On April 19, 2024, the domain marykay.com appeared on the leak site operated by the dispossessor Ransomware Group. The listing states that internal files were exfiltrated during a ransomware attack on the cosmetics company. The group has not publicly detailed the volume or exact nature of the stolen data, and Mary Kay has not yet issued a formal customer notification quantifying affected records.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch marykay.com
Get alerted the next time marykay.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about marykay.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The dispossessor leak site entry states that Mary Kay was compromised through a ransomware operation and that attackers successfully removed internal files. No specific record count is provided, nor does the listing enumerate the precise data types beyond the general description of internal files exfiltrated. The disclosure does not name the initial access vector or the encryption status of any systems. As of the publication date, the site continued to host the claim without releasing sample data or setting an explicit public extortion deadline.
Why This Matters for You and Your Family
When a company that sells directly to consumers suffers a ransomware breach, the information it holds often includes names, addresses, phone numbers, email addresses, and purchase histories tied to individual customers and independent beauty consultants. Even though the exact contents remain undisclosed, any exposure of such details increases the chance that you or members of your household could face targeted phishing, identity theft attempts, or unwanted solicitations. Families who have ordered products, hosted parties, or maintained consultant relationships with Mary Kay may find their contact information now circulating in criminal circles.
Internal files can also contain employee records, vendor contracts, or partner information that, once leaked, create secondary risks for anyone whose details appear inside them.