On December 26, 2022, European furniture retailer Casa International appeared on the leak site operated by the AvosLocker ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the company, which operates stores across multiple countries. The disclosure does not specify the number of people affected or detail exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Casa International
Get alerted the next time Casa International files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Casa International’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The AvosLocker leak site entry states that Casa International suffered a ransomware incident in which attackers extracted internal files before encrypting systems. No victim count is provided, and the listing does not break down the categories of data involved beyond stating that internal files were exfiltrated. The notification carries the standard extortion format used by the group, implying that the files will be published if demands are not met. Public records show the listing went live on December 26, 2022, and the exact deadline set by the attackers is not visible in the current mirror hosted on ransomware.live.
Why This Matters for You and Your Family
When a retailer like Casa International loses control of internal files, the information often includes customer orders, delivery addresses, payment details, employee payroll records, or supplier contracts. Even if the leak site does not list every data type, any of those records can be combined with other breaches to build a profile of your household. If you have shopped at Casa International, placed an order, or had furniture delivered, your name, address, phone number, or email may now sit in an attacker-controlled archive. That exposure increases the chance that fraudsters will target you or your family members with phishing, identity theft, or account takeover attempts.
Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one company. A single address or phone number allegedly taken from Casa International’s files can be cross-referenced against dozens of other breaches, creating an identity chain that links your shopping habits to gaming accounts, social-media handles, and family relationships. Attackers routinely sell or publish these chains on underground forums, enabling doxxing campaigns that reveal where you live, the names of your children, or even school schedules. Credential leaks like this one cascade into account takeovers, especially when the same password has been reused across retail sites, email, and gaming platforms. Children’s gaming accounts are particularly vulnerable because they often share the family address or parent email, turning one retailer breach into a doorway for harassment or further extortion.