Ransomware victim disclosure
← All victimsunilever
Claimed by Warlock · listed 1 year ago
Status timeline
- ListedJun 11, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- Netherlands
- Sector
- Consumer Services
- Listed on leak site
- Jun 11, 2025
About the victim
AI dossier — public-source company profileUnilever is a multinational corporation founded in 1929 with headquarters in London, England and Rotterdam, Netherlands. The company manufactures and sells branded consumer goods across food, beverages, cleaning agents, and personal care products, with distribution in over 190 countries and a portfolio of over 400 brands including Dove, Lipton, and Ben & Jerry's.
- Industry
- Consumer Goods & Personal Care
- Address
- London, England and Rotterdam, Netherlands
- Founded
- 1929
Attack summary
Severity: high — Confirmed data publication by the group against a major multinational corporation with global operations and significant brand portfolio; multinational enterprises typically hold sensitive business, financial, and employee data at scale.The Warlock group claims to have compromised Unilever and published exfiltrated data, though specific details regarding the scope of encryption, data types, or operational impact are not provided in the available leak post.
Original description
AI-summarised, not from the leak postUnilever is a multinational corporation that sells branded consumer goods. Founded in 1929 and based in London, England and Rotterdam, Netherlands, their products range across food, beverages, cleaning agents, and personal care products. Unilever has products available in over 190 countries, and owns over 400 brands including Dove, Lipton, and Ben & Jerry's.
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

