On March 5, 2026, the ransomware group Akira listed MerchNOW on its leak site and announced it would soon publish a large volume of the company’s internal files, including employee passports, driver’s licenses, Social Security numbers, scanned personal documents, financial records, contracts, client files, and NDAs.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch MerchNOW
Get alerted the next time MerchNOW files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about MerchNOW’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
MerchNOW is a music-merchandising firm with more than 20 years in business. It produces apparel, accessories, and custom merchandise for bands and artists and provides services such as screen printing, record pressing, embroidery, and order fulfillment. Public reporting indicates the company suffered a ransomware attack in which attackers exfiltrated corporate data. The Akira leak page states the group will upload “a great amount of employee personal documents” along with financials, contracts, client information, and project files. The exact number of people affected remains unknown. No confirmed timeline for the data release has been published beyond the March 5 listing.
Why This Matters for You and Your Family
When a company that handles orders, payments, and customer records is breached, the information it holds about you can appear in the wild. SSNs, driver’s licenses, and scanned passports are especially dangerous because they allow identity thieves to open accounts, file fraudulent tax returns, or impersonate you. Even if you only bought a T-shirt or hoodie years ago, your name, address, email, and payment details may have been stored. Once those records surface, they rarely disappear. Criminals combine them with data from other breaches to build complete profiles of ordinary people and their families.
The Doxxing and Identity-Chain Risk
Leaked employee and customer documents rarely stay isolated. A single scanned driver’s license can be linked to an email address used for online shopping, which in turn connects to a social-media handle or a child’s gaming account. These identity chains let attackers move from one platform to another, turning a merchandising purchase into doxxing material or account takeovers. Credential leaks of this kind frequently cascade into gaming platforms where children use family email addresses or shared passwords. What begins as a corporate ransomware incident can quickly become personal.