On July 24, 2024, the ransomware group donutleaks listed Jack “Designer” Sparrow on its leak site, claiming that the Canadian design firm suffered a ransomware attack in which internal files were exfiltrated. The listing, hosted on the Tor domain sbc2zv2qnz5vubwtx3aobfpkeao6l4igjegm3xx7tk5suqhjkp5jxtqd.onion, states that the company refused to negotiate or pay, prompting the attackers to begin publishing stolen data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Jack "Designer" Sparrow.
Get alerted the next time Jack "Designer" Sparrow. files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Jack "Designer" Sparrow.’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Posting
The donutleaks entry explicitly names the victim as Jack “Designer” Sparrow and describes the incident as a ransomware attack that resulted in the theft of internal files. It does not disclose the total number of records affected, the precise date of initial compromise, or a full inventory of the data taken. The disclosure indicates the attackers have begun releasing samples and threaten further publication if demands are not met. No ransom amount is stated in the public listing.
Why This Matters for You and Your Family
When a design studio’s internal files leave its control, anyone whose information touched those systems faces real risk. Clients, vendors, employees, and their families may find personal details suddenly available to identity thieves, fraudsters, or harassers. Even if you never directly hired this firm, shared contact lists, invoices, contracts, or licensing records can still expose names, addresses, email accounts, and phone numbers. Once those details surface on criminal forums, they rarely disappear. Your family’s daily life — from opening a new credit card to protecting children’s online identities — can be affected for years.
The Doxxing and Identity-Chain Risk
Stolen internal files frequently contain more than spreadsheets. They often hold email correspondence, project briefs, licensing keys, and reused credentials that link one account to many others. Attackers and opportunistic criminals follow these chains: an email address found in a design contract leads to a reused password at a retailer, which leads to a streaming account, which leads to a child’s gaming profile tied to the same home address. This is exactly how doxxing escalates from a single breach into persistent harassment. Credential leaks like this one cascade into account takeovers that can expose family photos, chat logs, and location data within hours of appearing on underground markets.