On February 22, 2024, the ransomware group Black Basta added hvd.host to its public leak site, listing Hosted Companies as the victim and claiming to have exfiltrated roughly 700 GB of internal files. The disclosure indicates that data taken includes accountings, financial records, personal employee documents, and legal materials from multiple Australian and UK brands hosted by the company, such as australiantextiles.com.au, ausweave.com.au, bartgroup.com.au, bruck.com.au, opt.net.au, wilsonfabrics.com, knoxbridge.com.au, novaemployment.com.au, primrose.co.uk, xenit.com.au, advancedcs.com.au, therose.pub, and localbar.com.au. The exact number of individuals whose information appears in the files remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch hvd.host
Get alerted the next time hvd.host files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about hvd.host’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The Black Basta leak page states that Hosted Companies suffered a ransomware attack in which attackers exfiltrated internal files before encrypting systems. It lists the specific data categories noted above and provides a total size of the stolen archive. The disclosure does not quantify how many employee or customer records are contained in the 700 GB, nor does it specify the precise date of initial compromise. A direct link to the onion site was indexed by ransomware.live, making the listing publicly verifiable as of late February 2024.
Why This Matters for You and Your Family
If you or anyone in your household works at one of the listed companies, or if your personal documents were stored in their shared systems, your information may now sit on a criminal data marketplace. Personal employee documents and financial data are high-value targets for identity thieves. Even when a breach notification has not yet reached you, the public listing means opportunistic criminals have had weeks to download and begin exploiting the material. For families, this risk extends beyond the employee to spouses, children, and shared addresses that appear in payroll or benefits files.
The Doxxing and Identity-Chain Risks
Leaked internal files often contain spreadsheets that link names, dates of birth, addresses, phone numbers, email accounts, and sometimes national identification numbers. Once criminals possess these, they can map your digital footprint across dozens of services. A single exposed work email can lead to credential-stuffing attacks on personal banking, shopping, or social-media accounts. Public reporting shows that such leaks frequently cascade into full doxxing chains where attackers publish your home address, family member names, and even children’s details to increase pressure or sell the package to other threat actors. Credential leaks like this one also threaten gaming accounts belonging to you or your children, because reused passwords and linked recovery emails allow attackers to seize those identities and further expand the chain.