On November 18, 2024, Pennsylvania-based office and institutional furniture supplier ATD-American appeared on the leak site operated by the blacklock Ransomware Group. The listing states that internal files were exfiltrated during a ransomware attack. The company has not yet published a formal breach notification detailing the number of people affected or the precise data categories involved.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ATD-American
Get alerted the next time ATD-American files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ATD-American’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The blacklock leak-site entry states that ATD-American suffered a ransomware intrusion and that attackers successfully removed internal files. No specific volume of records is listed, and the sample data download link does not publicly disclose customer, employee, or partner information. The disclosure indicates the data was taken prior to encryption attempts, a standard ransomware tactic. As of the publication date, the listing remains active without an announced extortion deadline or ransom amount.
Why This Matters for You and Your Family
If you have purchased furniture from ATD-American for your home, your child’s school, a medical facility, or any institutional setting, your contact details, order history, or payment records may be among the internal files now in criminal hands. Even when exact record counts remain unknown, the exposure of business-customer data frequently includes names, addresses, phone numbers, and email accounts. Once such information leaves a company’s control, it can be sold, traded, or used to launch targeted phishing campaigns against you or members of your household. Internal files exfiltrated in ransomware attack means the breach is not limited to a single spreadsheet; it can encompass years of transaction records that tie real-world identities to specific delivery addresses.
Doxxing and Identity-Chain Risks
Leaked customer and supplier files create long-term doxxing pathways. An address tied to a school furniture order can be cross-referenced with public records, social-media profiles, and children’s extracurricular accounts. Attackers routinely chain these fragments: an email from an institutional purchase becomes the recovery address for a parent’s personal account, which then reveals family photos, phone numbers, and geolocation data. The result is an identity chain that can lead to harassment, SIM-swapping attempts, or fraudulent loan applications in your name. Because many families use the same email or password across work, school, and personal services, a single breach can cascade into multiple account takeovers, including gaming profiles belonging to children that store credit-card details or chat histories.