Ransomware victim disclosure
← All victimsnorthernsafety.com
Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedSep 16, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Sep 16, 2024
About the victim
AI dossier — public-source company profileNorthern Safety Co., Inc. is a personal protective equipment and safety supplies distributor serving customers across the United States. A subsidiary of the Würth Group, the company offers respirators, earplugs, first aid kits, gloves, hard hats, safety glasses, and other occupational safety products to diverse industries including construction, manufacturing, and utilities.
- Industry
- Personal Protective Equipment & Safety Supplies Distribution
- Address
- 761 S. Danny Thomas Blvd. Memphis, TN 38126 USA
Attack summary
Severity: high — Confirmed exfiltration of sensitive business data at significant scale (750 GB) including financial records, HR information, and employee personal/confidential data. Data has been published.BlackBasta claims to have exfiltrated approximately 750 GB of data from Northern Safety, including corporate records, financial data, HR information, and employee personal data. The group has published the data as proof of the breach.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate data
- Finance data
- HR records
- Employee personal data
- Employee confidential data
What the group claims
Northern Safety Co., Inc. operates as a personal safety equipment distributor company. The Company offers disposable respirators, earplugs, first aid kits, gloves, hard hats, safety glasses, safety supplies, traffic work boots, and fall harnesses. Northern Safety serves customers in the United States.SITE: www.northernsafety.com Address : 761 S. Danny Thomas Blvd. Memphis, TN 38126 USAALL DATA SIZE: ≈750gb 1. Corporate data 2. Finance data 3. HR 4. Users, Employees personal, confidential data & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

