City Furniture was listed on the Hive ransomware leak site on July 14, 2022, with the group claiming to have exfiltrated internal files during a ransomware attack. The Florida-based home furnishings retailer’s customers, employees, and business partners now face the possibility that sensitive company data has been stolen and may surface publicly or be sold on underground markets.
Watch City-Furniture
Get alerted the next time City-Furniture files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about City-Furniture’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure comes directly from the Hive ransomware group’s leak portal. The listing states that City Furniture suffered a ransomware intrusion and that attackers successfully exfiltrated internal files. The site does not specify the volume of data taken, the exact types of records involved, or name any particular databases or systems. It simply states that internal data was removed prior to encryption and that the company has not met the group’s demands. As of the listing date, no sample files had been published, though ransomware operators frequently release proof packets or full archives if victims refuse to pay.
Why This Matters for You and Your Family
When a retailer like City Furniture loses control of internal files, the exposure often reaches far beyond the company. Purchase records, delivery addresses, phone numbers, email accounts, and payment details tied to customer orders can easily appear in the stolen bundle. If you have ever bought furniture from City Furniture, your residential address, order history, and contact information may now sit in an attacker-controlled archive. Employees’ payroll files, HR documents, or vendor contracts could also be included, creating direct identity and financial risks for staff and their households. The disclosure indicates the data was taken in a ransomware attack, meaning the files were deliberately chosen and removed before any encryption occurred.
Doxxing and Identity-Chain Risks
Stolen internal files frequently contain enough personal details to link disparate online handles to real-world identities. An email address found in a customer spreadsheet can be cross-referenced with usernames used on shopping sites, social media, or gaming platforms. Once attackers or data resellers establish those connections, they can build detailed profiles that include family members, home addresses, and even children’s accounts. Credential leaks of this nature regularly cascade into account takeovers, especially for gaming services where kids reuse passwords or email addresses tied to a parent’s purchase history. The result is a doxxing chain that can expose your family’s daily routines, locations, and financial habits.