On December 20, 2023, Horizon Pool and Spa was listed on the leak site operated by the 8base ransomware group. The wholesale distributor of pool and spa parts, which supplies repair, construction, and retail companies through its website horizonparts.com, is claimed to have had internal files exfiltrated during a ransomware attack. The listing does not specify how many people were affected or exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Horizon Pool and Spa
Get alerted the next time Horizon Pool and Spa files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Horizon Pool and Spa’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the 8base Listing
The primary disclosure on the 8base leak site states that Horizon Pool and Spa suffered a ransomware incident in which attackers successfully exfiltrated internal files. No victim count, no list of specific data types beyond the broad category of internal files, and no ransom demand figure appear in the posting. The disclosure indicates the company was added to the group’s public shaming page on December 20, 2023, giving the operator’s typical deadline for payment before further data publication. Public mirrors of the leak site, such as ransomware.live, preserve the original entry at the onion address http://xb6q2aggycmlcrjtbjendcnnwpmmwbosqaugxsqb4nx6cmod3emy7sad.onion/company/7890334.
Why This Matters for You and Your Family
When a supplier in the home-improvement sector is breached, customer invoices, vendor contracts, employee payroll files, and contact lists often sit inside the stolen material. Even though the exact contents remain unknown, any records that name you, your address, phone number, email, or payment details can surface later in identity-theft operations. Your family’s information may have been swept up if you recently bought replacement pool parts, booked a service call, or appeared as an employee or contractor. The uncertainty itself creates risk: you cannot defend against data you do not know exists.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain spreadsheets that link personal details to usernames, passwords, or customer account numbers. Attackers and subsequent buyers can chain those fragments with data from earlier breaches to build full identity profiles. A single reused password from a Horizon transaction can hand over access to your email, banking, or retail accounts. The same chains often reach gaming platforms where children use family email addresses or shared phone numbers, turning one corporate breach into household-wide account takeovers and doxxing campaigns.