On March 28, 2025, luxury leather goods manufacturer Moore & Giles appeared on the leak site of the safepay ransomware group. The Virginia-based company, known for high-end home furnishings, handbags, luggage and accessories, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people whose information may have been exposed remains unknown, any customer, supplier, employee or partner whose details appear in those files could now face heightened risks of identity theft and doxxing.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch mooregiles.com
Get alerted the next time mooregiles.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about mooregiles.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that safepay posted proof of compromise for Moore & Giles on its dark-web leak site. The data consists of internal files exfiltrated after the ransomware deployment. No precise count of affected records has been released, and the company has not yet issued a public statement detailing the breach scope or timeline. The listing appeared on March 28, 2025, giving victims and observers a narrow window to assess exposure before any potential data dump escalates.
Why This Matters for You and Your Family
When a company like Moore & Giles suffers a breach, the information inside its files often includes names, addresses, phone numbers, email accounts, payment details or order histories tied to real customers. If you or anyone in your household has ever purchased their leather goods, furnishings or accessories, your personal data may now sit on a ransomware leak site. That exposure can quietly feed larger identity theft operations that target you and your family for months or years. Children’s names linked to family orders can also surface, creating long-term privacy headaches that are difficult to untangle without deliberate effort.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one company’s files. A single exposed email or phone number can be cross-referenced with dozens of other breaches, linking your shopping habits, social-media handles, and even children’s gaming accounts into a detailed identity chain. Once attackers map those connections, they can launch targeted doxxing, account takeovers or extortion attempts. Credential leaks of this nature frequently cascade into gaming platforms, where a compromised family account can expose chat logs, linked payment methods and home addresses. The speed at which these chains grow makes early detection and remediation essential.