Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Rug & Home data breach. According to dark web monitoring sources, a hacker group calling itself rhysida claimed responsibility for a cyberattack on Rug & Home in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, Rug & Home has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About Rug & Home
Rug & Home is a retailer specializing in rugs, furniture, and home décor. Founded in 1995 and headquartered in Asheville, North Carolina, the company operates showrooms in Asheville, Kannapolis, and Pineville, NC, as well as Gaffney, SC, with close to 200,000 square feet of combined showroom space. The company has between 51 and 200 employees.
What Happened?
On September 7th, 2026, the Rhysida ransomware group listed Rug & Home on its dark-web leak site, as catalogued by Ransomware.live. This is an attacker-side allegation only. No public confirmation from Rug & Home, any regulatory body, or independent journalism has been found. The claim was independently catalogued by RedPacket Security and hendryadrian.com, both of which characterize it as an unverified attacker claim. RedPacket Security notes that no separate compromise date was provided and that the available details suggest a data-exfiltration incident with no explicit claim that systems were encrypted.
Per the attacker’s unverified claim, the allegedly compromised data includes: a customer database of 50,193 records containing full names, home addresses, email addresses, phone numbers, and purchase amounts; approximately 10,800 scans of signed delivery notes with customer addresses and phone numbers; plaintext passwords for approximately 60 B2B supplier portals; W-2, 1099, and W-9 tax forms containing employees’ and contractors’ Social Security numbers; a payroll database; company bank account details and employee direct-deposit information; and HR records including background checks, terminations, workplace injuries, and 401(k) information. None of these data types have been independently confirmed by Rug & Home or any regulator, and all should be treated as allegations.
Rhysida is a ransomware-as-a-service group active since May/June 2023, with close to 300 named victims as of September 2026, roughly half of them US-based organizations. The group uses a double-extortion model and typically gains initial access through compromised credentials. Rhysida is known for prior attacks on the British Library and Insomniac Games, and most recently claimed an attack on Berlin’s state government in August 2026. No prior breaches or security incidents involving Rug & Home were found, and no litigation connected to this specific incident has been identified.
Key Facts at a Glance
- Company or Organization: Rug & Home
- Industry: Retail & E-Commerce (rugs, furniture, home furnishings, home décor)
- Location: Headquartered in Asheville, North Carolina, with additional showrooms in Kannapolis, NC; Pineville, NC; and Gaffney, SC
- Incident type: Ransomware leak-site allegation (Rhysida); data exfiltration claimed
- Litigation status: No litigation connected to this incident found as of September 7th, 2026
- Source: Ransomware.live – Victim: Rug & Home; RedPacket Security – [RHYSIDA] Ransomware Victim: Rug & Home; hendryadrian.com – Ransom! Rug & Home (SEP-2026)
What Should You Do?
If you believe you may have been affected by this alleged incident, there are practical steps you can take now. Visit AnnualCreditReport.com to review your credit reports from all three major bureaus for any unfamiliar accounts or inquiries. Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion to make it harder for someone to open new accounts in your name. Monitor your existing financial accounts closely for unauthorized transactions. Because the attacker’s claim includes Social Security numbers from tax documents and payroll records, employees and contractors should be especially vigilant. If you notice signs of identity theft, report them to the Federal Trade Commission at IdentityTheft.gov, which can help you create a personalized recovery plan.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.