On October 18, 2024, the ransomware group Black Basta added jonti-craft.com to its public leak site, listing the Minnesota-based children’s furniture manufacturer as a victim and claiming to have exfiltrated roughly 700 GB of internal files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch jonti-craft.com
Get alerted the next time jonti-craft.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about jonti-craft.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Black Basta leak site states that Jonti-Craft suffered a ransomware attack in which attackers exfiltrated internal files before encrypting systems. The listing does not specify the exact number of people affected. It categorizes the stolen material as including home users data, financial data and payroll records, personal information, human resources files, engineering documents, and additional departmental data. The disclosure indicates the data volume reached approximately 700 GB. No ransom amount or payment deadline appears in the public listing.
Why This Matters for You and Your Family
When a company that supplies furniture to daycares, schools, and pediatric offices is breached, the ripple effects reach ordinary families. Payroll and human-resources files often contain names, addresses, Social Security numbers, and banking details of current and former employees. Financial records can expose vendor payments and customer invoices. If your child attends a facility that uses Jonti-Craft products, or if you or a family member ever worked there, your personal information may now sit in an attacker-controlled archive. The disclosure indicates the stolen material includes personal and HR data, which attackers routinely sell or publish to pressure the victim or to profit on underground markets.
Doxxing and Identity-Chain Risks
Leaked HR and payroll files frequently contain enough detail to link an individual’s work email, phone number, physical address, and date of birth. Once those pieces surface, criminals can chain them with usernames found in other breaches to take over email accounts, gaming profiles, or social-media handles. A single exposed work email can lead to password-reset attacks against personal services. For families, the danger compounds when children’s school or daycare records indirectly tie back to the same household address. Public reporting on similar incidents shows that initial credential leaks often cascade into full identity theft, account takeovers, and targeted harassment. Personal and financial data from this volume of records can fuel years of fraud if not addressed quickly.