Rhysida claims Rug & Home data theft
A leak-site listing attributed to Rhysida claims that data from Rug & Home includes customer, worker, supplier and banking records. The listing doesn't independently confirm the theft.
- Report priority
- Critical
- Involves
- Rug & Home
- Group
- Rhysida
What is known
- The indexed post attributes the claim to Rhysida.
- It alleges access to files and databases containing personal, employment, supplier and financial information.
- The post doesn't disclose how access was obtained, whether credentials or malware were used, or whether systems were encrypted.
- Ransomware.live says it indexes operators' public claims without obtaining or checking the underlying data.
What to do
First check whether you're a current or former Rug & Home customer, worker, contractor or B2B supplier. If you are, ask your normal Rug & Home account, HR or privacy contact whether the company has confirmed an incident and whether your records are involved. Suppliers should have their IT or account maintainer identify the portal account Rug & Home used and request specific confirmation about that account. Receiving no notice doesn't establish that you're unaffected.
Follow instructions from a notice you verify through established company or business contact details. Supplier account owners should ask whether their portal credentials were included and what action the responsible portal maintainer recommends.
Reported details
The indexed leak-site claim alleges exposure of customer contact and purchase records, delivery notes, B2B portal passwords, W-2, 1099 and W-9 forms, Sage EMPLOYEE/ESWAGE payroll data, HR files, First Citizens Bank deposit information and employee direct-deposit details. The listing doesn't independently verify the data, the intrusion method or the extent of any compromise.