On April 27, 2026, Avalon Flooring appeared on the leak site of the DragonForce ransomware group after the company’s internal files were allegedly exfiltrated during a ransomware attack. The New Jersey-based business, founded in 1958 and headquartered in Cherry Hill, installs residential and commercial flooring, supplies window treatments, and fabricates bathroom vanities. Public reporting indicates that the number of people whose personal information may have been exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch avalonflooring.com
Get alerted the next time avalonflooring.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about avalonflooring.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a classic ransomware operation in which attackers gained access to Avalon Flooring’s network, encrypted systems, and exfiltrated files before publishing a sample on their leak portal. The data consists of internal files rather than a structured database of customer records. No confirmed list of exposed record counts, customer names, or payment details has been published. The primary source remains the DragonForce leak site itself, indexed by ransomware.live at the onion address provided below.
Why This Matters for You and Your Family
When a local business like Avalon Flooring suffers a breach, the people most likely affected are ordinary customers who provided contact details, addresses, or payment information during a home renovation or purchase. If your email, phone number, or home address was stored in the company’s files, that information can now circulate among criminals. For families, a single leak often becomes the starting point for follow-on fraud, phishing texts, or identity theft attempts that can stretch for years. April 27, 2026 marks the public confirmation date; any stolen data could already be changing hands on underground forums.
The Doxxing and Identity-Chain Implications
Leaked internal files frequently contain spreadsheets that link customer names to addresses, phone numbers, order histories, and sometimes email accounts. Attackers and subsequent buyers can use these details to map relationships between your online handles, family members, and real-world identity. Credential leaks of this nature regularly cascade into account takeovers on email, banking, or shopping sites. Gaming accounts belonging to you or your children are especially vulnerable because kids often reuse passwords or email addresses tied to the same household. Once one account falls, the chain can lead to doxxing, harassment, or further extortion.