← All updates

Update · August 16, 2026

BAM is hunting a leaker. The keys to the inside of its Slack were on the open web.

Bricks & Minifigs corporate has spent weeks trying to seal its internal Slack. It has removed more than ten franchise owners and sent each a long letter of alleged violations. It has brought in a bot that owners believe is there to find leakers. It has left owners so afraid of being traced that they will not screenshot the app. It has done more than that, and for longer: a DMCA notice, a flagged livestream, a cease and desist to this site. None of it reaches the leak that matters, because the worst one was never a person. BAM’s own public systems were handing out keys to the inside of its Slack, one for every region it runs, the whole chain at once. Those keys are already out, and a key that has been given out is not taken back by tidying up. This site is not publishing the keys, or the full extent of what they reach.

Everything BAM has tried, so far

Set the effort down first, because it is the story’s other half. In the space of a few weeks, corporate has moved against the flow of information on nearly every front available to it. Here is each move, and what it produced.

BAM’s campaign against the leak, and what came of each move
BAM’s moveWhat came of it
BAM pressed a content-removal order in court. Covered hereIt is being narrowed, not widened.
A BJC livestream was flagged and vanished mid-broadcast; the platform does not name who reported it, and neither will this site. Covered hereBackfired into a Streisand effect. The removal drove interest to the very record it was flagged over: the public UCC-1 tying Legally Mine to 450,000 shares of BAM Franchising stock.
BAM’s legal team sent this site a cease and desist. Covered hereBackfired twice over. It drew more eyes to the documents, and by claiming copyright over them BAM inexplicably corroborated that the material is genuine, and its own.
COO Matthew McNeff filed a copyright takedown of BAM’s own operations manual. Covered hereBarely worked, and backfired worse. The front page went dark, but the manual’s pages stayed online. And to file the notice he swore under penalty of perjury that the manual was genuine, handing critics the one thing they needed established.
Corporate removed more than ten owners from Slack and sent each a letter of alleged violations.The owners kept talking to reporters. The workspace went quiet; the reporting did not.
Corporate put a bot inside Slack, which owners believe is there to find leakers.Information still gets out. Some powers owners fear are unverified, and one is checked below.
Owners were led to fear their screens are watermarked, and stopped screenshotting.No such Slack feature exists (fact check below). The fear polices the owners; the tool does not.
Echo Base Network, August 16, 2026
Watch · Echo Base Network · August 16, 2026
“BAM Owners Told Us Bricks & Minifigs Corporate Is Near the END”
Coach and Nick, relaying multiple current franchise owners · YouTube

CORROBORATED That BAM’s internal channels have gone quiet, and that owners are wary of speaking, tracks what this site has documented from the owners’ own words: the morale thread where they tell each other “hope is not a legitimate business strategy.”

AS REPORTED The bans, the letters, and a corporate bot inside the workspace are what current owners are telling Echo Base Network. The powers owners attribute to that bot, that it can ban, watermark screens, and trace screenshots to a store, are allegations relayed by owners; Echo Base Network says it has not verified them. One of those allegations can be checked, and is, below.

The leak that was never a person CONFIRMED

While corporate hunted for the owner who was talking, BAM’s own public systems were quietly doing far more damage than any owner could. Through a feature BAM left exposed, with no login and no membership in anything, those systems handed out a working key to the inside of BAM’s Slack, a separate one for each of the six regions BAM runs its stores under, exposed across 124 stores. There is no mole in this. Nothing was carried out by a person. It was BAM’s own infrastructure, serving the keys to anyone who looked.Source: The BAM Map’s own review of BAM’s public-facing systems. The records are preserved; nothing here is published that a reader could misuse. This is the same method behind what BAM’s privacy policy promises versus what its own settings show and the children’s-privacy exposure.

A key, not a screenshot

This is a different kind of exposure than a leaked screenshot, and for a company in BAM’s position, a worse one. A screenshot is one moment that already happened, pointing outward. A key is standing access, pointing in. It asks for no account, no invitation, and no password, because there is nothing to log in to and no one to ask; whoever holds it simply holds it. Owners are being made afraid of the wrong thing. What a key like this opens, and how far inside it reaches, this site is not going to draw a map of for BAM.

Fixing what BAM left open is not optional housekeeping. It is the job of the officers BAM pays to run its technology, and once a company is on notice of a hole this size, leaving it open stops being an IT problem and becomes a governance one. Officers who know of a serious security hole in their own systems and leave it unrepaired can face claims for breach of fiduciary duty. After today, no one responsible for BAM’s systems can say they did not know.

Six regions, one workspace, the whole chain
RegionStoresKey
West Coast32held
Southern States28held
Great Lakes22held
Rocky Mountain Corridor20held
East Coast18held
Corporate4held
Six regions, one workspace1246 distinct

The sixth region is not a figure of speech. BAM’s own systems label it Corporate, and it was exposed exactly like the other five. Among the handful of stores grouped under it is Orem, Utah, in the state where BAM is based. The room with corporate’s name on it stood as open as the rest.

Fact check: can BAM watermark a franchisee’s screen? FALSE

Owners are afraid to screenshot because they believe corporate can invisibly watermark each person’s screen and trace a leaked image back to them. Checked against how the tools actually work: Slack has no feature that does this. Slack does not stamp each user’s view with a hidden, personal marker. Per-user screen watermarking exists only as separate software installed on the viewer’s own computer, sold by outside vendors for locked-down corporate machines. For that to trace a franchise owner, BAM would need its monitoring software running on that owner’s personal computer, a machine BAM does not own and cannot quietly reach.How the technology works: EchoMark and other vendors describe per-user screen watermarking as software installed on the machine being watched, not a capability inside Slack.

Which leaves two possibilities, and both cut against BAM. Either the watermark is a scare with nothing behind it, and owners are policing themselves over a power that does not exist. Or corporate is quietly leaning on the oldest trick instead: feeding different people different details to see whose version comes back, which needs no technology at all, only distrust. Either way, the fear is doing work the tool cannot. That is not forensics. That is a company teaching its own owners to be afraid of each other.

The door they built

So set the two halves side by side. On one side, everything BAM has tried: the takedown, the flagged stream, the lawyers, the bans, the bot, the fear. Loud, effortful, escalating, and aimed at people. On the other side, the leak that made all of it beside the point, which was never a person at all, but a set of keys BAM’s own public systems left out for anyone. You can ban every owner in the workspace and it changes nothing about that. You can watermark a screen that isn’t there to watermark. The mole corporate is hunting is not the hole in the boat.

And here is the thought neither Ammon nor Matt McNeff can answer, the one behind every ban and every letter: they do not know what already went out while the door stood open, or who still holds a key. That is not a threat. It is just the shape of what BAM built.

What this site did, and did not, do

The BAM Map found this the way it finds everything public that it publishes: by reading what was left openly available on the internet. It did not, through the openings BAM left, post into, read, or otherwise handle anything BAM intended to keep private. It is not publishing the keys, and it is not drawing a map of what they reach. Skeptics are welcome to ask for proof. This site holds the records, and it will hand them to a regulator or a court before it hands them to the company that left them lying out.

The fair reading, kept straight. Nothing here alleges a data breach, and none is claimed: this is about what BAM left open, not about anyone who walked through it. The owners’ accounts of bans, a bot, and a company running out of money are theirs, relayed by Echo Base Network and labeled as such; this site vouches only for what it documented itself, and what it documented is the open door.
Sources. The BAM Map’s review of BAM’s public-facing systems (records preserved; keys withheld) · Echo Base Network, “BAM Owners Told Us Bricks & Minifigs Corporate Is Near the END” (Aug. 16, 2026) · BAM’s efforts, each covered here: the operations-manual takedown and the sworn oath it left behind, the stream flagged mid-broadcast, the cease and desist, the content-removal order coming off · The same method, earlier: the privacy policy versus BAM’s own settings, the children’s-privacy exposure · Owner morale in their own words: “hope is not a legitimate business strategy.” · How per-user screen watermarking actually works: EchoMark · Where this site’s positions live: the machine and the store.
← NewerAll updatesOlder →

The BAM Map is independent reporting on matters of public concern. Nothing here is a finding of any person’s guilt; the civil allegations described are unadjudicated, and every defendant is presumed innocent. Sources are linked so readers can check the record.  ·  Home · Map · The law · Bodycam