On August 02, 2022, Vietnamese e-commerce site kangaroo.vn appeared on the LockBit 3.0 ransomware leak site. The listing states that the group exfiltrated internal files during a ransomware attack and is now threatening to publish them unless the company meets their demands. The leak-site entry does not specify the volume of data taken or name any individual customers whose information may have been exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch kangaroo.vn
Get alerted the next time kangaroo.vn files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about kangaroo.vn’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure on the LockBit 3.0 portal, archived via ransomware.live, states that kangaroo.vn was listed after internal data was allegedly stolen. It does not quantify affected records, list specific file types beyond “internal files,” or provide a sample of the stolen material. The notification simply states that the data was exfiltrated during a ransomware incident and gives the company a deadline to negotiate or face full publication. Because the exact contents remain undisclosed, it is impossible to know whether customer records, employee details, or supplier contracts were included.
Why This Matters for You and Your Family
When a company that handles orders, payments, or personal accounts is breached, your information can be swept up even if you never see a direct notification. Internal files often contain names, addresses, phone numbers, email accounts, and order histories that criminals later sell or use to launch targeted attacks. For ordinary families this translates into higher risks of phishing emails that reference recent purchases, fake delivery scams, or identity thieves who already possess pieces of your profile. The uncertainty around the exact data taken makes it prudent to assume that any information you gave kangaroo.vn could now be in the hands of extortionists.
Doxxing and Identity-Chain Risks
Stolen internal files frequently serve as the first link in a doxxing chain. An email address or phone number taken here can be correlated with credentials from other breaches, gaming accounts, or social-media profiles to build a complete picture of your household. Once attackers map those connections they can hijack accounts, impersonate you to friends and family, or sell the bundle on underground markets. Credential leaks of this nature routinely cascade into gaming-platform takeovers, especially for children’s accounts that reuse the same password or recovery email. The result is not a single incident but an expanding web of exposure that can surface months or years later.