On January 25, 2024, British cosmetics retailer Lush appeared on the leak site of the Akira ransomware group. The listing states that attackers exfiltrated 110 GB of internal files during a ransomware incident and are preparing to publish them. The company, founded in 1995 and based in Poole, United Kingdom, has not yet issued a public breach notification detailing the exact number of people affected.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Lush
Get alerted the next time Lush files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Lush’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Akira leak page explicitly claims that the stolen archive contains personal documents especially passports, along with accounting, finance, tax, project, and client records. It does not specify how many customer or employee records are included, nor does it list every file type. The disclosure indicates the data was taken in a ransomware attack and that 110 GB of material is ready for release. No ransom demand figure or payment deadline is shown on the public page.
Why This Matters for You and Your Family
If you have ever bought from Lush, worked there, or had your details shared with the company as a supplier or partner, your information may now sit in an attacker-controlled archive. Passports and client documents represent high-value identity material that can be used for account takeover, loan fraud, or targeted phishing. Even when a company says it is “handling the matter,” the data already copied by ransomware operators rarely disappears. Ordinary customers and employees are left exposed long after the initial headlines fade.
The Doxxing and Identity-Chain Risk
A single leaked passport or client spreadsheet rarely stays isolated. Attackers and subsequent buyers routinely combine it with credentials from other breaches to build complete identity chains — linking your name, address, date of birth, email, phone number, and reused passwords. These chains fuel doxxing campaigns, SIM-swapping attempts, and harassment that can reach every member of a household. Credential leaks of this nature also cascade into gaming accounts belonging to you or your children, where the same email and password combinations are often reused, turning a corporate breach into persistent personal exposure across platforms.