Ransomware victim disclosure
← All victimsEternal Beauty Holdings Limited
listed as eternal.hk · Claimed by Lockbit5 · listed 4 hours ago
Status timeline
- ListedJun 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Hong Kong SAR China
- Listed on leak site
- Jun 20, 2026
About the victim
AI dossier — public-source company profileEternal Beauty Holdings Limited is a major distributor and retailer of luxury fragrance and beauty brands across China, Hong Kong, and Macau. The company represents a diverse portfolio of premium international brands including Hermès, Dolce & Gabbana Beauty, Coach, Chopard, and many others across fragrance and home fragrance categories.
- Industry
- Luxury Fragrance & Beauty Distribution
Attack summary
Severity: high — Data has been published by the threat actor (disclosed_status: data_published). Eternal Beauty Holdings Limited is a large multinational enterprise operating across multiple jurisdictions handling customer and commercial data for luxury brands; exfiltration at this scale poses significant business and customer privacy risk.LockBit5 claims to have attacked Eternal Beauty Holdings Limited and exfiltrated data. The group has published data from the breach; specific details on the scope of exfiltration (customer records, operational data, financial information, etc.) are not fully detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- business records
- potentially customer data
- operational information
What the group claims
Eternal Beauty Holdings Limited is the largest perfume group in China, including Hong Kong and Macau...
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

