Ransomware victim disclosure
← All victimsTown & Forest
listed as townandforest.co.uk · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedJul 19, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Business Services
- Listed on leak site
- Jul 19, 2024
About the victim
AI dossier — public-source company profileTown & Forest is a firm of Chartered Accountants and Statutory Auditors based in St Albans, UK, with an additional office in Ferndown. They provide statutory audit, financial statement preparation, and taxation services to small businesses, individuals, and corporations across the UK.
- Industry
- Accounting & Statutory Audit Services
- Address
- St Albans, United Kingdom (also office in Ferndown)
Attack summary
Severity: high — Exfiltration of client case files and financial records from an accounting firm exposes sensitive client financial and business data, as well as potentially regulated information subject to professional privilege and data protection laws.LockBit 3 claims to have exfiltrated client case files and related business data. The leak post references 'ALL CLIENT CASES' but provides minimal specific detail about the scope or nature of data taken.
Data the group says was taken
AI dossier — extracted from the leak post- client case files
- financial records
- audit documentation
- client personal/business information
What the group claims
ALL CLIENT CASES We are a dedicated team of experts who are passionate about providing the best possible service to our clients. With a diverse range of skills and expertise, we are dedicated to delivering high quality results and ensuring client...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

