On February 27, 2025, the ransomware group Clop added MCCUBBIN.COM to its public leak site, claiming that internal files had been exfiltrated from the family-owned hosiery manufacturer during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Mccubbin.Com
Get alerted the next time Mccubbin.Com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Mccubbin.Com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates that Clop listed McCubbin.com after the company apparently declined to pay a ransom demand. The exposed material consists of internal files rather than a structured database of customer records. No exact victim count has been published, and the precise volume or sensitivity of the documents remains unclear from the leak site itself. The incident follows Clop’s established pattern of using double-extortion tactics: encrypting systems and then threatening to publish stolen data if payment is not received.
Why This Matters for You and Your Family
Even when a breach does not list names and Social Security numbers, the files taken can still contain supplier contracts, employee payroll information, customer orders, or email correspondence that reveal personal details about ordinary families. If your family has ever bought socks, tights, or school uniforms from McCubbin or one of its retail partners, your contact information or payment records may sit inside those documents. Once leaked, that data can be combined with other breaches to build a profile that puts your household at risk of identity theft, phishing, or harassment. Children’s sizes and school-related orders are particularly sensitive because they can tie a real name and address to a minor.
The Doxxing and Identity-Chain Risk
Ransomware leaks like this one rarely stay isolated. Attackers and opportunistic criminals scrape the files for email addresses, usernames, phone numbers, and any mention of family members. These fragments are then cross-referenced across dozens of prior breaches. A single credential exposed in the McCubbin files can unlock a chain that leads to your online shopping accounts, loyalty programs, and even your children’s gaming profiles. Public reporting shows that such credential leaks frequently cascade into account takeovers, doxxing, and extortion attempts aimed at the most vulnerable members of a household.