On June 17, 2025, health-and-beauty company Alaffia appeared on the leak site of the dragonforce ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the Olympia, Washington-based maker of fair-trade skin and hair care products. While the exact number of people whose information was taken remains unknown, anyone who has ordered from Alaffia, worked with the company, or had their details stored in its systems could be affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Alaffia
Get alerted the next time Alaffia files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Alaffia’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Alaffia was listed by dragonforce on June 17, 2025. The company was founded in 2003 by Olowo-n'djo Tchala and Prairie Rose Hyde in their garage. It sells beauty and body care products made with traditional African ingredients and holds “Fair for Life” certification. The ransomware group claims to have taken internal files; no sample data has been publicly released at the time of writing. The breach falls into the category of ransomware extortion where stolen information is used as leverage for payment.
Why This Matters for You and Your Family
When a company that sells everyday personal-care items suffers a breach, the information taken is rarely limited to order numbers. It can include names, shipping addresses, email addresses, phone numbers, and payment details that tie directly to your household. Internal files exfiltrated often contain spreadsheets of customers, vendors, or employees that attackers later sell or publish. For an ordinary family, this means the same data used to ship your lotion can later be used to target you with phishing, identity theft, or unwanted solicitations. Children’s information linked to family orders can also surface, creating long-term exposure.
The Doxxing and Identity-Chain Implications
A single breach rarely stays isolated. Attackers map one piece of information to another until they build a complete picture. An email address from an Alaffia order can link to your social-media handles, your children’s gaming usernames, or school-related accounts. Once those connections exist, credential leaks cascade into account takeovers across unrelated services. Public reporting on similar incidents shows that doxxing chains often begin with seemingly harmless retail data and end with full personal dossiers posted on underground forums. Credential leaks like this one therefore threaten not only your privacy but also the security of every account that reuses the same password or security questions.