On June 09, 2024, the ransomware group known as BlackSuit listed a-g.com on its leak site, announcing the exfiltration of 38GB of internal files from the company and giving it four days to negotiate before public release of the data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch a-g.com
Get alerted the next time a-g.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about a-g.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The BlackSuit leak page states that the data was taken during a ransomware attack and totals 38GB affecting an estimated 150,000 records. It does not specify the exact types of files taken beyond describing them as internal documents. The listing includes a countdown that expired shortly after the initial publication, after which BlackSuit made at least a portion of the archive available for download. The disclosure indicates the victim operates under the domain a-g.com; no further details on the company’s industry or the precise systems compromised appear in the primary listing.
Why This Matters for You and Your Family
When a company’s internal files are taken in a ransomware operation, the information often includes employee records, customer databases, contracts, or correspondence that contain names, addresses, dates of birth, Social Security numbers, or financial details. Even if you never directly interacted with a-g.com, your data may have been shared with them as a vendor, client, or through a partner. Once published on a leak site, that information circulates quickly among identity thieves, fraud rings, and opportunistic criminals. The result is elevated risk of account takeovers, tax fraud, medical identity theft, or targeted phishing aimed at you or members of your household.
Doxxing and Identity-Chain Risks
Leaked internal files frequently contain email addresses, usernames, phone numbers, or customer IDs that attackers can cross-reference with other breaches. These linkages create identity chains that reveal far more than any single record suggests. A seemingly harmless work email can be tied to personal accounts, social-media handles, or even children’s online profiles. Public reporting shows that ransomware operators increasingly sell or publish these datasets precisely because they accelerate doxxing campaigns. Credential leaks of this nature routinely cascade into gaming-account takeovers, where stolen logins grant access to linked payment methods, chat histories, and real-world contact information.