On December 19, 2025, French cosmetics manufacturer Capsum appeared on the leak site of the safepay ransomware group. The company, which produces beauty and skincare products using patented microfluidic technology, may have had internal files stolen during a ransomware attack. While the exact number of people affected remains unknown, any customer, supplier, or employee whose personal information passed through Capsum’s systems could now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch capsum.com
Get alerted the next time capsum.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about capsum.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that safepay posted proof of the breach on its dark-web blog, claiming to have exfiltrated internal documents from Capsum’s network. The data includes files that ransomware operators typically harvest: contracts, employee records, customer lists, and operational spreadsheets. No sample data has been publicly released beyond the initial announcement, and Capsum has not yet issued a formal statement confirming the volume or exact nature of the stolen information. The incident follows the group’s standard pattern of encrypting victim systems before exfiltrating selected folders for leverage.
Why This Matters for You and Your Family
When a manufacturer like Capsum is hit, the ripple effects reach ordinary people. Customers who placed online orders may have had names, shipping addresses, phone numbers, and payment details stored in the compromised files. Employees and contractors could see payroll records, Social Security numbers, or health information leaked. Even if you never bought directly from Capsum, your data may appear in supplier spreadsheets or vendor agreements shared with the company. Once these records surface on criminal forums, they become raw material for identity theft, phishing campaigns, and long-term fraud targeting you and your family.
The Doxxing and Identity-Chain Risk
Stolen internal files often contain more than names and addresses. They frequently link email accounts, customer IDs, phone numbers, and sometimes notes about family members or children enrolled in brand loyalty programs. These connections create identity chains that criminals exploit. A seemingly minor leak can lead to gaming-account takeovers when the same password or recovery email is reused. Public reporting shows that credential leaks of this type regularly cascade into doxxing, where attackers map your online handles back to your real-world identity and home address. Protecting gaming accounts belonging to you or your children is therefore essential, because those platforms become entry points for broader harassment once personal details are known.