On February 10, 2024, Canadian company Groupe Goyette appeared on the leak site operated by the hunters ransomware group. The listing states that internal files were exfiltrated during a ransomware attack in which both data encryption and data theft occurred. The exact number of people whose information was taken remains unknown, and the hunters leak site does not detail the specific types of records involved.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Groupe Goyette
Get alerted the next time Groupe Goyette files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Groupe Goyette’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Primary Listing
The hunters ransomware leak page states that Groupe Goyette, based in Canada, suffered a ransomware incident. It explicitly notes that data was allegedly exfiltrated and that systems were encrypted. No sample files are shown in the public listing, and no ransom amount or negotiation status is displayed. The disclosure indicates the incident follows the group’s standard double-extortion model: encrypt the victim’s environment and threaten to publish stolen data if payment is not made.
February 10, 2024 marks the first public appearance of this victim on the hunters site. Because the listing does not quantify affected records or name the categories of information taken, individuals connected to Groupe Goyette cannot yet determine the precise scope of their exposure from the primary source alone.
Why This Matters for You and Your Family
When a company that handles employment, vendor, or customer records is hit by ransomware, the people whose data it holds face direct risk. Even though the hunters listing does not specify what was taken, internal files in most corporate environments commonly include names, addresses, dates of birth, Social Insurance Numbers, banking details, and employee files. Any of these can be used to commit identity theft, file fraudulent tax returns, or open accounts in your name.