On June 27, 2024, Canadian cannabis post-harvest solutions provider Ayurcann appeared on the leak site of the qilin ransomware group. The listing states that internal files were exfiltrated during a ransomware attack; the exact number of records affected and the specific data types contained in those files remain undisclosed by both the threat actor and the company.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ayurcan
Get alerted the next time ayurcan files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ayurcan’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The qilin leak site entry, still accessible via its onion address as of the initial publication date, states that Ayurcann was listed after refusing or failing to meet the group’s extortion demands. The disclosure indicates that attackers successfully exfiltrated internal files but does not quantify the volume of data or list exact contents such as customer records, employee personal information, or intellectual property. Public reporting on similar qilin postings shows that when full data sets are eventually published, they frequently include spreadsheets, PDFs, and database exports that can contain names, contact details, financial documents, and operational records. Ayurcann has not yet issued a public breach notification detailing the scope, leaving affected individuals without official confirmation of what, if anything, pertains to their personal information.
Why This Matters for You and Your Family
When a company that handles regulated pharmaceutical-grade cannabis products suffers a ransomware breach, the exposure can reach beyond employees to suppliers, business partners, and customers whose details appear in invoices, shipping manifests, or compliance filings. Internal files exfiltrated in ransomware attacks often contain enough personally identifiable information to fuel identity theft, tax fraud, or phishing campaigns tailored to cannabis consumers who may already face stigma or heightened scrutiny. For your family this means heightened risk that a data broker, underground forum, or extortionist now holds details that could be combined with other breaches to build a complete profile. Even if you never directly purchased from Ayurcann, supply-chain partners or shared vendors could have indirectly exposed your information through joint records.
Doxxing and Identity-Chain Implications
Ransomware operators like qilin rarely stop at simple data theft; they publish samples and threaten full dumps to pressure victims, which inevitably seeds the information into multiple criminal ecosystems. Once internal files surface, threat actors and opportunistic criminals cross-reference emails, phone numbers, and addresses against credential-stuffing databases and people-search sites. This creates cascading doxxing chains where a single leaked work email can expose personal accounts, family member names, home addresses, and even children’s gaming usernames that reuse similar passwords. The result is not a one-time leak but an identity chain that can be exploited for months or years through account takeovers, SIM swapping, or targeted harassment.