originalfootwear.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The originalfootwear.com Listed by lockbit3 Ransomware Group (reported February 8, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target manufacturers and suppliers that sit inside critical supply chains, using public leak sites to pressure organisations into paying. In early February 2024 one such listing named originalfootwear.com, a U.S. maker of occupational and tactical footwear. The claim, posted by the group known as lockbit3, asserts that internal files were taken during a ransomware attack. Because the number of people affected remains unknown and the precise contents of the files have not been confirmed, the incident still warrants careful attention from anyone who has done business with the company or its brands.
What follows is a factual account of what is publicly recorded, the background of the actor involved, and the practical implications for individuals and the organisation itself. No additional details beyond the reported facts have been invented.
What happened
On 8 February 2024, originalfootwear.com appeared on a leak site operated by the ransomware group lockbit3. The listing states that internal files were exfiltrated in a ransomware attack. Public records do not disclose when the intrusion began, how the attackers gained access, whether encryption was deployed on production systems, or whether any ransom demand was paid. The number of people affected is listed as unknown. No independent confirmation of the breach has been released in the available facts; the listing itself remains a claim by the group.
The organisation is described as Original Footwear, a manufacturer based in Morrison, Tennessee, founded in 1999 and parent to the Altama and Original S.W.A.T. brands. Beyond the assertion that internal files were taken, no further technical indicators, file counts, or sample data have been made public in the reported summary.
Who is lockbit3?
Lockbit3 is the current iteration of the LockBit ransomware operation, a long-running ransomware-as-a-service group that has been active for several years. The group typically recruits affiliates who conduct the initial intrusion and deployment; in return the affiliates share a portion of any ransom paid. Once data is stolen, LockBit operators commonly post the victim’s name on a dedicated leak site and threaten to release the material if payment is not received within a set period. The group has previously claimed responsibility for attacks against a wide range of sectors, including manufacturing, logistics and professional services. Its public communications emphasise speed of encryption and the volume of data allegedly taken, tactics designed to increase pressure on the victim.
In this instance the group claims that originalfootwear.com was among its victims and that internal files were exfiltrated. No further statements from lockbit3 about this specific organisation appear in the available facts, and the listing has not been independently verified.
originalfootwear.com and its sector
Original Footwear manufactures occupational and tactical footwear intended for military personnel, law-enforcement officers and first responders. The company, founded in 1999 and headquartered in Morrison, Tennessee, operates the Altama and Original S.W.A.T. brands. Organisations of this type typically maintain supplier contracts, product specifications, employee records, customer order histories and, in some cases, limited personal data linked to wholesale or government procurement accounts.
A breach affecting a supplier of specialised protective equipment can have consequences beyond the company itself. Military and public-safety customers rely on consistent product quality and secure supply chains; any disruption or loss of confidence can affect readiness and procurement processes. Because the firm sits inside those supply chains, the exposure of internal files—if the claim is accurate—raises questions about the integrity of design documents, pricing information and contractual relationships that are not normally public.
What data was at risk
The only data category named in the reported facts is “internal files exfiltrated in a ransomware attack.” No inventory of those files, no sample documents and no confirmation of personal identifiers, financial records or proprietary designs have been released. The number of individuals whose information may be contained in the files is listed as unknown.
Companies that manufacture tactical footwear commonly hold employee personnel files, vendor contracts, product-development drawings, quality-control records and customer order data. Whether any of those categories were among the files claimed by lockbit3 remains unconfirmed. Readers should therefore treat the precise contents as undisclosed until further official information appears.
What's at stake
For individuals, the principal risk is that any personal or contact information stored in internal systems could later appear in secondary markets or be used for targeted phishing. Because the scale of exposure is unknown, it is impossible to quantify how many people may be affected. Employees, contractors and wholesale customers are the groups most likely to have data inside corporate file stores.
For the organisation the stakes include potential operational disruption, loss of competitive information, and damage to relationships with government and first-responder buyers who expect secure handling of supply-chain data. Even if encryption was not deployed, the mere claim of data theft can trigger contractual notification obligations and reputational scrutiny. Until the company or independent investigators publish verified findings, both the human and commercial impact remain provisional.
What to do if you're exposed
Anyone who has worked for, contracted with, or purchased from Original Footwear or its brands should monitor financial and email accounts for unusual activity and enable multi-factor authentication wherever it is offered. If you receive unexpected messages that reference the company or its products, treat them with caution and verify the sender through a known channel. Changing passwords on any accounts that reused credentials associated with the organisation is a prudent first step.
Because the full scope of the claimed exfiltration is still unconfirmed, a practical next action is to check whether your email address has already appeared in other known breach data sets. Free exposure-scan tools can perform that check without requiring payment or the creation of an account. If matches are found, prioritise password changes and credit monitoring for the services involved. Continue to watch for any official statements from the company that may clarify which data categories were actually taken.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
acwlaw.com Listed by lockbit3 Ransomware Groupmadison-home.com Listed by lockbit3 Ransomware Groupglsco.com Listed by lockbit3 Ransomware Groupfbrlaw.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the originalfootwear.com Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.