LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › originalfootwear.com Listed by lockbit3 Ransomware Group

HIGH severityUnverified claimHow we verify

originalfootwear.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 8, 2024
originalfootwear.com Listed by lockbit3 Ransomware Group

Reported February 8, 2024.

HIGH
Severity
February 8, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The originalfootwear.com Listed by lockbit3 Ransomware Group (reported February 8, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target manufacturers and suppliers that sit inside critical supply chains, using public leak sites to pressure organisations into paying. In early February 2024 one such listing named originalfootwear.com, a U.S. maker of occupational and tactical footwear. The claim, posted by the group known as lockbit3, asserts that internal files were taken during a ransomware attack. Because the number of people affected remains unknown and the precise contents of the files have not been confirmed, the incident still warrants careful attention from anyone who has done business with the company or its brands.

What follows is a factual account of what is publicly recorded, the background of the actor involved, and the practical implications for individuals and the organisation itself. No additional details beyond the reported facts have been invented.

What happened

On 8 February 2024, originalfootwear.com appeared on a leak site operated by the ransomware group lockbit3. The listing states that internal files were exfiltrated in a ransomware attack. Public records do not disclose when the intrusion began, how the attackers gained access, whether encryption was deployed on production systems, or whether any ransom demand was paid. The number of people affected is listed as unknown. No independent confirmation of the breach has been released in the available facts; the listing itself remains a claim by the group.

The organisation is described as Original Footwear, a manufacturer based in Morrison, Tennessee, founded in 1999 and parent to the Altama and Original S.W.A.T. brands. Beyond the assertion that internal files were taken, no further technical indicators, file counts, or sample data have been made public in the reported summary.

Who is lockbit3?

Lockbit3 is the current iteration of the LockBit ransomware operation, a long-running ransomware-as-a-service group that has been active for several years. The group typically recruits affiliates who conduct the initial intrusion and deployment; in return the affiliates share a portion of any ransom paid. Once data is stolen, LockBit operators commonly post the victim’s name on a dedicated leak site and threaten to release the material if payment is not received within a set period. The group has previously claimed responsibility for attacks against a wide range of sectors, including manufacturing, logistics and professional services. Its public communications emphasise speed of encryption and the volume of data allegedly taken, tactics designed to increase pressure on the victim.

In this instance the group claims that originalfootwear.com was among its victims and that internal files were exfiltrated. No further statements from lockbit3 about this specific organisation appear in the available facts, and the listing has not been independently verified.

originalfootwear.com and its sector

Original Footwear manufactures occupational and tactical footwear intended for military personnel, law-enforcement officers and first responders. The company, founded in 1999 and headquartered in Morrison, Tennessee, operates the Altama and Original S.W.A.T. brands. Organisations of this type typically maintain supplier contracts, product specifications, employee records, customer order histories and, in some cases, limited personal data linked to wholesale or government procurement accounts.

A breach affecting a supplier of specialised protective equipment can have consequences beyond the company itself. Military and public-safety customers rely on consistent product quality and secure supply chains; any disruption or loss of confidence can affect readiness and procurement processes. Because the firm sits inside those supply chains, the exposure of internal files—if the claim is accurate—raises questions about the integrity of design documents, pricing information and contractual relationships that are not normally public.

What data was at risk

The only data category named in the reported facts is “internal files exfiltrated in a ransomware attack.” No inventory of those files, no sample documents and no confirmation of personal identifiers, financial records or proprietary designs have been released. The number of individuals whose information may be contained in the files is listed as unknown.

Companies that manufacture tactical footwear commonly hold employee personnel files, vendor contracts, product-development drawings, quality-control records and customer order data. Whether any of those categories were among the files claimed by lockbit3 remains unconfirmed. Readers should therefore treat the precise contents as undisclosed until further official information appears.

What's at stake

For individuals, the principal risk is that any personal or contact information stored in internal systems could later appear in secondary markets or be used for targeted phishing. Because the scale of exposure is unknown, it is impossible to quantify how many people may be affected. Employees, contractors and wholesale customers are the groups most likely to have data inside corporate file stores.

For the organisation the stakes include potential operational disruption, loss of competitive information, and damage to relationships with government and first-responder buyers who expect secure handling of supply-chain data. Even if encryption was not deployed, the mere claim of data theft can trigger contractual notification obligations and reputational scrutiny. Until the company or independent investigators publish verified findings, both the human and commercial impact remain provisional.

What to do if you're exposed

Anyone who has worked for, contracted with, or purchased from Original Footwear or its brands should monitor financial and email accounts for unusual activity and enable multi-factor authentication wherever it is offered. If you receive unexpected messages that reference the company or its products, treat them with caution and verify the sender through a known channel. Changing passwords on any accounts that reused credentials associated with the organisation is a prudent first step.

Because the full scope of the claimed exfiltration is still unconfirmed, a practical next action is to check whether your email address has already appeared in other known breach data sets. Free exposure-scan tools can perform that check without requiring payment or the creation of an account. If matches are found, prioritise password changes and credit monitoring for the services involved. Continue to watch for any official statements from the company that may clarify which data categories were actually taken.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyoriginalfootwear.com security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See originalfootwear.com’s full breach history →

More recent breaches

acwlaw.com Listed by lockbit3 Ransomware GroupNovember 22, 2024madison-home.com Listed by lockbit3 Ransomware GroupOctober 30, 2024glsco.com Listed by lockbit3 Ransomware GroupJuly 18, 2024fbrlaw.com Listed by lockbit3 Ransomware GroupJuly 18, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the originalfootwear.com Listed by lockbit3 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram