On November 28, 2022, the ransomware group Vice Society added IKEA Morocco and IKEA Kuwait to its public leak site, claiming that internal files had been exfiltrated during a ransomware attack on the two subsidiaries.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch IKEA Morocco IKEA Kuwait
Get alerted the next time IKEA Morocco IKEA Kuwait files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about IKEA Morocco IKEA Kuwait’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak Listing
The Vice Society leak page, archived via ransomware.live, states that data was taken from both IKEA entities and warns that samples will be published if a ransom is not paid. The listing does not quantify the number of records affected, does not list specific data types beyond “internal files,” and does not disclose the exact systems compromised. Public reporting on Vice Society indicates the group typically posts proof-of-exfiltration screenshots or small sample archives before escalating to full data dumps. As of the listing date, the exact volume and sensitivity of the stolen material remained unknown to outsiders.
Why This Matters for You and Your Family
When a global retailer like IKEA suffers a breach, customer and employee data often travels with internal files. Even if the leak site does not spell out every record type, ransomware operators routinely obtain spreadsheets containing names, contact details, dates of birth, national ID numbers, payroll information, or supplier contracts. Any of those pieces can be combined with data from previous breaches to build a profile on you or members of your household. November 28, 2022 therefore marks the moment when information tied to IKEA Morocco or IKEA Kuwait customers and staff entered the criminal underground.
Doxxing and Identity-Chain Risks
Internal files rarely stay isolated. A single leaked email address or phone number can be chained to gaming accounts, social-media handles, and family-member records. Attackers use these links to launch credential-stuffing attacks, SIM-swapping attempts, or targeted extortion. Children’s gaming profiles connected to a parent’s reused password are especially vulnerable; once one account falls, the entire household identity chain can unravel. The longer the exposed data circulates on dark-web forums, the higher the chance that opportunistic criminals will exploit it for identity theft or financial fraud.