account and order information, employee and contractor records, vendor and distributor details, product and regulatory documentation, and internal business correspondence. Those are sector norms, not findings about this incident. Exact contents remain unconfirmed, and the number of people affected is unknown. No reader should assume their own information was included solely because of the listing.
The real-world impact
If the group’s claims were accurate and documents left company control, affected individuals could face risks that commonly follow corporate document exposure: phishing that references real internal names or projects, credential stuffing if work emails and passwords appear, and social engineering aimed at employees or partners. Executive or historical internal material, if genuine and published, can also be misused to craft convincing fraud against staff, suppliers, or customers.
For the organization, a public leak-site listing can create reputational pressure, partner questions, and legal or regulatory attention even before facts are settled. That pressure is part of why extortion groups publish names. At the same time, an unconfirmed listing does not prove negligence, successful exfiltration, or operational failure. It establishes that Settra chose to name naturesplus.com; it does not establish the full technical story. People and partners should watch for official company notices rather than treat the leak site as a complete account.
If your data was involved
Because involvement is unproven and data types are undisclosed, treat the following as precautions if you have a relationship with NaturesPlus or Natural Organics, Inc.—as a customer, employee, or partner—not as confirmation that your information is out. Monitor account statements and order histories for unfamiliar activity. Prefer official channels for any password resets. Be wary of unexpected emails, calls, or messages that cite internal projects, executive names, or document titles that could have been scraped from public claims. Enable multi-factor authentication on email and shopping accounts where available. If you receive a ransom or extortion contact claiming to hold your personal data from this incident, do not pay; preserve the message and report it through appropriate local channels.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets unrelated to, or broader than, this listing. Official confirmation from the company, if it comes, should guide any further steps such as credit monitoring or targeted notifications. Until then, calm vigilance and skepticism toward unverified leak-site claims remain the practical response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.
More recent breaches
hollypoultry.com Listed by Settra Ransomware Groupbaltimorefreightliner.com Listed by Settra Ransomware Groupmcpolymers.com Listed by Settra Ransomware Grouptranslarity.com Listed by Settra Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the naturesplus.com Listed by Settra Ransomware Group →
Publicly posted by settra — unverified claim, pending independent verification. Leak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.