On October 5, 2023, relocation services provider Sirva Worldwide, Inc. appeared on the LockBit 3.0 ransomware leak site with the threat actors claiming to have exfiltrated more than 1.5 TB of internal documents plus three complete CRM database backups covering their European, North American, and Australian branches.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Details in the Leak-Site Posting
The LockBit 3.0 listing states that Sirva’s data was taken during a ransomware intrusion and that the attackers now possess over 1.5 TB of documents together with full backups of the company’s customer relationship management systems for its three major geographic regions. The posting does not specify the exact number of individuals whose records are contained in the material, nor does it list every file type. It does, however, make clear that both unstructured internal files and structured CRM databases were removed before encryption occurred on the victim’s systems. The disclosure indicates the data is now available for download by other criminals or for public release if Sirva does not meet the group’s demands.
Why This Matters for You and Your Family
If you or anyone in your household has ever used a corporate relocation service, worked with a real-estate firm that partners with Sirva, or had an employer that contracted with them for employee moves, your personal information may be inside the stolen material. Relocation records routinely contain full names, current and future addresses, phone numbers, email accounts, dates of birth, passport or visa details, employment information, and sometimes family member data. Once such details leave a company’s protected environment, they become permanent currency on underground markets. Even if you cannot confirm whether your records were included, the uncertainty itself forces you to treat the incident as though your information is exposed.
The Doxxing and Identity-Chain Risk
Stolen CRM backups and internal documents create long-term doxxing chains. A single address tied to a relocation file can be correlated with social-media handles, children’s school records, gaming usernames, and vehicle registrations. Threat actors routinely combine these fragments to map an entire household. Credential leaks that surface in the same datasets often allow attackers to seize email accounts, which then become the entry point for further targeting of family members. Gaming accounts belonging to children are especially vulnerable because the same email or password reused from a parent’s relocation paperwork can hand over an account that contains chat logs, voice recordings, and linked payment methods. The longer these connections remain unmapped, the higher the chance that one breach quietly fuels another months or years later.