HackerFeeds
All ransomware incidents
aldoshoes.com

Ransomware group clop hits ALDOGROUP.COM(ALDOSHOES.COM)

CRITICAL
·Retail & E-Commerce·CA·2026-09-23

ALDOGROUP.COM(ALDOSHOES.COM) — a retail & e-commerce target operating in CA has been listed by the clop ransomware group on 2026-09-23. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationALDOGROUP.COM(ALDOSHOES.COM)
Threat Group
clop
Summary[AI generated] Aldo Group (aldoshoes.com) is a Canadian footwear and accessories company headquartered in Montreal, Quebec. Operating in the retail and fashion industry, it designs, manufactures, and sells shoes, handbags, and accessories through brands including ALDO, Call It Spring, and Globo. The company operates retail stores and e-commerce platforms internationally, serving customers across North America, Europe, the Middle East, and Asia.
Date of Breach2026-09-23
Discovery Date2026-09-23
RegionCA
Target DomainALDOSHOES.COM
Business SectorRetail & E-Commerce
Severity
CRITICAL

Claim by clop

[AI generated] Aldo Group (aldoshoes.com) is a Canadian footwear and accessories company headquartered in Montreal, Quebec. Operating in the retail and fashion industry, it designs, manufactures, and sells shoes, handbags, and accessories through brands including ALDO, Call It Spring, and Globo. The company operates retail stores and e-commerce platforms internationally, serving customers across North America, Europe, the Middle East, and Asia.

Posted by the clop threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

ALDOSHOES.COM

Leak post (onion / Tor)

tor

http://santat7kpllt6iyvqbr7q4amdv6dzrh6paatvyrzl7ry3zm72zigf4ad.onion/aldogroup-com-aldoshoes-com

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.