DR.WU Skincare Co., Ltd.
bd_dc35cbc983d9d859 · schema v1 · pii pii-v2
Full breach record for DR.WU Skincare Co., Ltd. →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedSecurities and Futures Commission. DR.WU Skincare Co., Ltd.: The internal information system of DR.WU Skincare was the victim of a cyberattack. The company assessed that the impact on its operations is not significant. After detecting the anomaly, it immediately activated its security incident response mechanism and isolated the affected systems. The company has not found any personal data leakage to date. Linked ransomware group: lockbit5.
P pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 11, 2026
Press report
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
If an SEC 8-K, state-AG notice or victim statement lands, DisclosureLens merges it into an incident and links it here.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
lockbit5
According to ransomware.live, LockBit 5.0 ("ChuongDong") emerged in September 2025 as the group's resurgence following the February 2024 law enforcement takedown, introducing cross-platform payloads targeting Windows, Linux, and VMware ESXi with enhanced evasion capabilities and continuing the RaaS affiliate model of its predecessors.