Quiltcraft was listed on the frag ransomware group's leak site on October 23, 2024, claiming that the household-goods manufacturer suffered a ransomware attack in which attackers exfiltrated internal files. The company, which supplies draperies, cubicle curtains, roller shades, and wall upholstery to healthcare, hospitality, and commercial clients, has not published a formal breach notification, leaving the exact number of affected individuals unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Quiltcraft
Get alerted the next time Quiltcraft files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Quiltcraft’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The frag leak site states that its operators successfully extracted several categories of sensitive material during the ransomware attack. These include partnership agreements, licenses and contracts, contact information of clients and employees, HR documents, driving licenses, immunization medical documents, and both employee and client social security numbers. The listing does not quantify how many records were taken or name specific systems that were compromised. It also does not disclose the ransom demand or any payment deadline.
Why This Matters for You and Your Family
When a vendor that serves healthcare and hospitality organizations loses client and employee records, the fallout reaches far beyond the company itself. If you or anyone in your household has ever received services from a Quiltcraft customer, your personal details may now sit in an attacker-controlled archive. Social security numbers, driving licenses, and immunization records are high-value identity documents that can be used to open accounts, file fraudulent taxes, or impersonate you in medical settings. Even if your own employer was not directly breached, the exposure of client contact lists creates a secondary risk: attackers can target you simply because your information traveled through Quiltcraft’s network.
The Doxxing and Identity-Chain Implications
Credential leaks and stolen personal documents rarely remain isolated. A single social security number paired with an email address or phone number can be correlated with usernames you use on other sites, quickly forming a chain that leads to account takeovers. This is especially true for gaming accounts belonging to you or your children; stolen credentials often surface first on dark-web marketplaces and are then used to pivot into linked services. The result is doxxing that can expose home addresses, family relationships, and financial details. Continuous monitoring across large breach repositories is one of the few practical defenses against these cascading identity chains.