On March 21, 2024, the ransomware group LockBit3 added northerncasket.com to its public leak site, claiming that the Canadian casket manufacturer had been hit by a ransomware attack in which internal files were exfiltrated.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch northerncasket.com
Get alerted the next time northerncasket.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about northerncasket.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit3 leak-site entry states that Northern Casket suffered a ransomware intrusion and that attackers successfully removed internal files. The disclosure does not quantify the number of records affected, list specific data types beyond “internal files,” or reveal the ransom demand. It simply presents the company name, a screenshot placeholder, and a countdown timer typical of the group’s extortion pages. The primary source is the LockBit3 onion site, mirrored on ransomware.live at the URL below.
Why This Matters for You and Your Family
When a business like Northern Casket is breached, the information stolen often includes documents that contain names, addresses, phone numbers, dates of birth, Social Security numbers, or financial details of customers, suppliers, or employees. Even though the exact contents remain undisclosed, any exfiltrated internal files create immediate risk for the people whose information is inside them. If your family has ever purchased a casket or related services from Northern Casket, worked with the company, or had your data stored in its systems, you should treat this incident as though your personal information may now be in the hands of criminals who have already demonstrated willingness to publish it.
The Doxxing and Identity-Chain Risk
Ransomware operators rarely stop at posting a single company name. They frequently release sample documents or full data sets to pressure payment. Once those files appear, the information can be scraped by identity thieves and cross-referenced with other breaches. A customer address listed in a Northern Casket invoice can be chained with an email address from an earlier breach, a phone number from a data broker, and a username from a gaming platform. That chain quickly leads to account takeovers, targeted phishing, or full identity theft. Credential leaks of this nature also cascade into gaming accounts belonging to you or your children, where the same reused password or security question can hand over an account in minutes.