LFHCNA A.I CyberSecurity Scoring
LFHCNA
Company Information
Website:https://www.lush.com/us/en_us
Employees number:3,639
Number of followers:170,747
NAICS:32562
Industry Type:Personal Care Product Manufacturing
Homepage:lush.com
LFHCNA Risk Score (AI oriented)
Between 0 and 549
LFHCNAPersonal Care Product Manufacturing
Updated:
06/06/2026
06/06/2026
543/1000
Critical
C
LFHCNA Global Score (TPRM)
xxxx
LFHCNAPersonal Care Product Manufacturing
Score locked

LFHCNACritical
Current Score
543C (CRITICAL)
01000
2 incidents
-258 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
543
MAY 2026
539
APRIL 2026
537
MARCH 2026
533
FEBRUARY 2026
528
JANUARY 2026
524
DECEMBER 2025
519
NOVEMBER 2025
769
Ransomware
14 Nov 2025 • LFHCNA
Lush: Akira ransomware starts hitting Nutanix AHV
Akira Ransomware Expands Targets to Nutanix AHV in Critical Sectors
511
CRITICAL-258
LUS1780770254
Akira Ransomware Expands Targets to Nutanix AHV in Critical Sectors
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and European law enforcement, has issued an updated advisory on the Akira ransomware operation, warning of its evolving tactics and heightened threat to critical infrastructure. The group has now added Nutanix AHV virtual machines to its list of targets, alongside previously exploited platforms like VMware ESXi and Hyper-V.
First detected in June 2025, Akira’s attacks on Nutanix hypervisors widely used in healthcare, finance, and government sectors were confirmed as recently as November 2025. The group, linked to Russian cybercriminals, has amassed $244.17 million in ransom payments and increasingly targets manufacturing, education, IT, healthcare, financial services, and food/agriculture sectors, despite its historical focus on small and medium businesses.
Akira affiliates gain initial access through multiple vectors, including:
- Exploiting CVE-2024-40766, a critical SonicWall SSL-VPN vulnerability affecting over 438,000 exposed devices (per BitSight research).
- Compromised VPN credentials, brute-force attacks, or password spraying (e.g., using SharpDomainSpray).
- Exploiting SSH on routers or unpatched Veeam Backup servers (CVE-2023-27532, CVE-2024-40711).
Once inside, attackers move laterally to Nutanix AHV platforms, deploying encryption payloads that risk exposing business-critical and sensitive data. Notably, Akira has bypassed multi-factor authentication (MFA) in some attacks by compromising one-time password seeds or generating fraudulent tokens.
The advisory includes updated indicators of compromise (IOCs) and mitigation strategies, though core defenses remain consistent: patching vulnerabilities, enforcing MFA, strong password policies, network segmentation, and maintaining secure backups.
Akira, an offshoot of the defunct Conti ransomware group, emerged in 2023 and has since claimed high-profile victims, including Lush, Stanford University, Tietoevry, and the Toronto Zoo. Its expansion to Nutanix AHV signals a sophisticated, adaptive threat requiring heightened vigilance across critical sectors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
769
SEPTEMBER 2025
769
AUGUST 2025
769
JULY 2025
769
JUNE 2011
769
Cyber Attack
16 Jun 2011 • LFHCNA
Lush Fresh Handmade Cosmetics North America
Cyberattack on Lush Cosmetics Retail Chain
751
HIGH-18
LUS185221124
Lush, the well-known cosmetics retail chain, has become the focus of a cyberattack, and a thorough investigation is currently underway.
In 2011, the store faced a hacking incident leading to the temporary suspension of their website and online sales.
A representative from Lush is collaborating with law enforcement and external IT forensic specialists to address and resolve the current issue.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for LFHCNA ??
What was LFHCNA's A.I Rankiteo Cyber Score in May 2026 ??
What was LFHCNA's A.I Rankiteo Cyber Score in April 2026 ??
What was LFHCNA's A.I Rankiteo Cyber Score in March 2026 ??
What was LFHCNA's A.I Rankiteo Cyber Score in February 2026 ??
What was LFHCNA's A.I Rankiteo Cyber Score in January 2026 ??
What was LFHCNA's A.I Rankiteo Cyber Score in December 2025 ??
What was LFHCNA's A.I Rankiteo Cyber Score in November 2025 ??
What was LFHCNA's A.I Rankiteo Cyber Score in October 2025 ??
What was LFHCNA's A.I Rankiteo Cyber Score in September 2025 ??
What was LFHCNA's A.I Rankiteo Cyber Score in August 2025 ??
What was LFHCNA's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on LFHCNA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with LFHCNA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view LFHCNA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?