On January 14, 2026, Samson Equipment appeared on the leak site of the tengu ransomware group. The company, which designs and manufactures custom weight rooms for schools, colleges, and tactical training facilities, is claimed to have had internal files exfiltrated following a ransomware attack. While the exact number of individuals whose information may have been exposed remains unknown, anyone who has done business with Samson Equipment — from parents ordering equipment for school gyms to coaches, athletes, or facility managers — may have had personal or financial details placed at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Samson Equipment
Get alerted the next time Samson Equipment files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Samson Equipment’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that tengu actors breached Samson Equipment’s systems and removed internal files before encrypting them. The data was later published on the group’s leak site. Samson Equipment specializes in durable strength training gear such as power racks, barbells, and accessories, along with 3D render consultations and lifetime warranties. Available reporting describes the exposed material as internal files; the precise volume and types of records have not been independently verified by third parties. No confirmed count of affected customer records has been released.
Why This Matters for You and Your Family
When a company that handles orders, payments, and shipping information is breached, your name, address, phone number, email, and payment details can end up in the hands of criminals. For families, this often means school-related purchases: a new set of racks for the high-school weight room, equipment for a college strength program, or gear bought for a local training facility. Once that information leaks, it can be sold, combined with other stolen data, and used for identity theft, fraudulent orders, or targeted scams against you or your children. Credential leaks like this one frequently cascade into account takeovers on other services where the same email and password were reused.
The Doxxing and Identity-Chain Implications
Stolen customer records rarely stay isolated. Attackers map connections between an email address, phone number, shipping address, and any usernames that appear in the files. Those links can reveal your children’s gaming accounts, social-media handles, or school affiliations. What begins as a purchase record can grow into a full identity chain that leads to doxxing, harassment, or further extortion. Public reporting on similar incidents shows that once data reaches ransomware leak sites, it is often reposted on multiple underground forums, accelerating the spread.