Knoll Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Knoll Listed by alphv Ransomware Group (reported October 6, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continued through 2022 to target established manufacturers and design firms, pairing encryption with data theft and public leak-site pressure. In that environment, the appearance of Knoll on an alphv listing in early October underscored how even companies outside the most frequently attacked sectors can find internal material claimed as stolen.
Public reporting on 6 October 2022 stated that Knoll, a subsidiary of MillerKnoll, Inc., had been listed by the alphv ransomware group after an asserted ransomware attack in which internal files were exfiltrated. The number of people affected remains unknown, and many operational details have not been disclosed. The episode matters because office-furniture and design businesses hold supplier, employee, customer and project records whose exposure can create lasting practical risk even when the precise contents stay unconfirmed.
What happened
According to the reported summary, Knoll was listed by the alphv ransomware group on or around 6 October 2022. The listing described internal files as having been exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of individuals affected, or the precise date the intrusion began. The method of initial access, the duration of any dwell time, and whether systems were encrypted in addition to the claimed theft have not been detailed in the available record. What is known is limited to the group’s claim that it held and intended to release internal Knoll material.
The group behind it: alphv
Alphv, also widely known as BlackCat, is a ransomware operation that rose to prominence in 2021 and operated as a ransomware-as-a-service model. Affiliates typically gain access, move laterally, exfiltrate data, and then deploy encryption while threatening to publish the stolen material on a dedicated leak site if payment is not made. The group has been associated with attacks across manufacturing, professional services and other sectors, often using double-extortion tactics. In this case the group claims Knoll as a victim and asserts that internal files were taken; that claim has not been independently confirmed in the public facts available here, and no specific statements by alphv beyond the listing itself are recorded.
About Knoll
Knoll is an American design and manufacturing firm and a subsidiary of MillerKnoll, Inc. It produces office systems, seating, files and storage, tables and desks, textiles and accessories for workplace, residential and higher-education settings. Through its KnollStudio division it manufactures furniture associated with designers including Ludwig Mies van der Rohe, Harry Bertoia, Florence Knoll, Frank Gehry, Charles Gwathmey, Maya Lin and Eero Saarinen. Organisations of this type routinely maintain employee records, supplier and contractor details, customer and dealer information, design and project files, and internal financial or operational documents. A breach affecting such a firm is consequential because those categories of data can be reused for fraud, competitive intelligence or further social-engineering attacks long after the initial incident.
The information in question
The only data type named in the public report is “internal files exfiltrated in ransomware attack.” No inventory of specific file categories, no count of records, and no confirmation of whether personal data, credentials, contracts or design materials were included has been released. Companies in the furniture and office-systems sector typically hold human-resources information, vendor contracts, customer purchase and shipping records, and proprietary design or manufacturing documentation. Because the exact contents remain undisclosed, it is not possible to state what was actually taken; the alphv listing simply asserts that internal files were removed.
What's at stake
For individuals whose information may have been among the claimed files, the practical risks include targeted phishing, identity misuse if personal details were present, and potential exposure of employment or contact data. For Knoll and its parent, the stakes include disruption of operations, possible regulatory or contractual notification duties, reputational harm, and the cost of investigation and remediation. Even when the scale is unknown, the mere assertion that internal material left the organisation can erode trust among employees, dealers and institutional clients. Because the number of people affected is unconfirmed, the full scope of downstream harm cannot yet be measured.
If your data was in this claimed breach
If you have a past or present relationship with Knoll or MillerKnoll as an employee, contractor, customer or supplier, treat the incident as a prompt to review account security. Change passwords on any related accounts, enable multi-factor authentication where available, and watch for unexpected messages that reference the company or request sensitive information. Monitor financial and credit activity for unusual behaviour. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which provides an additional early-warning step while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
SUMITOMO BAKELITE USA Listed by alphv Ransomware GroupSSI Schäfer Shop Listed by alphv Ransomware GroupSchnee Berger Listed by alphv Ransomware GroupAeroproductsco Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Knoll Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.