Ransomware victim disclosure
← All victimsRug & Home
Claimed by Rhysida · listed 5 days ago
Status timeline
- ListedSep 8, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Sector
- Retail
- Listed on leak site
- Sep 8, 2026
- Data size
- 1.55 TB
- Records
- 50193 customers, ~10800 delivery note scans, ~60 B2B supplier portal passwords
About the victim
AI dossier — public-source company profileRug & Home is a US-based retailer specializing in rugs, furniture, and home décor. The company operates a B2B supplier network and maintains customer sales operations at scale.
- Industry
- Home Furnishings & Décor Retail
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII (50K+ customer records with full contact details), employee SSNs and tax data, banking credentials, protected health information (disability certificates under GDPR Article 9), and sensitive M&A/corporate records. Multi-category regulated data exposure at industrial scale.Rhysida claims to have exfiltrated 1.55 TB of data including customer databases, employee records, tax documents, payroll systems, bank details, and extensive B2B/M&A materials. The group is auctioning the data with a 7-day bidding window.
Data the group says was taken
AI dossier — extracted from the leak post- Customer database (50,193 records with names, addresses, emails, phone, purchase history)
- Delivery notes with addresses and phone numbers (~10,800 scans)
- B2B supplier portal credentials (plaintext passwords for ~60 portals)
- Tax forms (W-2, 1099, W-9 with SSNs)
- Payroll database (Sage EMPLOYEE/ESWAGE system)
- Bank account details (First Citizens Bank) and employee direct deposit information
- HR records (background checks, terminations, workplace injuries, 401k)
- CRM backup (customers, contacts, deals, communications)
- M&A materials (~150 active deals, 70,000+ files from data rooms, 12,500+ SPAs, 7,500+ NDAs, 3,900+ audited reports)
- Payroll records with IBANs (~1,300 records)
- Employment contracts (~1,200)
- Passport/ID scans (483, including disability certificates)
- KYC/AML files (~4,200)
What the group claims
A leading destination in the USA for rugs, furniture, and home decor, offering a vast selection of unique designs and top brands.
The leak post
captured from the group's siteRug & Home is a leading destination in the USA for rugs, furniture, and home decor, offering a vast selection of unique designs and top brands.Database of 50,193 customers�full names, home addresses, email addresses, phone numbers, purchase amounts (CSV)~10,800 scans�signed delivery notes with customer addresses/phone numbersPlaintext passwords for ~60 B2B supplier portalsW-2, 1099, W-9 � tax forms with employees' and contractors' SSNsPayroll database for all employees (Sage EMPLOYEE/ESWAGE)Company bank details (First Citizens Bank deposits) and employee accounts (direct deposit)HR: background checks, terminations, workplace injuries, 401(k)And much more With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! As a key player in Hungarian development policy, our Company participates in the planning and implementation of development programs based on certain EU and domestic funds. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to bu…
Data the group says was taken
- customer database
- full names
- home addresses
- email addresses
- phone numbers
- purchase amounts
- signed delivery notes
- plaintext passwords
- W-2 forms
- 1099 forms
- W-9 forms
- SSNs
- payroll database
- bank details
- employee accounts
- background checks
- termination records
- workplace injury records
- 401(k) records
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

