Cosmesia Listed by The Gentlemen Ransomware Group
If you are a customer of Cosmesia, here’s what is being claimed, and what it would mean for you.
nutritionprofess.com Nutrition Profess Public Company Limited is a leader in the production of dietary supplements and cosmetics under customer brands. They focus on planning and developing high-quality, distinctive products while providing friendly consulting services. The company aims to enhance health and well-being through innovative and effective products tailored to diverse client needs. Their commitment to quality and customer satisfaction drives their mission to promote better health
— from The Gentlemen’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On March 9, 2026, Nutrition Profess Public Company Limited appeared on the leak site of the ransomware group known as The Gentlemen. The company, which produces dietary supplements and cosmetics for customer brands, had internal files exfiltrated during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, anyone who has purchased from the company, worked with it, or had their details stored in its systems could be affected.
Watch Cosmesia
Get alerted the next time Cosmesia files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Cosmesia’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Nutrition Profess, reachable at nutritionprofess.com, had internal documents taken and later listed for download or extortion on the group’s dark-web portal. The breach involved internal files rather than a clearly defined customer database, but such material frequently contains supplier lists, employee records, customer orders, and contact information. No confirmed total of records or specific data fields has been published, yet the presence of the company on a ransomware leak site signals that sensitive business data may now be in the hands of criminals.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why This Matters for You and Your Family
When a company that handles health-product orders suffers a breach, your name, delivery address, phone number, email, and payment details can end up exposed. For many families this means more than spam: it can lead to targeted fraud, phishing texts that look like order confirmations, or identity thieves using your details to open accounts. Children’s information sometimes appears in family orders or school-program shipments, creating long-term risks that parents must address quickly.
The Doxxing and Identity-Chain Implications
Stolen internal files often link email addresses to real names, home addresses, and order histories. Attackers can combine this data with information from other breaches to build detailed profiles. A single credential leak from this incident can cascade into gaming-account takeovers if your family shares passwords across services. Once a gamer tag is connected to a real identity and home address, doxxing escalates rapidly through social engineering and public records. Credential leaks like this one frequently start chains that expose children’s accounts alongside adult ones.
The Gentlemen’s Publicly Known Track Record
Public reporting attributes The Gentlemen ransomware group with emerging in late 2024. The group has listed dozens of organizations on its leak site, typically small-to-medium businesses in manufacturing, services, and retail. Their standard playbook involves gaining initial access through phishing or exploited remote-desktop credentials, exfiltrating documents before encryption, and then demanding payment to prevent publication. If no ransom is paid they publish samples and offer the full archive for sale or free download, a pattern seen in earlier incidents tracked by ransomware-monitoring services.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, with cleanup handled by the service.
- Rotate any password you used on nutritionprofess.com or related supplier portals anywhere it has been reused, and switch on 2FA through an authenticator app rather than text messages.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak that touches your family is caught in hours, not months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that can chain back to the same address or email.
- Let remediation specialists perform hands-on takedown requests across data brokers and leak sites on your behalf while you focus on securing accounts.
The incident shows how quickly business data breaches become personal threats. Acting promptly on exposed credentials and connected identities limits the damage. Start your DoxxScan trial for continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and family coverage that includes children’s gaming accounts. DoxxScan by GalaxyWarden is effective for protecting both your accounts and your children’s gaming profiles because credential leaks like this one routinely cascade into account takeovers and doxxing chains.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Zelham Listed by The Gentlemen Ransomware Group
zelham.com rocketreach.co/zelham-inc-profile_b580fe5ef66e1a3f Zelham, Inc. is a U.S. hospitality ren…
Wooshin Systems Co Listed by The Gentlemen Ransomware Group
wooshinsys.com wooshinna.com finance.yahoo.com/quote/017370.KS/financials/ Wooshin Systems Co., Ltd.…
Wooshin Safety Systems Co Ltd Listed by The Gentlemen Ransomware Group
wooshinsys.co.kr wooshinsys.com finance.yahoo.com/quote/017370.KS/financials/ WOOSHIN SAFETY SYSTEMS…