Ransomware victim disclosure
← All victimsFoot Solutions
Claimed by qilin · listed 6 days ago
Status timeline
- Listed
May 15, 2026
- Data leaked
At a glance
- Group
- qilin
- Status
- Data leaked
- Country
- US
- Sector
- Consumer Services
- Listed on leak site
- May 15, 2026
About the victim
AI dossier — public-source company profileFoot Solutions is a US-based specialty retail franchise with locations also in Ireland, UK, Australia, Canada, and Quebec, focused on foot wellness for over 20 years. The company offers custom orthotics (including 3D-printed in-house), arch supports, and healthy footwear, conducting comprehensive foot and gait analyses at retail locations. It serves thousands of medical referrals annually and operates a franchise model across multiple countries.
- Industry
- Specialty Retail – Foot Health & Custom Orthotics
Attack summary
Severity: high — Data has been published by the group (data_published status), indicating confirmed exfiltration. As a foot health and orthotics provider serving medical referrals, the company likely holds health-related customer PII, elevating sensitivity. No specific data inventory was published but the combination of confirmed publication and health-adjacent consumer data warrants a high severity rating.The Qilin ransomware group claims an attack on Foot Solutions with a disclosed status of 'data_published', indicating data has been exfiltrated and released. No specific data volume or ransom demand was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal information
- Medical/foot health records
- Franchise business records
- Employee data
- Financial records
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
