Ransomware victim disclosure
← All victimsBlystone & Bailey, CPAs, PC
listed as Blystone & Bailey · Claimed by Incransom · listed 4 months ago
Status timeline
- ListedFeb 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Feb 3, 2026
About the victim
AI dossier — public-source company profileBlystone & Bailey, CPAs, PC is a Michigan-based certified public accounting firm providing audit, tax preparation and planning, payroll, bookkeeping, financial planning, and IT services management. The firm serves a broad range of industries including real estate, hospitality, oil and gas, construction, manufacturing, agriculture, franchising, and government and non-profit sectors.
- Industry
- Accounting & CPA Services
- Address
- Michigan, United States
Attack summary
Severity: critical — The attackers claim possession of the entire customer base along with financial documents, audits, and mail — constituting large-scale exfiltration of regulated financial and potentially PII-laden data belonging to clients across multiple industries, with data already published.The Incransom group claims to have exfiltrated the entire Blystone & Bailey customer base, including client email communications, financial documents, and audit records.
Data the group says was taken
AI dossier — extracted from the leak post- Client email communications
- Financial documents
- Audit records
- Customer database
- Payroll records
- Tax preparation files
What the group claims
Blystone & Bailey, CPAs, PC is a Michigan-based CPA firm offering a range of services including audit, tax preparation and planning, payroll, financial planning, bookkeeping, and IT services management. The firm caters to various industries such as real estate, hospitality, oil, gas and energy, professional services, construction, manufacturing, retail, agriculture, franchising, and government and non-profit sectors. We have the entire Blystone & Bailey customer base at our disposal. Mail, financial documents, audits and more.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

