On June 23, 2026, the Chaos ransomware group added randa.net to its leak site, claiming that it had exfiltrated internal files from Randa Apparel & Accessories, a major New York-based company behind many well-known apparel and lifestyle accessory brands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch randa.net
Get alerted the next time randa.net files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about randa.net’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates the incident is a classic ransomware attack in which the group first gained access, encrypted systems, and then exfiltrated data before threatening to publish it. The listing appeared on the Chaos leak site hosted on the dark web, with the primary source being the onion address tracked by ransomware.live. Available reporting describes the exposed material as internal files, though the exact volume and full list of data types have not been publicly detailed. The number of individuals whose personal information may be inside those files remains unknown at this time. Randa Apparel & Accessories, headquartered at 417 Fifth Avenue in New York City, has not yet issued a public statement confirming the breach or notifying affected parties.
Why This Matters for You and Your Family
When a company like Randa suffers a breach, the information stolen often includes details that can be linked back to customers, suppliers, employees, or business partners. If your name, address, email, phone number, or payment information appears in any of those internal files, it can be sold or dumped alongside data from dozens of other breaches. Credential leaks like this one frequently cascade into account takeovers on shopping sites, loyalty programs, and email accounts that millions of families use every day. Once criminals control even one of those accounts, they can reset passwords elsewhere, request new credit cards, or open accounts in your name. For families, the risk extends to children whose school forms, sports registrations, or family-linked profiles may sit in the same corporate databases.
The Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers map relationships between corporate contacts, customer records, and personal details to build complete identity chains. A single email address taken from a vendor list can be cross-referenced with breached gaming accounts, social-media handles, or family addresses. This chaining turns one leak into repeated harassment, targeted phishing, or full doxxing. Public reporting shows that ransomware groups increasingly release or sell this data in batches, giving other criminals easy starting points for identity theft or extortion. Children’s gaming accounts are especially vulnerable because parents often reuse passwords or security questions tied to family information that may now sit inside the Randa files.