On October 7, 2025, American Home Furniture and Mattress appeared on the leak site of the lynx Ransomware Group. The New Mexico-based retailer, which has operated for 84 years and employs 150 people across stores in Albuquerque, Santa Fe, and Farmington, is claimed to have had internal files exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch americanhome
Get alerted the next time americanhome files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about americanhome’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the company was listed on the lynx leak site hosted on the dark web. The data consists of internal files exfiltrated after the ransomware operators gained access to American Home’s systems. No confirmed total of affected individuals has been released, and the precise volume or sensitivity of the stolen documents remains unclear from available reporting. The listing appeared on October 7, 2025, consistent with the group’s typical practice of publishing victim data when ransom demands go unmet.
Why This Matters for You and Your Family
When a local business like American Home suffers a breach, customer records, vendor contracts, employee payroll files, and other personal information can be exposed. If you have ever bought furniture there, filled out a credit application, provided your driver’s license for delivery, or had an employee file processed by the company, your data may now sit in an attacker’s archive. Names, addresses, phone numbers, email addresses, and financial details are the everyday building blocks criminals need to open accounts in your name or target your family with phishing and identity theft. Children’s information linked to family purchases can also surface, creating long-term risks that grow quietly until harm appears on a credit report or in a stranger’s message.
The Doxxing and Identity-Chain Implications
Stolen internal files often contain more than isolated records. They can include spreadsheets that link customer emails to home addresses, phone numbers to order histories, and employee details to family members. Attackers chain these fragments together with data from other breaches to build complete profiles. A single leaked furniture-store record can anchor a doxxing chain that reveals where your family lives, what schools your children attend, and which online accounts share the same passwords. Credential leaks like this one frequently cascade into gaming-account takeovers, especially for children who reuse email addresses or simple passwords across entertainment platforms and retail sites.