On September 30, 2025, self-storage company Storage King appeared on the leak site of the anubis ransomware group, with attackers claiming to have exfiltrated internal files containing a major volume of personal data.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Storage King
Get alerted the next time Storage King files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Storage King’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that the anubis ransomware group added Storage King to its data-leak portal on that date. The listing states that internal files were taken during a ransomware incident. Available reporting describes the exposed material as containing significant personal information, though the exact number of affected individuals has not been confirmed by the company. No public statement from Storage King detailing the breach scope, timeline of initial compromise, or specific data categories has been widely circulated as of this writing.
Internal files exfiltrated and listed on the anubis leak site represent the core confirmed event. The incident follows the group’s typical pattern of encrypting victim systems, exfiltrating data, and then publishing samples or full datasets when ransom demands are not met.
Why This Matters for You and Your Family
When a company that stores your household belongings, contracts, insurance details, or payment records suffers a breach, the information taken can include names, addresses, phone numbers, email accounts, dates of birth, and financial references. Any of these details can be used to impersonate you, open accounts in your name, or target your family members. Children’s information, sometimes included in family storage contracts or emergency contacts, can also surface in these leaks. Once personal data leaves a company’s control, you and your family bear the long-term risk of identity theft, phishing campaigns, and unwanted solicitations that feel personal because attackers know so much about your life.