On January 29, 2026, the Medusa ransomware group added Balloons.com to its leak site, claiming that internal files had been exfiltrated from the Alabama-based wholesale distributor of party supplies. Customers who have placed orders, attended training sessions, or created accounts on the site may have personal information now in the hands of attackers.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from Reporting
Public reporting indicates the company, headquartered at 16474 Greeno Road, Fairhope, Alabama, specializes in foil, latex, and themed balloon products. The Medusa leak page states that internal files were taken during a ransomware incident. No exact number of affected individuals has been disclosed. Available details list only that the data consists of internal files exfiltrated rather than a specific list of record types such as names, addresses, or payment details.
Why This Matters for You and Your Family
When a company that sells party supplies suffers a breach, the information exposed often includes customer names, shipping addresses, email addresses, and phone numbers tied to orders for birthdays, weddings, or school events. If you or your family have ever bought balloons or decoration kits from Balloons.com, those details could be used to impersonate you, send targeted phishing messages, or combine with other leaks to build a fuller picture of your household. Credential leaks like this one frequently cascade into account takeovers on other sites where the same email and password are reused.
The Doxxing and Identity-Chain Implications
Attackers rarely stop at one dataset. A single order record can link your email address to your physical home, children’s names on birthday orders, or even gaming usernames entered during promotions. Once connected, these fragments allow doxxing chains that expose family members across social media, gaming platforms, and data-broker profiles. Public reporting shows such combinations are routinely sold or published to increase pressure on victims. Protecting gaming accounts matters here because children’s usernames and shared family emails often appear in party-related purchases and can be the starting point for further targeting.