On January 10, 2025, Canadian disaster-recovery firm Qualinet appeared on the leak site of the rhysida ransomware group, with internal files reportedly exfiltrated during a ransomware attack. The posting affects anyone whose personal information passed through Qualinet’s systems in Quebec since the company began operations in 1994, including customers who used its cleanup and restoration services after floods, fires, or other disasters.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Qualinet
Get alerted the next time Qualinet files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Qualinet’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Qualinet was listed on the Rhysida leak portal with samples of stolen internal documents. The company, which advertises “one customer at a time” and has operated for more than 30 years, has not yet published an official statement confirming the volume of data taken or the exact number of individuals affected. Available reporting describes the exposed material as internal files rather than a structured database of customer records, but the precise contents remain unclear. No specific deadline for ransom payment has been publicly detailed in the initial listing.
Why This Matters for You and Your Family
If you or anyone in your household has ever filed an insurance claim that required Qualinet’s water, fire, or mold remediation services, your contact details, insurance policy numbers, property addresses, or claim descriptions may now sit in an attacker’s archive. Personal information from disaster-recovery firms is especially valuable because it often includes phone numbers, email addresses, and home addresses tied to real-world events that reveal when a family was vulnerable. Once that data circulates, it can be sold quietly on underground forums and used for follow-on scams that impersonate insurers, contractors, or government agencies offering “extra assistance” after your claimed disaster.
The Doxxing and Identity-Chain Risks
A single breach like this rarely stays isolated. Attackers routinely combine newly leaked names and addresses with credentials from earlier breaches to build detailed identity chains. A phone number allegedly taken from Qualinet can be matched to a reused password from an old retail breach; that password can unlock an email account; the email can reveal children’s names or gaming usernames. The result is a road map that leads from your family’s disaster-recovery records straight to social-media profiles, children’s online accounts, and eventually to doxxing or targeted extortion. Credential leaks of this nature frequently cascade into account takeovers precisely because people reuse the same passwords across work, personal, and gaming logins.