USTAR Listed by thegentlemen Ransomware Group
If you are a customer of Ustar, here’s what is being claimed, and what it would mean for you.
www.ustar.co.th USTAR specializes in beauty products that enhance women's appearance and confidence, offering high-quality items at affordable prices. Their product range includes cosmetics for the eyes, face, and lips, such as foundations, lipsticks, and skincare creams. USTAR aims to cater to women's fashion, beauty, and lifestyle needs. The company is committed to providing friendly service and support to its clients.
— from The Gentlemen’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Assessing Ustar as a vendor?
Check your own domain — free, no cardEnter a work email. We count the addresses at that domain sitting in the leaked-data corpus, and how many arrived with a password.
Were you personally caught up in this? Run a free 15-second personal scan.
On January 20, 2026, Thai cosmetics company USTAR appeared on the leak site operated by the ransomware group known as thegentlemen. The listing states that internal files were exfiltrated during a ransomware attack on the company, which sells affordable beauty and skincare products across Thailand.
Reported Details of the Incident
Public reporting from ransomware trackers indicates the data was taken from www.ustar.co.th. The company’s ZoomInfo profile describes it as a cosmetics business focused on eye, face, and lip products including foundations, lipsticks, and creams. No confirmed victim count has been published, and the precise volume or types of files remains unclear beyond the description of internal files exfiltrated. The listing appeared on the group’s onion site, which is indexed by services such as ransomware.live.
Why This Matters for You and Your Family
When a company that holds customer orders, payment details, or contact information is breached, your personal data can end up in the hands of criminals. Even if you only bought lipstick or face cream, the exposed files may contain your name, delivery address, phone number, or email. Once that information leaves the company’s control, it can be sold, combined with other leaks, and used to target you or members of your household with phishing, identity theft, or harassment. Children’s accounts linked to the same family address or parental email are especially vulnerable because gaming platforms and social apps often reuse the same credentials.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
The Doxxing and Identity-Chain Risk
A single breach rarely stays isolated. Criminals map connections between your email, phone, username, and real-world identity to build a complete profile. Public reporting shows that ransomware operators frequently sell or publish stolen data that fuels follow-on attacks. A leaked order record can reveal your child’s nickname or gaming handle, which then links to an unprotected Roblox or Discord account. These identity chains allow attackers to move from one service to another, escalating from simple data theft to full account takeover and doxxing.
The Gentlemen Ransomware Group’s Track Record
Public reporting attributes the group’s emergence to mid-2024. It has targeted organizations across Asia and Europe, with prior victims including manufacturing, logistics, and retail companies. The typical playbook begins with initial access through phishing or exploited remote desktop services, followed by exfiltration of internal documents, and then extortion demands backed by the threat of public leak. The group posts samples and full datasets on its dedicated leak site when victims do not pay.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, then use the cleanup to remove what you can.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak that touches your family is caught in hours rather than months.
- Rotate any password you used at ustar.co.th anywhere else it is reused, and switch on 2FA through an authenticator app instead of SMS.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts tied to the same address or parental email.
- Let remediation specialists handle takedown requests for any exposed personal records that appear on data broker sites or underground forums.
The incident shows that even purchases as ordinary as cosmetics can expose your family to long-term risk once data leaves a company’s systems. Taking concrete steps now limits how far attackers can travel along the identity chain that begins with this claimed breach. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Gould Sherwood Consulting Listed by thegentlemen Ransomware Group
gouldsherwood.com zoominfo.com/c/gould-sherwood-consulting-llc/347553210 Gould-Sherwood Consulting i…
Espac Listed by thegentlemen Ransomware Group
espac.cl zoominfo.com/c/espac/425816287 ESPAC Construcción is a leading Chilean company based in San…
Layher Listed by thegentlemen Ransomware Group
layher.cl zoominfo.com/c/layher-del-pacífico-sa--layher-chile/1319092699 Layher Chile is the local …