milliondollarbabyco.com Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
milliondollarbabyco.com was listed by the dragonforce ransomware group on April 14, 2026, with internal files reported exfiltrated. Individuals who may have had dealings with the company should review any notices from the organisation and consider protective steps such as monitoring accounts and changing passwords.
On April 14, 2026, the ransomware group dragonforce listed milliondollarbabyco.com on its leak site, claiming to have obtained internal files from the company through a ransomware operation. The number of individuals whose information may be involved remains unknown, as does the precise nature or volume of any data that left the organisation. For customers, employees, and business partners of a children’s furniture supplier, the practical question is whether personal or operational records have moved outside the company’s control.
Breaking down the breach
The only confirmed public detail is the listing itself. The group states that internal files were exfiltrated during a ransomware attack. No figure has been released for the number of records, the date of the intrusion, or the method used to gain access. The company has not issued a public statement confirming or denying the claims, and independent verification of the data’s contents has not been published.
Inside dragonforce
Dragonforce is a ransomware operator that maintains a public leak site where it posts the names of organisations it claims to have targeted. Like other groups in this category, it typically combines data theft with encryption of systems and then uses the threat of publication to pressure victims. The group’s listings are assertions made by the actors themselves; independent confirmation of the underlying incidents varies from case to case.
About milliondollarbabyco.com
Million Dollar Baby Co. is a privately held company founded in 1990 and based in Los Angeles. It operates seven children’s furniture brands, including Babyletto, daVinci, Nursery Works, and Namesake. Its products are sold through major retailers such as Target and Amazon as well as specialty stores. As a manufacturer and wholesaler in the juvenile products sector, the company routinely handles supplier contracts, design specifications, employee records, and customer or retailer account information.
The information in question
The listing refers only to “internal files.” No inventory of specific data types has been released. Companies of this kind commonly store customer order details, retailer account credentials, employee personal information, and proprietary product or supply-chain records. Whether any of these categories are present in the claimed exfiltration is not confirmed by the available facts.
Why it matters
Exposure of internal files can create downstream risks for individuals whose details appear in those records, such as unauthorised account access or targeted fraud. For the organisation, the incident may affect relationships with retailers and suppliers that rely on the confidentiality of shared commercial information. Because the scale of exposure is undisclosed, the full extent of these consequences cannot yet be measured.
What to do if you're exposed
Individuals who have placed orders with the company’s brands or who work with its retailers can monitor their financial and email accounts for unusual activity. Enabling multi-factor authentication on retailer and payment accounts reduces the chance that stolen credentials can be used. Running a free exposure scan of one’s email address against known breach data provides a quick way to check whether any of one’s information has already appeared in public listings from incidents such as this one.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
rosehillgardens.com Listed by dragonforce Ransomware Groupavalonflooring.com Listed by dragonforce Ransomware Groupkleankanteen.com Listed by dragonforce Ransomware GroupEdward Beiner Listed by dragonforce Ransomware GroupLatest breaches
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.