On July 10, 2024, the ransomware group Flocker publicly listed O***M on its leak site, claiming it had breached the organization’s network at O***M.com and exfiltrated 450GB of highly confidential internal files. The disclosure indicates that anyone whose personal or financial information was stored in those systems may now be at risk of identity theft, account takeover, or targeted fraud.
Watch O***M
Get alerted the next time O***M files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about O***M’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Flocker leak-site posting states that the group gained access to O***M’s systems and removed 450GB of internal data. The listing does not specify the exact types of records taken, the number of individuals affected, or the precise date of initial compromise. It follows the group’s standard format: an initial access claim followed by samples of allegedly stolen material and a demand for payment to prevent full publication. No official breach notification from O***M had appeared on state attorney-general portals or SEC filings at the time the listing went live.
Why This Matters for You and Your Family
When a company that holds your data suffers a ransomware attack, the consequences reach far beyond corporate embarrassment. Internal files frequently contain names, addresses, dates of birth, Social Security numbers, medical records, or payment details. If any of that information belongs to you or someone in your household, it can be sold, traded, or used to open fraudulent accounts in your name. Children’s records are especially attractive because they often remain unused and undetected for years. The breach also signals that the company’s security posture was insufficient to stop the intrusion, raising questions about how safely your information was stored in the first place.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at encrypting files. Once data is exfiltrated, it becomes fuel for long-term extortion and doxxing campaigns. A single leaked email or phone number can be correlated with usernames on gaming platforms, social media, and shopping sites. Attackers then build an identity chain that links your real name to your children’s Roblox or Fortnite accounts, school emails, and family address. That chain makes targeted phishing, SIM-swapping, and swatting far easier. Even if the full 450GB archive is not immediately published, subsets of the data are often circulated in underground markets where other criminals can exploit them for years.