On December 20, 2024, foam manufacturer Jacobs & Thompson appeared on the leak site operated by the lynx Ransomware Group. The listing states that the company suffered a ransomware attack in which internal files were exfiltrated. The notification does not disclose the number of records affected, the exact data types stolen, or any ransom demand.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Jacobs & Thompson
Get alerted the next time Jacobs & Thompson files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Jacobs & Thompson’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Lynx Listing
The lynx leak site entry states that Jacobs & Thompson, a North American supplier of customized foam, adhesive, and textile components established in 1947, had files removed during a ransomware incident. No sample data is currently shown, and the posting does not quantify the volume or sensitivity of the material taken. Public views of the listing indicate the group is using the typical double-extortion model of encryption plus data-theft threats. The disclosure itself remains sparse on technical specifics, which is common for early-stage ransomware leak-site postings.
Why This Matters for You and Your Family
When a supplier like Jacobs & Thompson loses control of internal files, anyone whose personal or payment information ever passed through that company faces heightened risk. Employees, customers, vendors, and even families who received products containing custom foam components may find their details exposed. Internal files frequently contain spreadsheets with names, addresses, phone numbers, email accounts, and sometimes payment records. Once these files leave the company’s network, they can circulate rapidly among criminals who specialize in identity theft and account takeover. Your family’s information does not need to be the primary target for it to be harvested and sold.
Doxxing and Identity-Chain Risks
Stolen internal documents often create long identity chains. An email address found in one file can be matched to usernames on forums, gaming platforms, or shopping sites. Those handles then link to home addresses, children’s names, or school details. The result is a map that lets attackers target you or your family across multiple services at once. Credential leaks of this kind frequently cascade into gaming-account takeovers, especially for children whose usernames and passwords are reused from family email addresses. Continuous monitoring that traces these connections is one of the few practical defenses once data has already left the victim’s control.