On December 02, 2024, Avico Spice of New York State appeared on the Medusa ransomware group’s leak site, claiming the company suffered a ransomware attack in which internal files were exfiltrated. The family-owned spice packer, formerly known as A. Vitagliano & Company and established in 1926, supplies grated cheese, fruit and nut products, flavorings and spices sold in retail and food-service packaging. Anyone whose personal information appears in those stolen files—employees, customers, suppliers or business partners—now faces immediate exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Avico Spice
Get alerted the next time Avico Spice files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Avico Spice’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Medusa leak-site entry states that internal files were exfiltrated during a ransomware incident. The listing does not disclose the exact number of records affected, the specific types of documents taken, or any ransom demand. It simply lists Avico Spice as a victim and provides a sample of the allegedly stolen material. The disclosure indicates the data was obtained through a ransomware deployment, after which the attackers chose to publish the company on their public shaming portal when negotiations presumably failed.
Why This Matters for You and Your Family
When a local manufacturer like Avico Spice is hit, the breach rarely stays inside the company walls. Payroll records, vendor contracts, customer orders, employee tax forms and health-insurance documents often contain names, addresses, Social Security numbers, dates of birth and banking details. If any of those records belong to you or someone in your household, the information may now be in the hands of professional extortionists. Even if you never bought their spices, your data may have traveled through their supply chain or HR systems. The exposure is personal, and the clock is ticking.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at posting company files. They harvest any personally identifiable information to launch follow-on attacks: credential stuffing, tax-refund fraud, medical-identity theft and full doxxing campaigns. A single leaked work email or phone number can be chained with data from other breaches to map your entire digital life—online shopping accounts, children’s school portals, even gaming usernames. These identity chains let attackers impersonate you or your family members with increasing precision. Public reporting on similar incidents shows that employees of breached vendors frequently see targeted phishing and account takeovers within weeks.