Ransomware victim disclosure
← All victimsMerchNOW
Claimed by Akira · listed 2 months ago
Status timeline
- ListedMar 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Mar 31, 2026
About the victim
AI dossier — public-source company profileMerchNOW is a US-based music merchandising company with over 20 years of experience. They specialize in products such as music, apparel, accessories, and custom merchandise for bands and artists. Their services include screen printing, record pressing, embroidery, and order fulfillment.
- Industry
- Music Merchandising & Fulfillment
Attack summary
Severity: critical — The group claims exfiltration of regulated PII at scale — including SSNs, passports, and driver's licenses belonging to employees — alongside financial and client data. This constitutes confirmed exfiltration of sensitive regulated personal data meeting the critical threshold, with data publication explicitly threatened.Akira claims to have exfiltrated a significant volume of corporate data from MerchNOW, including employee personal identity documents (passports, driver's licenses, SSNs), financial records, contracts, client files, NDAs, and project materials, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Driver's licenses
- Social Security Numbers (SSNs)
- Scanned identity documents
- Financial records
- Contracts and agreements
- Client files
- NDAs
- Project files
What the group claims
MerchNow is a music merchandising company with over 20 years of e xperience, specializing in a wide range of products including mus ic, apparel, accessories, and custom merchandise for bands. They offer services such as screen printing, record pressing, embroide ry, and fulfillment to help artists create unique merchandise. We will upload corporate data soon. Great amount of employee pers onal documents (passports, DLs, SSNs and other scanned docs), fin ancials, contracts and agreements, client files, NDA, projects, e tc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

