💼 Professional & Business Services¶
Legal, accounting, consulting, staffing, marketing, real estate services · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed
Victims L30D8▼ −5
Prior 30D13
Active actor L90DQilin · 16
Active actor L90DINC Ransom · 5
Active actor L90DAkira · 4
Today — 12 Sep 2026¶
No industry-tagged items in today's briefing — see recent activity below.
Last 14 days¶
Recent victim claims¶
Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.
September 2026
Sep 07
Lightcast
Direwolf
US-based provider of human resources / labor-market analytics software; Direwolf DLS claim Sep 7, 2026; data scope and impact unconfirmed. 🟥 Unverified DLS claim; verify before treating as a breach. · Sources: https://www.redpacketsecurity.com/direwolf-ransomware-victim-lightcast/
Sep 04
Blanco & Etcheverry
Gunra
Uruguayan law firm (~$5M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/QmxhbmNvICYgRXRjaGV2ZXJyeUBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-blanco-etcheverry/
Sep 03
Complete Packaging Solutions
Qilin
Qilin DLS claim Sep 3 2026; UK business services and packaging solutions provider. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/qilin-ransomware-targets-complete-packaging-solutions/
Sep 03
Katten Muchin Rosenman
SilentRansomGroup
Am Law firm claimed by SilentRansomGroup; DLS Sep 3; full-service US law firm; data scope and authenticity unverified. · Sources: https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-katten-muchin-rosenman/
Sep 02
Greenberg Traurig
SilentRansomGroup
Am Law firm claimed by SilentRansomGroup; DLS Sep 2; data scope and authenticity unverified; threat to publish if no contact made. · Sources: https://www.dexpose.io/silentransomgroup-compromises-greenberg-traurig/
Sep 01
Holland & Knight
SilentRansomGroup
Am Law firm claimed by SilentRansomGroup; DLS Sep 1; data scope and authenticity unverified; threat to publish if no contact. · Sources: https://www.hookphish.com/blog/ransomware-group-silentransomgroup-hits-holland-and-knight/
August 2026
Aug 29
LAPoco Architects
Qilin
Qilin DLS claim Aug 29, 2026; architecture firm; scope and data volume unconfirmed · Sources: https://www.ransomware.live/summary/
Aug 23
Aurore Development S.p.A.
Qilin
Italian business services company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-targets-aurore-development-s-p-a-in-ransomware-attack/
Aug 10
ATMS & Co. LLP
INC Ransom
Chartered accountant firm; INC_RANSOM DLS posting August 10, 2026; part of INC's SonicWall SMA 1000 exploitation campaign (CVE-2026-15409/CVE-2026-15410 CVSS 10.0); data scope unconfirmed · Sources: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
Aug 09
Studio Associato Tibaldi
Unknown
DLS claim posted August 9 on ransomware.live; Italian professional firm based in Rome; group attribution not confirmed in available sources · Sources: https://www.ransomware.live/
Aug 08
Louisville Bar Association
INC Ransom
INC Ransom DLS claim August 8 2026; Kentucky-based legal professional association; consistent with INC Ransom sustained 2026 legal-sector campaign; no victim statement; data scope unconfirmed · Sources: https://www.ransomware.live/group/incransom
Aug 07
Morguard Corporation
Helix
Helix ransomware group (emerged July 2026; Microsoft OAuth/SharePoint data exfiltration, no custom malware) posted DLS claim Aug 7; 160GB claimed exfiltrated; negotiations broke down. Helix uses voice phishing and OAuth abuse targeting SharePoint. · Sources: https://ransomware.live/id/TW9yZ3VhcmRASGVsaXg=
Aug 06
Signature Services
Play
Play ransomware DLS listing, Aug 6 2026; files encrypted, data exfiltrated · Sources: https://ransomware.live/id/U2lnbmF0dXJlIFNlcnZpY2VzQHBsYXk=
Aug 02
Encore Enterprises
CRPxO
CRPxO DLS claim August 2 2026; US commercial real estate firm; attacker claims 700 GB exfiltrated. No victim statement; data not yet published. · Sources: https://www.ransomware.live/id/RW5jb3JlIEVudGVycHJpc2VzLCBJbmMuQENSUHhP
Aug 01
Questel SAS
ShinyHunters
ShinyHunters DLS posting August 1 2026 with August 4 contact deadline; claims 21M+ Salesforce records plus 147 GB internal corporate data; Questel is a major IP and patent management firm serving global enterprise clients; no statement from Questel; data not yet published · Sources: https://breachnews.com/breaches/shinyhunters-lists-questel-alcon-and-lumenis-on-leak-site-with-new-extortion-claims/ https://www.dexpose.io/shinyhunters-breach-questel-sas-french-ip-giant-under-siege/
July 2026
Jul 29
Accenture
888
Threat actor 888 (PwnForums) claimed theft of 35 GB including Azure DevOps source code, Azure access keys, tokens, RSA/SSH keys, and config files; Accenture confirmed incident was contained with no operational impact; disclosed approximately July 29 2026 · Sources: https://www.securityweek.com/accenture-confirms-data-breach-after-hacker-claims-source-code-theft/ https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
Jul 27
Ernst and Young
ShinyHunters
Supply-chain compromise of third-party IT service management platform Mar 28-Apr 12 2026; yielded credentials to EY Jira, GitHub, Azure; client tax documents with SSNs and financial data; July 31 2026 deadline issued · Sources: https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
Jul 25
Jubilee Jobs
Qilin
DLS posting July 25 2026 by Qilin. Employment/staffing services firm. Country and data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 25
The Myers Y Cooper
Qilin
DLS posting July 25 2026 by Qilin. Professional services firm; sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25
Health Law Advocates
INC Ransom
Boston non-profit legal organization; INC Ransom DLS posting July 26 2026, estimated attack date July 25; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://www.ransomware.live/
Jul 15
Ernst & Young (EY)
Unattributed
EY disclosed on July 15 that client data was accessed via a compromised third-party IT support platform used for UK client engagements; breach window estimated March-April 2026; exposed data includes client tax records, investment data, and Social Security Numbers for affected individuals; EY notified affected clients directly; investigation ongoing with external forensics; no ransomware group has claimed the breach; attack vector believed to be credential theft at the third-party vendor · Sources: https://www.bleepingcomputer.com/news/security/ey-discloses-data-breach-exposing-client-tax-and-financial-records/
Jul 13
Allied Plumbing Heating & Cooling
Qilin
HVAC/plumbing services company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 13
Access Group International
DragonForce
Business services company claimed on DragonForce DLS July 13; data type and volume unconfirmed · Sources: ransomware.live · purpleops.io
Jul 12
Century Equities
Qilin
Real estate company claimed on Qilin DLS; data type and volume unconfirmed · Sources: ransomware.live · breachsense.com
Jul 11
Alan F. Burke CPA
Qilin
Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10
The Schuett Companies
Qilin
Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10
Sintax
Qilin
Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 08
HIVE360
DragonForce
DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08
PCCC Realty LLC
NightSpire
NightSpire DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/nightspire · Sources: [ransomware.live]
Jul 08
Greenbotz
Everest
Everest DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/everest · Sources: [SharkStriker] · [ransomware.live]
Jul 07
Chisholm, Persson & Ball, PC
Akira
Akira DLS claim July 7, 2026; 45 GB claimed including client passports, visas, SSNs, court files, and police reports; data scope unconfirmed; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-akira-hits-chisholm-persson-and-ball/ · https://www.ransomware.live/group/akira · Sources: [HookPhish] · [ransomware.live]
Jul 06
Wood Ellis & Wood CPA
Qilin
Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-attack-on-wood-ellis-wood-cpa/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06
Max Fordham
Qilin
independent building engineering consultancy (MEP/sustainability; clients include museums, schools, housing); Qilin DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/qilin-ransomware-targets-max-fordham-in-uk-cyberattack/ · https://www.ransomware.live/group/qilin · Sources: [DeXpose] · [ransomware.live]
Jul 06
CSEC RATP
The Gentlemen
The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 02
Amtivo
SETTRA
ANAB-accredited ISO and management system certification body (formerly Orion, ASR, CMA, Audit3, QSR, ISA in North America); offers ISO 9001, 14001, 27001, 45001 certification and training; SETTRA DLS claim July 1–2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071991911431426416 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jul 02
X-Copper Professional Corporation
MoneyMessage
Canadian law firm specialising in traffic ticket defence, minor criminal charges, and licence-related legal matters; MoneyMessage DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.hendryadrian.com/ · Sources: [hendryadrian.com]
Jul 01
Dennis Waters Rental Properties
Qilin
residential rental property company; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Laughlin Nunnally Hood & Crum
Qilin
US law firm; Qilin DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01
Gies Dienstleistungen
LockBit
German facility management and building services company; LockBit 5.0 DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
CBAssociates
Icarus
Icarus DLS claim July 1, 2026; 🟥 unverified · https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data · Sources: [Dark Reading]
Jul 01
Orion Registrar Inc.
SETTRA
US-based management system certification registrar; SETTRA DLS claim June 30–July 1, 2026; claimed exposure of sensitive financial documents; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-targets-orion-registrar-inc/ · Sources: [DeXpose]
Jul 01
Dolrad
MedusaLocker
69 emails claimed exfiltrated; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-dolrad/ · https://ransomware.live/id/RG9scmFkQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]
June 2026
Jun 30
KALIACT ANCHETA et Associés
Qilin
French legal advisory firm; Qilin DLS June 30, 2026; data scope unconfirmed; 🟥 unverified · https://socradar.io/free-tools/ransomware-intelligence/victims/kaliact-ancheta-et-associs-67e467e9 · https://www.ransomware.live/id/S0FMSUFDVCBBTkNIRVRBIGV0IEFzc29jaXNAcWlsaW4 · Sources: [SOCRadar] · [ransomware.live]
Jun 30
Advanced Business Systems
Akira
regional office technology solutions and managed services provider; Akira DLS claim June 30, 2026; 31 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jun 30
Melcor Developments Ltd
The Gentlemen
diversified real estate developer and asset manager headquartered in Edmonton, Alberta; community development, commercial property, and residential construction across Western Canada; The Gentlemen DLS claim June 30, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-melcor-developments-ltd/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 30
Brooklyn Defender Services
Genesis
New York City public defender organization providing legal representation to low-income individuals; Genesis DLS claim June 30, 2026; estimated attack date June 23, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · https://www.redpacketsecurity.com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 30
Ilex Paysages et Urbanisme
SETTRA
distinguished French landscape architecture and urban planning firm; SETTRA DLS claim June 30, 2026; estimated attack date June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/settra-ransomware-attack-targets-ilex-paysages-et-urbanisme/ · https://www.redpacketsecurity.com/settra-ransomware-victim-ilex-paysages-com/ · https://www.ransomware.live/id/aWxleC1wYXlzYWdlcy5jb21Ac2V0dHJh · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 30
Cedrick Frank Associates
SETTRA
SETTRA DLS claim June 30, 2026; sector and data scope unconfirmed; 🟥 unverified · https://x.com/FalconFeedsio/status/2071950309254185226 · https://www.ransomware.live/group/settra · Sources: [FalconFeeds] · [ransomware.live]
Jun 26
callhorton.com
INC Ransom
personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26
johndufourlaw.com
INC Ransom
personal injury law firm; INC Ransom DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jun 26
Ingerman
Chaos
multifamily developer and property management company; Chaos DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/chaos-strikes-ingerman-in-ransomware-attack/ · https://www.redpacketsecurity.com/chaos-ransomware-victim-ingerman-com/ · Sources: [DeXpose] · [RedPacket Security]
Jun 26
Hokua Suites
AiLock
upscale resort-style ocean-view residential condominium on the Oahu coast; AiLock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ailock-ransomware-group-attacks-hokua-luxury-condominiums/ · https://www.redpacketsecurity.com/ailock-ransomware-victim-hokua/ · https://www.ransomware.live/id/SG9rdWFAQWlMb2Nr · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 25
JMS Southeast
Akira
temperature measurement and control products distributor (thermocouples, RTDs, thermowells, transmitters); Akira DLS claim June 25, 2026; ~25 GB claimed including employee PII (names/addresses), payment data, NDAs, project contracts, agreements with government entities, and customer information · https://www.redpacketsecurity.com/akira-ransomware-victim-jms-southeast/ · https://malware.news/t/akira-ransomware-attack-targets-jms-southeast/108233 · Sources: [RedPacket Security] · [malware.news]
Jun 25
BDS CZ
The Gentlemen
Czech real estate agency; DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.breachsense.com/breaches/ · https://www.ransomware.live/group/thegentlemen · Sources: [Breachsense] · [ransomware.live]
Jun 25
Delegal Poindexter & Underkofler, P.A.
Morpheus
employment law firm; Morpheus DLS claim June 25, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-morpheus-hits-delegal-poindexter-and-underkofler-p-a/ · https://www.dexpose.io/morpheus-ransomware-targets-delegal-poindexter-underkofler-p-a/ · Sources: [HookPhish] · [DeXpose]
Jun 22
Klue
Icarus
OAuth integration credential compromised June 11-12; malicious code pushed to harvest customer OAuth tokens; Salesforce integrations revoked June 12; CrowdStrike engaged for IR · https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [SecurityWeek] · [BleepingComputer]
Jun 21
JAG Group
Stormous
US-based business services company; corporate emails (@jaggroup.com), Active Directory domain logins with clear-text passwords, complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration data exfiltrated; full data dump published June 29, 2026 (new link posted after June 24 initial dump); estimated attack date June 20 · https://www.dexpose.io/stormous-ransomware-breach-exposes-jag-group-data/ · https://www.redpacketsecurity.com/stormous-ransomware-victim-jaggroup-com-update-full-data-dump/ · https://www.ransomware.live/id/amFnZ3JvdXAuY29tIFVQREFURS1GVUxMIERBVEEgRFVNUEBzdG9ybW91cw · Sources: [DeXpose] · [RedPacket Security] · [ransomware.live]
Jun 20
One Believing Interiors
Nova
interior design studio specializing in built spaces including National Gallery projects; DLS claim June 20, 2026; data scope and impact unconfirmed · https://www.hookphish.com/blog/ransomware-group-nova-hits-one-believing-interiors/ · https://www.ransomware.live/id/T25lIEJlbGlldmluZyBJbnRlcmlvcnNAbm92YQ== · Sources: [HookPhish] · [ransomware.live]
Jun 20
Preferred Properties
Payload
DLS claim June 20, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/payload-ransomware-victim-preferred-properties/ · Sources: [RedPacket Security]
Jun 19
ALS Global Limited
Aur0ra
ASX-listed global testing, inspection, and certification firm (est. 1863; ~70 countries; mining, environmental, food safety, life sciences, materials testing); attack May 2026 (disclosed June 11 via ASX filing); Aur0ra DLS claim June 19, 2026; data published dark web June 22; 500+ employees' home directories including cached credentials; hundreds of plaintext password files; passport scans; bank account details; payroll data; workplace injury records; client laboratory results and analytical data; ALS confirmed breach, engaged cybersecurity specialists, and notified ACSC and relevant regulators · https://www.cyberdaily.au/security/13794-exclusi · https://www.dexpose.io/aurora-ransomware-strikes-als-global/ · https://www.breachsense.com/breaches/als-global-data-breach/ · Sources: [Cyber Daily] · [DeXpose] · [Breachsense]