Lush cyber attack claimed by Akira ransomware gang
The group says it has accessed and will release data including passports, tax information, and client data


A cyber attack on the UK-based cosmetics and bath product company Lush has been claimed by the Akira ransomware group.
The incident was first reported on 11 January, with Lush saying it was working with external IT forensic specialists to try to uncover what happened.
"The investigation is at an early stage but we have taken immediate steps to secure and screen all systems in order to contain the incident and limit the impact on our operations," the company said in a statement. "We take cyber security exceptionally seriously and have informed relevant authorities."
Now, the Akira ransomware gang appears to have claimed responsibility for the attack.
"110 GB of their files are prepared for uploading. There are a lot of personal documents especially passports. Accounting, finance, tax, projects, clients information and much more could be found in the archives we are going to share," it says in a post shared by the RansomLock open source ransomware-tracking website.
Read more
Lush says it’s now operating largely as normal. However, Brian Boyd, head of technical delivery at security firm i-confidential, says there may be more effects to come.
"Lush is a massive cosmetics company that operates globally, so the perpetrators have potentially gained access to a treasure trove of customer data, which they could use to extort the company or to execute targeted phishing scams," he says.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Lush must inform impacted parties as a priority so they can take steps to protect their data. Customers must understand if and how their data has been impacted, because any compromised information could be used against them."
The Akira group was first observed during spring last year and was found targeting Cisco VPNs that were not configured for multi-factor authentication (MFA). According to Sophos, it has mainly targeted organizations located in Europe, North America, and Australia, attacking sectors as diverse as government, manufacturing, technology, education, consulting, pharmaceuticals, and telecommunications.
RELATED RESOURCE
What are the essentials of a developer security platform?
The group has already been busy this year, carrying out several attacks: Earlier this month, it was confirmed to be the gang behind the hack of Toronto Zoo, with the group saying it was publishing 133GB of data, including NDAs and confidential agreements, as well as personal files such as drivers' licences.
It has also claimed responsibility for the recent hack of Finnish IT services and enterprise cloud hosting provider Tietoevry. The attack affected one of Tietoevry's data centers in Sweden affecting cloud hosting customers including Sweden's largest cinema chain, Filmstaden, retail chain Rusta, and numerous universities and colleges.
In the last few days, the group has claimed attacks on Brazilian Business Park, ANI Networks, Ding Sheet Metal and Valley Telecom Group.
"It was also responsible for breaching almost 465,000 records in 2023 and had an average ransom of $1 million," says Rebecca Moody, head of data research at Comparitech.
In response to Akira's claims, Lush told ITPro: "We know the group responsible for this incident have made claims regarding data they have taken relating to Lush. Alongside our specialist partners we are working hard to validate these claims."
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won't be the last
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott
-
‘Insiders don’t need to break in’: A developer crippled company networks with malicious code and a ‘kill switch’ after being sacked – and experts warn it shows the huge danger of insider threats
News Security experts have warned ITPro over the risks of insider threats from disgruntled workers after a software developer deployed a 'kill switch' to sabotage his former employer’s networks.
By Ross Kelly
-
Healthcare systems are rife with exploits — and ransomware gangs have noticed
News Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
By Nicole Kobie
-
Alleged LockBit developer extradited to the US
News A Russian-Israeli man has been extradited to the US amid accusations of being a key LockBit ransomware developer.
By Emma Woollacott
-
February was the worst month on record for ransomware attacks – and one threat group had a field day
News February 2025 was the worst month on record for the number of ransomware attacks, according to new research from Bitdefender.
By Emma Woollacott
-
CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted
News The Medusa ransomware as a Service operation compromised twice as many organizations at the start of 2025 compared to 2024
By Solomon Klappholz
-
Warning issued over prolific 'Ghost' ransomware group
News The Ghost ransomware group is known to act fast and exploit vulnerabilities in public-facing appliances
By Solomon Klappholz