Crosswear.co.uk appeared on the madliberator ransomware group’s leak site on June 19, 2024. The UK wholesaler, which has supplied partyware and greeting cards since 1972, is the latest victim publicly listed after a ransomware attack that resulted in the exfiltration of internal files. The disclosure does not specify how many people are affected or exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch crosswear.co.uk
Get alerted the next time crosswear.co.uk files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about crosswear.co.uk’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The madliberator leak site lists Crosswear.co.uk and states that internal files were exfiltrated during a ransomware incident. No victim count, no sample data, and no ransom demand figure appear in the listing. The notification simply states that data was stolen and is now hosted on the group’s onion site at the address referenced above. Public reporting on madliberator indicates the group follows the now-standard double-extortion model: encrypt systems, exfiltrate documents, then threaten to publish unless payment is made.
Why This Matters for You and Your Family
When a supplier like Crosswear suffers a breach, customer and supplier records often travel with the internal files. If you have ever placed an order, supplied product, or shared contact details with the company, your information could sit inside the stolen archive. For ordinary families this means names, addresses, phone numbers, order histories, and possibly payment references may now be in the hands of criminals. Even when the listing does not quantify affected records, the real-world exposure is concrete: one more dataset that can be used for phishing, identity fraud, or sold on to other threat actors.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain spreadsheets that link personal details to email addresses, phone numbers, and sometimes partner or family contacts. Attackers chain these fragments together with data from previous breaches to build complete profiles. A single leaked order record can expose your home address, then tie it to children’s names if party supplies were ordered for birthdays. These chains accelerate doxxing because one breach becomes the bridge that connects your shopping habits to gaming accounts, social-media handles, and ultimately your real-world identity. Credential leaks of this type routinely cascade into account takeovers, especially for gaming platforms used by children.