Ransomware victim disclosure
← All victimsA&A Global Industries
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 18, 2026
About the victim
AI dossier — public-source company profileA&A Global Industries is a U.S.-based supplier and distributor of toys, candy, and creative promotional products. The company serves operators, retailers, and business owners, providing product solutions designed to build customer loyalty and drive foot traffic. It operates as a trusted B2B partner across multiple retail and amusement-adjacent channels.
- Industry
- Toys, Candy & Promotional Products Distribution
Attack summary
Severity: high — The group explicitly claims exfiltration of regulated PII at scale (SSNs, passports, medical information) affecting employees, meeting the threshold for critical/high; however, the data has not yet been published (imminent upload threatened), and no proof files are currently advertised, placing this at high rather than critical pending confirmation.Akira claims to have exfiltrated corporate data from A&A Global Industries and states it will publish detailed personal employee files including SSNs, passports, driver's licenses, and medical information, along with HR records.
Data the group says was taken
AI dossier — extracted from the leak post- Employee SSNs
- Passport documents
- Driver's licenses
- Employee medical information
- HR files
- Corporate data
What the group claims
A&A Global is a trusted partner operators, retailers, and busines s owners turn to for toys, candy, and creative product solutions that build loyalty, increase foot traffic, and drive real busines s results. We will upload corporate data soon. Detailed personal files of em ployees (SSNs, passports, DLs, medical information and other pers onal files), HR files and so on.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

