On April 14, 2025, the ransomware group known as Play added Merri-Makers to its public leak site, claiming that internal files had been exfiltrated from the United States-based company during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Merri-Makers
Get alerted the next time Merri-Makers files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Merri-Makers’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involves a classic ransomware pattern: initial access, data theft, and subsequent extortion pressure. The Play ransomware group listed Merri-Makers on its dark-web leak page, stating that internal files were taken. No exact victim count has been disclosed, and the precise number of people whose information appears in the files remains unknown. Available reporting describes the exposed material as internal company documents rather than a structured database of customer records. The listing appeared on the group's onion site, which is tracked by services such as ransomware.live.
Why This Matters for You and Your Family
When a company that handles orders, shipments, payments, or customer accounts suffers a breach, your personal details can easily end up in the stolen files. Even if your name is not on the front page of the leak, information such as email addresses, phone numbers, shipping addresses, or order histories can be combined with data from other breaches to build a profile of you and your household. Credential leaks from one service frequently cascade into gaming accounts, family email, and online shopping profiles. For families, this risk extends to children's accounts where the same password or recovery email is reused. Once attackers have a foothold, they can pursue identity theft, account takeovers, or targeted harassment that affects every member of the home.
The Doxxing and Identity-Chain Risks
Stolen internal files often contain more than obvious personal data. They can include employee directories, vendor lists, customer spreadsheets, or logs that link usernames, handles, and real-world details. Attackers use these connections to map an identity chain — turning one leaked email into a gaming username, a phone number, a home address, and eventually a full picture of your family's online life. Public reporting shows this pattern repeatedly leads to doxxing, swatting, or extortion attempts. Gaming accounts belonging to children are especially vulnerable because they frequently share the same recovery details as adult accounts. A single breach like this can therefore expose the entire household if the links are not identified and broken quickly.