Ransomware victim disclosure
← All victimsTange , Mann & Garza
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Apr 1, 2026
About the victim
AI dossier — public-source company profileTange, Mann & Garza is a full-service accounting firm based in the United States. The firm provides a broad range of accounting and financial services to individuals, business owners, executives, and independent professionals. No additional public site information was available to further characterize the firm's scale or location.
- Industry
- Accounting & Tax Services
Attack summary
Severity: critical — The exfiltration includes regulated PII (government-issued IDs such as passports and driver's licenses) for employees, as well as sensitive client financial records and legal agreements from an accounting firm — constituting a large-scale exposure of both personal and financial regulated data.Akira claims to have exfiltrated approximately 40 GB of corporate data from Tange, Mann & Garza, including employee passports, driver's licenses, detailed client financial records, agreements, and NDAs, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driver's licenses
- Client financial records
- Client agreements
- Non-disclosure agreements (NDAs)
- Corporate data (general)
What the group claims
Tange , Mann & Garza is a full-service accounting firm offering a broad range of services for individuals, business owners, execut ives, and independent professionals. We will upload 40gb of corporate data soon. Employee passports DL and so on, detailed client information (financials, agreements a nd so on), NDA, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

