On February 28, 2023, luxury homewares company LSA International appeared on the LockBit 3.0 ransomware leak site. The listing states that internal files were exfiltrated during a ransomware attack on the UK-based manufacturer of handmade glassware and porcelain. The number of records affected remains unknown, and the precise contents of the stolen data have not been detailed by the group.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch lsa-international.com
Get alerted the next time lsa-international.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about lsa-international.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The LockBit 3.0 leak page, archived via ransomware.live, states that lsa-international.com was listed after the company apparently declined or failed to meet the attackers’ demands. It describes the incident as a standard ransomware operation involving both encryption and data exfiltration. No specific volume of records, customer names, or payment-card details is published on the leak site itself. The disclosure indicates that the stolen material consists of internal files, but does not enumerate file types or whether customer, supplier, or employee information is included.
Why This Matters for You and Your Family
When a retailer of everyday household goods such as wine glasses, vases, and tableware suffers a breach, the people whose data ends up in the stolen files are often ordinary customers who placed orders, created accounts, or contacted support. Even without an exact record count, the exposure can include names, delivery addresses, email addresses, telephone numbers, and order histories. Once that information leaves the company’s control, it can be sold, swapped, or used to fuel further fraud against you or members of your household. The breach also signals that any passwords or payment details you may have reused on the LSA site could now be in circulation.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain spreadsheets that link customer identities to addresses, phone numbers, and sometimes dates of birth. Attackers and subsequent buyers can combine these fragments with other breaches to build a complete profile. A single leaked order confirmation that shows your name next to a delivery address can be chained to social-media handles, children’s school details, or gaming usernames that share the same household IP range or recovery email. These identity chains accelerate doxxing, targeted phishing, and account takeovers. Credential leaks like this one cascade into gaming account compromises when the same password protects both a shopping login and a child’s Fortnite, Roblox, or Steam profile.