Widdop & Co. Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Widdop & Co. Listed by rhysida Ransomware Group (reported May 18, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
People whose contact details or business dealings appear in supplier and buyer records may now face unwanted outreach, fraud attempts, or competitive misuse of commercial information. Public reporting indicates that Widdop & Co., a family-owned wholesale gifts and home-decor supplier, was listed by the rhysida ransomware group on 18 May 2024 after an alleged ransomware attack in which internal files were said to have been taken.
The group claims to be offering the source code of the company’s Widdop Data System program together with related SQL databases dated 29 April 2024. Exact numbers of individuals affected remain unknown, and independent confirmation of the full scope is limited. What is known so far is enough to warrant careful attention from anyone who has traded with or supplied the firm.
Inside the incident
According to the listing attributed to rhysida, the group claims to have exfiltrated internal files during a ransomware attack against Widdop & Co. The material offered for sale is described as the source code of the Widdop Data System program and associated SQL databases dated 29 April 2024. The group further asserts that these databases hold records of all suppliers and buyers with contact details, the company’s financial flows, and algorithms used for discounts and margins. It characterises the package as a “turnkey ready-made business.”
Public detail beyond this claim is limited. The number of people affected is unknown. The precise method of initial access, the duration of any intrusion, and whether encryption was also deployed have not been disclosed in available reporting. The listing itself was reported on 18 May 2024. No independent verification of the volume or completeness of the alleged data has been published.
Who is rhysida?
Rhysida is a ransomware group that has operated since mid-2023 and is known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish or sell it if a ransom is not paid. The group typically posts victim names and sample files on a dedicated leak site, then offers the full data set for purchase or free download after a short countdown. It has previously claimed responsibility for attacks on healthcare providers, educational institutions, government contractors and commercial firms across multiple countries.
Like other ransomware operators, rhysida relies on initial access through phishing, exploited vulnerabilities or compromised credentials, followed by lateral movement and data staging before encryption. Its public statements about any single victim should be treated as claims until corroborated by the organisation or independent forensic work. In this case the listing of Widdop & Co. remains an unverified assertion by the group.
Widdop & Co. and its sector
Widdop & Co. is described as a family-owned wholesale supplier of gifts and home décor. Businesses of this type sit in the middle of retail supply chains: they source products from manufacturers, maintain catalogues and pricing structures, manage wholesale accounts, and ship goods to independent retailers and larger chains. They routinely hold supplier and customer contact lists, order histories, pricing algorithms, margin calculations and internal financial records.
A breach involving such records can disrupt commercial relationships, expose negotiating positions, and create opportunities for competitors or fraudsters to impersonate legitimate trading partners. Because wholesale operations often process personal data of sole traders and small-business owners alongside corporate accounts, the impact can reach individuals as well as companies.
The information in question
The rhysida listing claims the exposed material consists of internal files, specifically the source code of the Widdop Data System program and SQL databases containing all suppliers and buyers with contact details, the company’s financial flows, and algorithms for discounts and margins. No further breakdown of file counts, exact fields or personal identifiers has been published. The number of people whose data may be present is unknown.
Organisations of this kind typically store names, addresses, telephone numbers, email addresses, account numbers, order histories and banking or payment references for suppliers and wholesale customers. Whether those specific elements appear in the claimed databases remains unconfirmed. Readers should therefore treat the precise contents as alleged rather than established fact.
Why it matters
If the claimed databases are genuine, suppliers and buyers could face targeted phishing, invoice fraud or social-engineering attempts that reference real trading relationships. Contact details may be used for spam or more sophisticated scams. Financial-flow data and margin algorithms could give competitors insight into pricing strategies or allow outsiders to undercut legitimate offers. Source-code exposure, if accurate, raises the additional risk that proprietary business logic could be reused or reverse-engineered.
For Widdop & Co. itself the incident carries operational, reputational and potential regulatory consequences. Even without confirmed personal-data volumes, the mere listing can erode trust among trading partners. Affected individuals and small businesses may need to monitor accounts and communications for unusual activity for months after any public release.
If your data was in this claimed breach
If you have done business with Widdop & Co. as a supplier or buyer, treat unsolicited messages that reference past orders or account details with caution. Verify any payment or banking change requests through a known, independent channel. Consider placing fraud alerts with relevant credit-reference services if personal identifiers may be involved, and update passwords on any accounts that reused credentials linked to the company.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Stay alert for follow-up communications from the company itself once official statements become available, and retain records of any suspicious contact for possible reporting to local fraud authorities.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Sibbalds Listed by rhysida Ransomware GroupMatlock Security Services Listed by rhysida Ransomware GroupDe Rose Lawyers Listed by rhysida Ransomware GroupFylde Coast Academy Trust Listed by rhysida Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Widdop & Co. Listed by rhysida Ransomware Group →
Publicly posted by rhysida — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.