On December 27, 2025, the ransomware group DragonForce added Caramel to its leak site, claiming that it had exfiltrated internal files from the London-based apparel manufacturer founded in 1999.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Caramel
Get alerted the next time Caramel files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Caramel’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that DragonForce claims to have stolen internal documents during a ransomware incident at Caramel. The company, which produces and sells clothing, has not yet released a public statement detailing the breach scope or notifying affected parties. Available reporting describes the data as internal files, though the exact volume and specific categories of information remain unconfirmed by independent verification. The listing appeared on the group's onion-based leak site, a common tactic used to pressure victims into payment.
Caramel operates from headquarters in London, England. No customer count or precise number of individuals whose data may be exposed has been disclosed. Ransomware.live, which tracks such incidents, mirrored the DragonForce posting, giving the event wider visibility within cybersecurity circles.
Why This Matters for You and Your Family
When a company like Caramel suffers a breach, the information it holds can include supplier details, employee records, customer orders, or payment information. If your name, address, email, phone number, or payment data was connected to Caramel, that information may now be in the hands of attackers. Internal files often contain spreadsheets or databases that link personal details across multiple systems, making it easier for criminals to build a complete profile on you.