On July 4, 2025, the ransomware group known as Warlock listed getdomain on its leak site after exfiltrating internal files from the company during a ransomware attack. The data has since been sold to other buyers, according to public reporting on the incident. Anyone whose personal information was stored in those internal files—including customers, employees, or business contacts—may now face heightened risks of identity theft, account takeovers, and doxxing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch getdomain
Get alerted the next time getdomain files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about getdomain’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that getdomain suffered a ransomware attack in which attackers gained access to internal systems and exfiltrated files. On July 4, 2025, the Warlock group added the victim to its public leak site hosted on the dark web. The exposed material consists of internal files rather than a structured database of customer records, but such documents frequently contain names, email addresses, phone numbers, contracts, employee details, and other sensitive business information that can be repurposed for fraud.
Available reporting describes that the stolen data has been purchased by third parties, meaning the information may now be in the hands of unknown actors who may resell it or use it directly. The exact number of individuals affected remains unknown because the contents have not been publicly sampled. No evidence suggests payment was made to the attackers or that the data was returned.
Why This Matters for You and Your Family
When a company you have interacted with loses internal files, your personal details can quickly move from a relatively private business record into criminal marketplaces. Names, emails, phone numbers, and addresses are the building blocks criminals need to open accounts in your name, file fraudulent tax returns, or impersonate you to your bank. For families, the risk extends beyond one person: children’s names or school-related documents sometimes appear in business files, giving predators an entry point.