Incident Details
- Victim: Rug & Home
- Sector: Retail & E-Commerce
- Country: US
- Actor: rhysida
- Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=267
- Discovered: 2026-09-07T17:01:07.710515+00:00
- Published: 2026-09-07T17:00:45.402655+00:00
Information
- Database of 50,193 customers, including full names, home addresses, email addresses, phone numbers, and purchase amounts (CSV)
- About 10,800 scans of signed delivery notes with customer addresses and phone numbers
- Plaintext passwords for around 60 B2B supplier portals
- W-2, 1099, and W-9 tax forms containing employees’ and contractors’ SSNs
- Payroll database for all employees (Sage EMPLOYEE/ESWAGE)
- Company bank details, including First Citizens Bank deposits, and employee direct deposit account information
- HR records such as background checks, terminations, workplace injuries, and 401(k) data
- Additional sensitive internal data and documents

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.