Lifesum Data Breach

Alleged

Ransomware claim involving Lifesum.

Published: Aug 19, 2026 Direwolf
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Lifesum
Industry
Consumer Health
Threat Actor
Direwolf
Date of Incident
Aug 19, 2026

Executive Summary

Lifesum, a prominent Swedish company operating in the healthcare technology and consumer health sector, has been identified as a victim by the DireWolf ransomware group. The listing occurred on August 19, 2026, as reported by SOCRadar’s Dark Web Monitoring. Lifesum’s core business revolves around a popular nutrition and health app that manages user dietary information, weight history, and integrates data from health devices. This makes the company a potentially attractive target for ransomware actors due to the sensitive nature of the personal data it handles and its large user base. DireWolf’s recent activity, as of August 19, includes other listed victims such as PayUp in Financial Services, InfoFlo CRM in Technology, and Photon Health, Inc. in Healthcare. The group’s targeting strategy often focuses on organizations where the sensitivity of data can be leveraged to increase extortion pressure, aiming to go beyond the impact of a direct ransom demand. A consumer health platform with a history of credential exposure aligns precisely with this operational profile, suggesting a strategic choice by DireWolf to target Lifesum.

Technical Analysis

SOCRadar’s Dark Web Monitoring identified a listing for Lifesum by the DireWolf ransomware group on August 19, 2026. The analysis of stealer-log telemetry associated with the domain lifesum[.]com revealed 25 customer credential records. These records have a freshness window spanning from March 2024 to August 19, 2026, indicating a continuous exposure of customer accounts for approximately two and a half years, concluding on the day of the publication. This ongoing harvest of customer accounts is attributed to potential user-side phishing attacks targeting Lifesum accounts, exploitation of platform authentication weaknesses, or a combination of both, leading to a dominant profile of customer account takeover. The presence of 25 exposed customer records over an extended period carries significant implications, particularly concerning GDPR compliance for Lifesum. As a Swedish company handling sensitive personal data for millions of users, including dietary habits and health metrics, a personal data breach requires reporting to Sweden’s data protection authority (IMY) within 72 hours of awareness. The sustained credential exposure over 2.5 years, culminating on the publication date, likely meets this reporting threshold, highlighting a critical data protection concern. While the 25 customer records do not definitively confirm that DireWolf gained access to Lifesum’s backend systems through these compromised accounts, the prolonged and continuous credential harvesting is consistent with pre-attack reconnaissance and intelligence gathering. Such activity is often preparatory to an extortion claim, allowing the threat actor to build leverage before initiating a ransomware attack or data exfiltration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.