On November 18, 2024, customer relationship management provider Followup CRM appeared on the leak site operated by the killsec ransomware group. The listing states that the company suffered a ransomware attack in which internal files were exfiltrated, and the group claims to have stolen company data. The exact number of people affected remains unknown because neither the leak-site posting nor any subsequent company notification has disclosed record counts or the specific categories of customer information involved.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Followup CRM
Get alerted the next time Followup CRM files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Followup CRM’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The killsec leak site entry states that Followup CRM was listed after the company apparently declined to pay a ransom demand. It states that internal files were taken during the ransomware incident. The disclosure does not specify the volume or types of data beyond describing them as internal files, nor does it list sample records or publish a data dump at the time of the initial posting. Public trackers such as ransomware.live mirror the same limited details, showing only that the victim was added on November 18, 2024, and that the actor asserts successful exfiltration of company information.
Why This Matters for You and Your Family
When a CRM company is breached, the information it holds often includes names, contact details, purchase histories, support tickets, and sometimes payment records of its clients. If you or your family have ever used Followup CRM directly or interacted with a business that relied on it, your personal data may now sit in an attacker-controlled archive. Even without exact figures, the exposure creates immediate risk because ransomware operators routinely use stolen contacts for follow-on phishing, identity fraud, or sale on underground markets. Internal files exfiltrated can contain spreadsheets that link customer identities to addresses, phone numbers, or account credentials, turning a corporate breach into a personal one.
The Doxxing and Identity-Chain Implications
Stolen CRM records frequently serve as the foundation for larger doxxing chains. An email address allegedly taken from Followup CRM can be cross-referenced with credential leaks from other services, revealing linked social-media handles, gaming accounts, or family-member details. Once attackers map these connections, they can impersonate you to reset passwords elsewhere or sell the full identity package. This is especially dangerous for households with children whose gaming usernames or parent-linked accounts appear in the same datasets. Credential leaks like this one routinely cascade into account takeovers that expose chat logs, location data, and photos. DoxxScan by GalaxyWarden continuously monitors across 13.1B+ breach records and 100+ platforms with AI-powered identity-chain mapping that links handles to real identities, while its specialists provide hands-on remediation and household coverage that includes children’s gaming accounts.