Ransomware victim disclosure
← All victimsCoswell
Claimed by Metaencryptor · listed 3 years ago
Status timeline
- Listed
Aug 16, 2023
- Data leaked
At a glance
- Group
- Metaencryptor
- Status
- Data leaked
- Country
- Italy
- Sector
- Manufacturing
- Listed on leak site
- Aug 16, 2023
- Ransom demanded
- $157M
- Estimated revenue
- $157M
About the victim
AI dossier — public-source company profileCoswell is an Italian family-run group of companies specialising in the manufacturing and distribution of body and oral care products, health foods, masstige and selective fragrances, skin care, and cosmetics. The company serves the mass market as well as perfumeries and pharmacies. It reported revenue of approximately $157 million in 2021.
- Industry
- Personal Care Products & Cosmetics Manufacturing
Attack summary
Severity: high — Data has been published by the threat actor, confirming exfiltration of significant business data from a mid-sized manufacturing and distribution company; while no regulated medical or government data is explicitly stated, the scale of the operation and confirmed publication elevate this to high severity.Metaencryptor claims to have compromised Coswell and has published data (disclosed status: data_published); the leak post references $157M as the ransom figure, consistent with the company's reported revenue, and data exfiltration is implied by the published-data status.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial records
- Business operational data
- Employee records
- Customer and distribution partner data
- Proprietary product formulations or trade data
What the group claims
The Company Coswell is an italian family run group of companies specialized in manufacturing and distribution of body and oral care products, health foods, masstige and selective fragrances, skin care and cosmetics in the mass market, perfumeries and pharmacies. Revenue: $157M Year 2021
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
