Ransomware victim disclosure
← All victimsjonti-craft.com
Claimed by Blackbasta · listed 2 years ago
Status timeline
- ListedNov 19, 2024
- Data leakeddate unknown
At a glance
- Group
- Blackbasta
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Nov 19, 2024
About the victim
AI dossier — public-source company profileJonti-Craft, Inc. is a family-owned manufacturer of children's furniture for educational and recreational settings including classrooms, daycares, libraries, and waiting rooms. Based in Wabasso, Minnesota, they produce branded lines such as Baltic Birch, Berries, and EverPlay furniture emphasizing safety, durability, and developmental benefit.
- Industry
- Children's Furniture Manufacturing
- Address
- 171 State Highway 68, PO Box 30, Wabasso, MN 56293, USA
Attack summary
Severity: high — Confirmed exfiltration of 700 GB spanning multiple sensitive categories including financial, payroll, HR, and personal data from a manufacturing company. Scale and data diversity indicate significant business and employee information exposure.Black Basta claims to have exfiltrated approximately 700 GB of data from Jonti-Craft, including home user records, financial data, payroll information, personal data, human resources records, and engineering documentation.
Data the group says was taken
AI dossier — extracted from the leak post- Home user/customer data
- Financial records
- Payroll information
- Personal data
- Human Resources records
- Engineering documents
What the group claims
Jonti-Craft is a family-owned company that manufactures children’s furniture for a variety of settings, including classrooms, daycares, and waiting rooms.SITE: www.jonti-craft.com Address : 171 State Highway 68 PO Box 30, Wabasso MN 56293 USATEL#: (507) 342-5169ALL DATA SIZE: ≈700gb 1. Home users data 2. Financial data, Payroll 3. Personal 4. Human Resources 5. Engineering 6. Depts & etc…
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

