Ransomware victim disclosure
← All victimsStokes Inc.
listed as Stokes · Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 13, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileStokes Inc. is Canada's leading tableware, kitchenware and home décor retailer, headquartered in Montreal, Quebec. The privately owned company operates two brands — Stokes and thinkkitchen — across more than 100 stores nationwide, complemented by a growing e-commerce presence. The company employs more than 1,000 associates.
- Industry
- Tableware, Kitchenware & Home Décor Retail
- Address
- Montreal, Quebec, Canada
- Employees
- 1000+
Attack summary
Severity: high — Confirmed exfiltration of 23 GB including employee PII (addresses, phone numbers, personal bank statements) and client data constitutes significant sensitive data exposure; bank statements in particular border on regulated financial data, and the scale (1,000+ employees plus client records) elevates severity.Akira claims to have exfiltrated approximately 23 GB of corporate data from Stokes Inc., including employee personal information, financial records, client information, contracts and agreements, and other confidential files, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information (phone numbers, addresses)
- Employee personal bank statements
- Confidential corporate files
- Financial records
- Client information
- Contracts and agreements
What the group claims
Stokes Inc. is Canadas leading tableware, kitchenware and home dé cor store. Based in Montreal, we are a privately owned and operat ed company with two brands at the heart of our success: Stokes an d thinkkitchen. Now operating more than 100 stores in Canada, as well as running an ever-growing online presence, we employ more t han 1,000 associates and are constantly expanding our horizons. We will upload 23gb of corporate data soon. Employee personal inf ormation (phones, addresses, personal bank statements and other i nformation), confidential files, financials, clients information, contracts and agreements, etc.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

