WACOAL Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The WACOAL Listed by qilin Ransomware Group (reported September 8, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target mid-sized and specialist retailers, treating customer databases and internal networks as leverage in double-extortion schemes. Listings on criminal leak sites have become a routine pressure tactic, often appearing before any independent confirmation of what was taken or whether negotiations occurred. Against that backdrop, the appearance of WACOAL on a qilin-associated site in September 2023 fits a familiar pattern: an apparel company named, a claim of network access, and a promise of forthcoming data dumps that may or may not materialise in full.
Public reporting on 8 September 2023 stated that WACOAL had been listed by the qilin ransomware group. The group claimed it had exfiltrated internal files and would soon publish a large leak that included all customer data. The number of people affected remains unknown, and independent verification of the full scope has not been published in the available record. For customers and employees, the listing itself is reason enough to treat the incident seriously while recognising that many details stay unconfirmed.
What happened
According to the reported summary, Wacoal America—an apparel and fashion company specialising in lingerie and intimate wear—was listed by the qilin ransomware group. The group stated that it had taken internal files from the company’s network in a ransomware attack and intended, “in the near future,” to publish a large leak that would include all customer data. The listing was reported on 8 September 2023. No public figure has been given for the number of individuals affected, no technical description of the initial access method has been released in the facts at hand, and no confirmation has appeared that the threatened publication occurred or what volume of material was ultimately released. The available record therefore consists of the group’s claim of exfiltration and its stated intention to leak customer data alongside other internal files.
The group behind it: qilin
Qilin is a ransomware operation that has operated as a ransomware-as-a-service model, recruiting affiliates who conduct intrusions and share proceeds with the core operators. Like many contemporary groups, it commonly employs double extortion: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. Listings on dedicated leak sites serve both as proof of access and as a pressure mechanism. Public reporting over recent years has associated qilin with attacks across multiple sectors, including manufacturing, professional services and retail. The group’s claims about any single victim should be treated as assertions until corroborated by the organisation, regulators or independent forensic disclosure. In this case, the facts record only that qilin listed WACOAL and claimed it would publish internal files and customer data; they do not confirm payment, non-payment, or the eventual fate of the stolen material.
Who is WACOAL?
Wacoal is an established name in intimate apparel, with Wacoal America operating as the U.S. arm of a longer-standing Japanese lingerie and fashion business. Companies in this sector typically maintain e-commerce platforms, wholesale and retail relationships, customer loyalty or account systems, order and shipping records, and the usual back-office infrastructure of finance, human resources and product development. A breach affecting such an organisation is consequential because it can touch both consumer personal information and internal commercial data. Even when the precise contents of a leak remain unverified, the combination of customer records and corporate files creates lasting exposure risks for individuals and competitive or operational risks for the business.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack and that the group claimed the forthcoming leak would include all customer data. No itemised inventory of file types, record counts or specific data fields has been disclosed in the public summary. Organisations of this kind ordinarily hold names, addresses, email addresses, phone numbers, purchase histories, payment-related tokens or billing details (often handled by processors), account credentials or reset information, and internal documents such as contracts, employee records and product or pricing material. Because the exact contents remain unconfirmed, it is not possible to state as fact which of these categories were present in the material qilin claimed to hold. Readers should treat the group’s reference to “all customer data” as a claim rather than a verified catalogue.
What's at stake
For individuals, the principal risks are phishing and social-engineering attempts that reuse leaked names, emails or order details; account takeover if passwords or reset mechanisms were among the files; and longer-term fraud or identity misuse if richer personal identifiers were included. Intimate-apparel purchase data can feel especially sensitive, raising privacy and reputational concerns even when financial loss does not immediately follow. For the organisation, stakes include regulatory notification duties, potential civil claims, disruption to operations if systems were encrypted, and erosion of customer trust. Because the scale of the incident is unknown and the full contents unconfirmed, both the personal and corporate impact remain difficult to quantify from public information alone. The prudent stance is to assume that customer-related material may have left the network and to act accordingly until clearer inventories appear.
If your data was in this claimed breach
If you have shopped with Wacoal or held an account, treat any unexpected messages that reference orders, refunds or account problems with caution. Change passwords on the Wacoal site and on any other services where you reused the same credentials; enable multi-factor authentication where it is offered. Monitor bank and card statements for unfamiliar charges and consider fraud alerts with major credit bureaus if you believe richer identity data may have been involved. Retain any breach notices the company may later issue, as they often contain specific guidance and timelines. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets, which provides an additional signal while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GYP New Tree SA Listed by qilin Ransomware GroupGoodwill Manasota Listed by Qilin RansomwareDixie Beverage Listed by qilin Ransomware GroupDennis Waters Rental Properties Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the WACOAL Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.