On February 17, 2026, floral and event company Saiful Bouquet appeared on the leak site of the qilin ransomware group, which claims to have stolen and exfiltrated the firm’s internal files during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Saiful Bouquet
Get alerted the next time Saiful Bouquet files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Saiful Bouquet’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates that Saiful Bouquet was listed on the qilin leak portal with an announcement that internal data had been taken. The exact volume of records and the specific types of files remain unconfirmed in available reporting. No customer count or precise list of exposed data fields has been publicly detailed by the company or the threat actors. The listing follows the group’s typical pattern of publishing samples or announcements after an initial extortion window passes.
Why This Matters for You and Your Family
When a business like a florist or event planner is breached, the files taken often contain names, addresses, phone numbers, email addresses, payment details, and contracts for ordinary customers — people planning weddings, anniversaries, or family events. If your information was among the records, it can surface in follow-on fraud, phishing campaigns, or identity theft attempts. Credential leaks from such incidents frequently cascade into personal account takeovers months later. Families who used the same email or password across work, personal, and children’s accounts face heightened risk because one breach can quietly connect multiple parts of their digital lives.
The Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at the initial theft. Once internal files are obtained, attackers or opportunistic criminals can map disparate pieces of information — an email here, a child’s gaming username there, a home address on a contract — into a complete identity profile. This process, known as identity-chain mapping, turns a single breach into long-term exposure. Public reporting describes how stolen customer databases frequently feed doxxing marketplaces where real names are linked to social-media handles, phone numbers, and family details. Gaming accounts belonging to children are especially vulnerable because usernames and email addresses often reuse the same credentials that appear in business files, creating a direct path from corporate breach to personal harassment or account takeover.