On April 26, 2024, Singapore-based soya bean chain Mr Bean appeared on the leak site of the spacebears ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which operates more than 60 stores across Singapore and Asia. The disclosure does not specify the number of people affected or list exact data types beyond claiming that internal files were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Mr Bean
Get alerted the next time Mr Bean files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Mr Bean’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The spacebears leak site entry for Mr Bean, first observed on April 26, 2024, claims the company suffered a ransomware intrusion in which attackers copied internal files before encrypting systems. The listing does not quantify the volume of data or name specific categories such as customer records, payment details, or employee information. It also does not disclose any ransom demand or negotiation status. Public views of the onion address show only the company name, logo, and a brief statement that data had been exfiltrated.
Mr Bean, founded in 1995, is a well-known regional retailer of soya bean drinks, snacks, ice creams and pastries. The breach therefore touches any customer, employee or supplier whose information may have been stored in the compromised internal systems.
Why this claimed breach Matters for You and Your Family
When a familiar local brand like Mr Bean is hit, ordinary customers and staff face tangible risk. If you have ever bought a drink at one of their outlets, completed a loyalty form, applied for a job, or had your details recorded during a purchase or promotion, those records may now sit in an attacker-controlled archive. Even though the leak-site listing does not detail what was taken, internal files in a retail environment routinely contain names, contact numbers, email addresses, dates of birth, partial payment information and delivery addresses.