On November 28, 2024, the ALLTUB Group (alltub.com) appeared on the leak site operated by the fog ransomware group. The listing states that attackers exfiltrated 20 GB of internal files during a ransomware incident. The notification does not disclose the exact number of people affected or list specific categories of personal data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ALLTUB Group (alltub.com)
Get alerted the next time ALLTUB Group (alltub.com) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ALLTUB Group (alltub.com)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The fog ransomware group’s onion site lists ALLTUB as a victim and claims the company failed to meet an extortion deadline. The entry states that 20 GB of internal files were taken. No sample data has been published yet, and the listing does not detail which systems were initially compromised or the precise records contained in the archive. Public views of the leak site, archived via ransomware.live, show the posting dated November 28, 2024.
Why This Matters for You and Your Family
When a company that provides services to households has its internal files stolen, the information inside can easily include names, addresses, contact details, or payment records tied to customers. Even if the disclosure does not quantify affected records, any leak of internal files creates downstream risk for the individuals whose data was stored. Internal files exfiltrated in ransomware attacks frequently contain spreadsheets, contracts, support tickets, or employee records that reference real customers and their families. Once that material surfaces on a criminal forum, it can be repackaged and sold for identity theft, phishing, or further extortion.
The Doxxing and Identity-Chain Risks
Stolen internal files often contain enough fragments—email addresses, phone numbers, account references, or employee details—to link an individual’s online handles to their real-world identity. Attackers chain these fragments across multiple breaches, building profiles that expose family members, including children. Credential leaks of this nature frequently cascade into gaming-account takeovers, where stolen corporate logins or personal emails are tested against Steam, Roblox, or Discord. A single exposed email from an ALLTUB file can become the starting point for doxxing chains that reveal home addresses, children’s names, and linked accounts.