On August 21, 2025, Japanese cosmetics maker Mandom Corporation appeared on the leak site of the ransomware group World Leaks. The company, known for brands such as Gatsby and Lucido-L, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose information was taken remains unknown, any customer, employee, or supplier whose details were stored in those systems could now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Mandom Corporation
Get alerted the next time Mandom Corporation files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Mandom Corporation’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that World Leaks posted Mandom Corporation on its dark-web leak site on August 21, 2025. The listing states that internal files were exfiltrated during a ransomware incident. No sample data has been publicly released in the initial posting, and the precise volume or type of records taken has not been disclosed by either the company or the attackers. Mandom has not yet issued a public statement confirming the breach or detailing what customer, employee, or partner information may have been inside the stolen files.
Why This Matters for You and Your Family
When a company that sells everyday personal-care products suffers a breach, the consequences reach ordinary households. Purchase records, contact details, payment information, or employee payroll data can give criminals the starting point they need to target you. Once your email, phone number, or address is in the hands of threat actors, it can be sold, combined with other leaks, and used for phishing, identity theft, or harassment that affects every member of your family.
Credential leaks like this one frequently cascade into account takeovers. If you have ever used the same password on a shopping site as you do for email or banking, the exposure of Mandom data raises the risk that someone else could seize control of those accounts.