On October 14, 2025, Canadian retailer Radiant Beauty Supplies appeared on the leak site of the qilin ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details of the Incident
Public reporting indicates that qilin listed Radiant Beauty Supplies, a business operating since 1968 that supplies professional hair, esthetics, and related beauty products. The data exposed consists of internal files stolen in the ransomware incident. The number of people whose information was contained in those files remains unknown. No specific deadline for payment has been publicly detailed in available reporting, though ransomware groups routinely set short windows before full data publication.
Why This Matters for You and Your Family
When a retailer like Radiant Beauty Supplies suffers a breach, customer records, supplier details, employee information, and order histories can be exposed. If you or your family have ever placed an order, attended a training session, or worked with the company, your contact details, payment records, or personal documents may now sit in an attacker’s archive. Stolen internal files often contain spreadsheets that link names, addresses, phone numbers, and email accounts. Once that information reaches underground forums, it can be resold within hours. For ordinary families this means a sudden spike in phishing emails, fake delivery texts, or identity-theft attempts that feel personal because the attackers already know where you shop and what you buy.
The Doxxing and Identity-Chain Risk
Credential leaks like this one rarely stop at a single company. A password reused between your beauty-supplies account and your email, streaming service, or children’s gaming logins creates a chain. Attackers map these connections, turning one breach into multiple account takeovers. Public reporting describes how such chains frequently lead to doxxing: home addresses published alongside family names, phone numbers, and photos scraped from linked social-media profiles. Gaming accounts belonging to children are especially vulnerable because parents often share the same password or recovery email. The result can be harassment, swatting, or financial fraud that starts from something as ordinary as buying hair products.