On November 11, 2023, Singapore-based 3D printing supplier Creatz3D appeared on the LockBit 3.0 ransomware leak site, with the group claiming to have exfiltrated internal files during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch creatz3d.sg
Get alerted the next time creatz3d.sg files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about creatz3d.sg’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page states that Creatz3D suffered a ransomware intrusion and that attackers successfully removed internal company files. The listing does not quantify how many records were taken, name specific data types such as customer databases or employee records, or disclose the ransom demand. It simply lists the company alongside a countdown timer and samples of allegedly stolen material. The disclosure indicates the data was taken prior to encryption attempts, a standard LockBit tactic. No official breach notification from Creatz3D had been published at the time the listing went live.
Why This Matters for You and Your Family
When a vendor like Creatz3D is breached, anyone who has purchased 3D printers, filament, or printing services from them may have personal details exposed. This can include names, delivery addresses, phone numbers, email accounts, and payment information tied to orders. Internal files often contain spreadsheets of past customers, supplier contacts, and employee payroll data. If your information sits in those files, it becomes raw material for identity thieves who combine it with other leaks. Your family members listed on the same address or shared email accounts face the same risk even if they never interacted with the company directly.
The Doxxing and Identity-Chain Risk
Stolen internal files frequently expose more than names and addresses. They can reveal account usernames, order histories that mention children’s school projects or hobby usernames, and sometimes direct links between personal emails and gaming handles. These fragments allow attackers to build identity chains that connect your real-world identity to online profiles. Once mapped, the same credentials are tested across gaming platforms, social media, and financial apps. Credential leaks like this one routinely cascade into account takeovers, especially for households that reuse passwords. Children’s gaming accounts are particularly vulnerable because parents often use the same email address for family purchases and kid-oriented services.