On May 12, 2025, the ransomware group Safepay added sander-doll.com to its leak site and began publishing what it claims are internal files exfiltrated from the company during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch sander-doll.com
Get alerted the next time sander-doll.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about sander-doll.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the victim is sander-doll.com, an online retailer. Available details show the group exfiltrated internal files before encrypting systems or disrupting operations. The exact number of people whose information appears in the files remains unknown, as does the precise volume of data. No sample files have been independently verified by third parties at the time of writing, and the company has not issued a public statement confirming the breach or describing what customer or employee records were taken.
Why This Matters for You and Your Family
When a retailer’s internal files are stolen, the information inside often includes names, addresses, email accounts, phone numbers, order histories, and payment details for ordinary customers. If your family has ever shopped at sander-doll.com or used the same email and password combination elsewhere, those credentials may now be in criminal hands. Credential leaks like this one frequently cascade into account takeovers on other services, identity theft, and targeted harassment. Children’s accounts linked to a parent’s email are especially vulnerable because gaming platforms and family-sharing services often reuse the same contact information.
The Doxxing and Identity-Chain Risk
Stolen internal files rarely stop at one company. Attackers can combine the exposed data with information already circulating on underground forums to build a complete picture of your household. A single email address can link your shopping history, children’s usernames, home address, and phone number into what specialists call an identity chain. Once mapped, this chain makes it easier for criminals to launch spear-phishing attacks, SIM-swapping attempts, or full doxxing campaigns that publish your family’s personal details online. Gaming accounts belonging to children are frequent targets because they often contain linked payment methods and chat logs that reveal even more personal context.