On March 21, 2025, the ransomware group RansomHub added www.core-1.com to its leak site, claiming that it had exfiltrated internal files from the California-based IT services provider during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What's Publicly Reported from Reporting
Public reporting indicates that Core-1 specializes in IT asset disposition, data center relocation, server decommissioning, and secure data destruction. The company helps clients dispose of or recycle obsolete hardware in an eco-friendly manner. Available reporting describes the incident as a ransomware attack in which internal files were taken. The exact number of people whose information appears in the stolen data remains unknown. The leak site listing itself serves as the primary public evidence of the breach.
Why This Matters for You and Your Family
When an IT services company like Core-1 suffers a breach, the internal files often contain information about both business and individual clients. Internal files exfiltrated can include contracts, invoices, shipping addresses, phone numbers, email accounts, and proof of hardware serial numbers tied to real people. If your family has ever used an ITAD provider, recycled old computers through a professional service, or had a business send hardware for secure destruction, your details may now sit in a ransomware leak. Criminals treat such data as raw material for identity theft, account takeovers, and targeted scams against you or your children.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently link names, addresses, emails, and phone numbers to specific devices or service tickets. Once criminals have that chain, they can correlate it with usernames found on gaming platforms, social media, or older breaches. A single leaked address can connect your work email to a child’s Roblox or Fortnite account, turning a corporate ransomware incident into household doxxing. Credential leaks like this one routinely cascade into account takeovers because people reuse passwords across work, personal, and gaming logins. The result is a map that lets attackers harass, impersonate, or extort family members who never directly interacted with Core-1.