Original Footwear, the Tennessee-based manufacturer of military, law enforcement and first-responder boots, appeared on the LockBit 3.0 leak site on February 08, 2024. The listing states that internal files were exfiltrated during a ransomware attack. The company has not yet published a formal breach notification, so the exact number of people whose data may be exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch originalfootwear.com
Get alerted the next time originalfootwear.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about originalfootwear.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak site entry explicitly names originalfootwear.com and describes the incident as a successful ransomware deployment in which attackers copied internal files before encrypting systems. No sample data is shown on the page, and the listing does not specify which categories of documents were taken or how many records are involved. The disclosure indicates a countdown clock for public release of the stolen material if the company does not negotiate. Public reporting on LockBit 3.0 shows the group routinely posts victim company names and partial file trees once they decide to escalate extortion.
Why This Matters for You and Your Family
If you have ever purchased tactical boots, work shoes, or duty footwear from Original Footwear, Altama, or Original S.W.A.T., your name, shipping address, phone number, and payment details may sit inside the stolen internal files. Even when exact record counts are not published, ransomware operators routinely harvest customer databases, employee payroll spreadsheets, vendor contracts, and email archives. Any of those records can be sold or used to launch follow-on fraud, phishing, or identity theft against you or members of your household. The breach therefore touches both current and former customers as well as anyone whose employment or vendor records are stored by the company.
Doxxing and Identity-Chain Risks
Stolen internal files often contain spreadsheets that link names to email addresses, phone numbers, and physical addresses. Attackers and subsequent data brokers can combine those details with usernames found in the same archives, creating long identity chains. A single leaked work email can expose your LinkedIn profile, gaming accounts, and family photos. Credential leaks like this one cascade into account takeovers that reach far beyond the original footwear purchase. Children’s gaming handles tied to a parent’s reused password or shared family address are especially vulnerable to doxxing that begins with a seemingly mundane retail breach.