On May 26, 2023, debt collection agency FAMS Recovery Solutions appeared on the LockBit 3.0 ransomware leak site. The company, based in Woodstock, Georgia, and operating since 1993, had its internal files exfiltrated during a ransomware attack. The listing does not specify how many individuals are affected or list the exact data types beyond claiming that internal files were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the Leak Site
The primary disclosure on the LockBit 3.0 leak site states that FAMS Recovery Solutions suffered a ransomware incident and that attackers successfully exfiltrated internal files. No victim count is provided, and the posting does not quantify the volume or specific categories of data stolen. The notification simply confirms the breach occurred and gives the company a deadline to negotiate before further publication. Public reporting on LockBit 3.0 indicates the group typically posts samples of stolen data as proof while threatening to release the full archive if ransom is not paid.
Why This Matters for You and Your Family
If you have ever been contacted by a debt collector, used a financial service that partners with collection agencies, or live in an area where FAMS Recovery Solutions operates, your personal information may have been inside the compromised systems. Debt collection firms routinely handle names, addresses, Social Security numbers, dates of birth, phone numbers, email addresses, employment details, and financial account information. When these records are stolen, the exposure extends beyond the primary debtor to spouses, co-signers, and sometimes adult children listed as authorized contacts. The disclosure indicates the data was taken from internal systems, meaning the breach likely includes records that connect multiple family members to the same household.
Doxxing and Identity-Chain Risks
Stolen debt-collection files create long-term doxxing and identity-chain vulnerabilities. Attackers or buyers of the data can link your name and SSN to current and past addresses, phone numbers, and email accounts. These details then serve as seeds for credential-stuffing attacks against banks, email providers, and government portals. Once one account is compromised, the attacker maps additional relationships—spousal employment records, children’s school information, or shared utility accounts—building a complete household profile. Credential leaks like this one cascade into account takeovers, especially for gaming accounts that often reuse the same email or password as adult family members. Children’s usernames and linked emails become entry points for further harassment or social-engineering attacks that ultimately trace back to the family’s real-world identity.