Ransomware victim disclosure
← All victimsLIFESTRAW.COM
Claimed by Clop · listed 5 days ago
Status timeline
- ListedAug 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Retail & E-Commerce
- Listed on leak site
- Aug 12, 2026
About the victim
AI dossier — public-source company profileLifeStraw is a certified B Corp and Climate Neutral brand that designs and sells water filtration products including pitchers, dispensers, bottles, straws, gravity filters, and high-volume solutions for home, travel, outdoor, and emergency use. The company validates all products through WHO, US EPA, NSF, and WQA-aligned protocols with an ISO-certified in-house lab. Every product purchase funds a year of safe water for a child in need through their Give Back program.
- Industry
- Water Filtration & Purification Products
Attack summary
Severity: medium — Disclosed status indicates data publication claim by CLOP, but the leak post excerpt provided contains only a generic queue message with no proof files, data inventory details, or confirmation of what was actually exfiltrated. LifeStraw handles customer PII (orders, addresses) and potentially business data, warranting medium severity pending additional evidence.The CLOP ransomware group listed LifeStraw.com in their victim queue with a 'data_published' disclosure status, indicating claimed exfiltration of company data. No specific details about encrypted systems, data types, or proof files are provided in the available leak post excerpt.
Original description
AI-summarised, not from the leak postLifeStraw is an American consumer goods company specializing in portable water filtration and purification products. Founded in Switzerland and now headquartered in the United States, it produces filters, straws, bottles, and pitchers designed to remove bacteria, parasites, and microplastics from water. The company serves outdoor enthusiasts, travelers, and humanitarian relief efforts globally, making safe drinking water accessible in both recreational and emergency contexts.
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

