Ransomware victim disclosure
← All victimsMichael Larson & Co., P.C.
listed as Michael L Larson · Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Feb 13, 2026
About the victim
AI dossier — public-source company profileMichael Larson & Co., P.C. (MLL Co) is a tax and client advisory firm based in the greater Portland, Oregon area. The firm provides services to businesses operating locally, nationally, and globally. It handles sensitive financial and personal data on behalf of its business and individual clients.
- Industry
- Tax & Business Advisory Services
- Address
- Portland, Oregon, United States
Attack summary
Severity: critical — The threat actor claims exfiltration of regulated PII at scale including passports, driver's licenses, and medical information belonging to both employees and customers, alongside sensitive financial records from a professional tax advisory firm — constituting a multi-category regulated data breach.Akira claims to have exfiltrated company data including financial records, employee and customer personally identifiable information (passports, driver's licenses, medical information), invoices, audit documents, and personal files, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Audit documents
- Payment details
- Financial reports
- Invoices
- Employee passports
- Customer passports
- Medical information
- Driver's licenses
- Personal files
- Customer data
What the group claims
Michael Larson & Co., P.C. (MLL Co) specializes in providing tax and client advisory services to businesses operating globally, na tionally, and within the greater Portland area. We are going to upload company data soon. You will find financial data (audit, payment details,financial reports, invoices), emplo yees and customers information (passports, medical information, d river's license ) A bit of personal files and customers data.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

