LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › UNOde50 Listed by worldleaks Ransomware Group

HIGH severityUnverified claimHow we verify

UNOde50 Listed by worldleaks Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·November 14, 2025
UNOde50 Listed by worldleaks Ransomware Group

Reported November 14, 2025.

HIGH
Severity
November 14, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

UNOde50 was listed by the worldleaks ransomware group on November 14, 2025, after internal files were exfiltrated in a ransomware attack. Individuals who may have had data with the company should review any notifications and take protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On November 14, 2025, the ransomware group worldleaks listed the Spanish jewelry company UNOde50 on its leak site. The listing states that internal files were exfiltrated during a ransomware operation. No confirmed count of affected individuals has been released, and the company has not issued a public statement detailing the scope or impact of the incident. The event occurs amid a sustained pattern of ransomware activity targeting commercial organizations that maintain customer records and supply-chain data. Such listings often precede or accompany demands for payment, though the precise sequence and outcome in this case remain undisclosed.

Inside the incident

The only confirmed public information is the November 14, 2025 listing itself. The group claims to have obtained internal files through a ransomware attack. No further technical details, such as the initial access method, duration of access, or volume of data, have been made public. The number of people potentially affected is listed as unknown.

The group behind it: worldleaks

Worldleaks is a ransomware operation that has appeared in public reporting since 2024. Like other groups in this category, it typically combines encryption of systems with the theft of data, then uses a leak site to pressure victims. Its listings usually include claims of exfiltrated material and sometimes partial samples. The accuracy of any individual claim on such sites is not independently verified unless the victim or law enforcement confirms it.

About UNOde50

UNOde50 is a Spanish jewelry and accessory brand founded in the late 1990s. Its name derives from an initial production model that limited each design to fifty units. The company produces handcrafted items and distributes them internationally. Organizations of this type routinely hold customer contact information, order histories, payment details processed through third parties, and internal operational records.

What data was at risk

The listing refers only to “internal files.” No inventory of specific data categories has been released. In the jewelry retail sector, internal files can contain a range of material, including supplier contracts, employee records, and customer correspondence. Without an official disclosure from the company, the exact contents remain unconfirmed.

Why it matters

Even without a confirmed data volume, the exposure of internal files can create downstream risks for individuals whose information appears in those records. These risks include targeted phishing, account takeover attempts, or misuse of any personal or financial details that may have been stored. For the organization, the incident adds to the operational costs of investigation, potential regulatory reporting, and remediation.

Were you affected?

Individuals concerned about possible exposure should monitor their email accounts and financial statements for unusual activity. A practical first step is to run a free exposure scan using a reputable breach-checking service to see whether an email address has appeared in previously published data sets. Organizations that hold personal data are expected to notify affected individuals when required by applicable law; any official notification from UNOde50 would provide the most direct guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyUNOde50 security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See UNOde50’s full breach history →

More recent breaches

Nike, Inc. Listed by worldleaks Ransomware GroupDecember 16, 2025Peruvian Connection Listed by worldleaks Ransomware GroupSeptember 23, 2025Legend Senior Living Listed by worldleaks Ransomware GroupJuly 27, 2025Prime Beverage Group Listed by worldleaks Ransomware GroupJune 15, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the UNOde50 Listed by worldleaks Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by worldleaks — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram