Ransomware victim disclosure
← All victimsCrowe
Claimed by Coinbasecartel · listed 2 hours ago
Status timeline
- ListedAug 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Coinbasecartel
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 19, 2026
About the victim
AI dossier — public-source company profileCrowe is a public accounting, consulting, and technology firm headquartered in the United States. It provides audit, tax, advisory, risk, and performance services to clients across various industries including financial services, healthcare, and government, operating globally through Crowe Global, a network spanning over 140 countries.
- Industry
- Accounting, Consulting & Advisory Services
Attack summary
Severity: medium — Data published status indicates exfiltration occurred, but the leak post excerpt provides no inventory of data types, proof files, or operational impact details. Crowe's access to sensitive client financial and healthcare data elevates concern, but without proof details the severity cannot be confirmed as high.The coinbasecartel group claims to have attacked Crowe. No specific details are provided in the available leak post excerpt regarding what data was exfiltrated, encrypted, or the nature of the operational impact.
Original description
AI-summarised, not from the leak postCrowe is a public accounting, consulting, and technology firm headquartered in the United States. It provides audit, tax, advisory, risk, and performance services to clients across various industries, including financial services, healthcare, and government. Crowe operates globally through its membership in Crowe Global, a network of independent accounting and advisory firms spanning over 140 countries.
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

