Ransomware victim disclosure
← All victimsReviso Cloud Accounting Limited
Claimed by Direwolf · listed 6 hours ago
Status timeline
- ListedAug 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- Denmark
- Sector
- Financial Services
- Listed on leak site
- Aug 21, 2026
About the victim
AI dossier — public-source company profileReviso is a cloud-based accounting and invoicing software platform designed for small and medium-sized businesses (SMEs). The platform provides tools for bookkeeping, invoicing, financial reporting, VAT management, bank reconciliation, inventory control, and project management. It serves self-employed professionals, small companies, and accounting practices across multiple regions.
- Industry
- Financial Technology & Accounting Software
Attack summary
Severity: medium — Disclosure status is 'data_published' with no data size specified and no proof files advertised. The breach affects a financial software provider serving SMEs, meaning customer data (invoices, accounting records, potentially PII of business owners and employees) could be exposed; however, without confirmation of exfiltration scope or nature, and given the absence of proof artifacts, severity is rated medium rather than high.The direwolf group claims to have breached Reviso Cloud Accounting Limited. The leak post does not specify whether data was encrypted, exfiltrated, or both, nor does it detail what categories of data are at stake.
Original description
AI-summarised, not from the leak postReviso Cloud Accounting Limited is a software company that provides cloud-based accounting solutions primarily targeting small and medium-sized businesses. The platform offers tools for bookkeeping, invoicing, financial reporting, and VAT management. The company operates within the financial technology and accounting software industry and is based in the United Kingdom, serving businesses seeking accessible and scalable online accounting services.
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

