ishoppes.com was listed on the LockBit 3.0 ransomware leak site on November 16, 2023. The Canadian online retailer, which sells travel accessories and lifestyle goods, is the latest victim claimed in the group's ongoing extortion campaign. Anyone who has shopped with iShoppes, joined its mailing list, or provided an email address may have their information indirectly exposed through the internal files the attackers say they stole.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details from the Leak-Site Listing
The LockBit 3.0 panel states that iShoppes suffered a ransomware attack in which internal files were exfiltrated. The listing does not disclose the exact number of records involved, the specific types of documents taken, or any ransom demand amount. It simply states that data was removed from the company's systems and warns that the information will be published if the victim does not negotiate. As of the publication date, samples or full archives had not yet been released on the leak site, which is typical while the group applies pressure. The disclosure indicates the breach stems from a classic ransomware deployment followed by data theft for double-extortion purposes.
Why This Matters for You and Your Family
When a retailer like iShoppes loses internal files, the exposure often includes customer databases, order histories, email lists, and employee records. Even though the exact contents remain unknown, such leaks frequently contain names, physical addresses, phone numbers, and payment details that criminals can sell or use directly. For ordinary shoppers this translates into heightened risk of phishing emails that reference recent purchases, identity theft attempts using your real address tied to your email, or credential-stuffing attacks if any reused passwords were stored. Your family members listed on the same account or sharing the household email become part of the same exposure chain.
The Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers or buyers on underground forums combine them with other breaches to build detailed profiles. An email address from iShoppes can be cross-referenced with gaming accounts, social-media handles, or data-broker records to reveal your full name, current home address, and family relationships. This is exactly how doxxing chains begin: one retail breach supplies the seed data that unlocks further accounts. Credential leaks like this one frequently cascade into gaming-platform takeovers, especially for children whose usernames and passwords are reused across services. Once an attacker controls a family gaming account, they can harvest additional personal details or demand payment to restore access.