Ransomware victim disclosure
← All victimsNEAD SRL (North East Advisors S.R.L.) / NEAD PRO - Professionisti Riuniti
listed as NEAD PRO / NEAD SRL (North East Advisors) · Claimed by Rhysida · listed 1 day ago
Status timeline
- ListedOct 1, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileNEAD is a multidisciplinary professional firm operating in Gorizia and Udine, Italy. It comprises two entities: NEAD SRL, a dottore commercialista (accounting/tax firm, P.IVA 01114220310), and NEAD PRO (law firm, P.IVA 01157140318). The firm provides legal, tax, bankruptcy, and accounting consulting services to hundreds of clients.
- Industry
- Legal & Accounting Professional Services
- Address
- Via Roma 20, Gorizia (Friuli-Venezia Giulia), Italy; also Udine, Italy
- Employees
- 40+
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at scale: complete client dossiers with tax codes and PII; criminal case files including undercover operations and minors; medical records (GDPR Art. 9); banking credentials; and financial/tax data for hundreds of clients. Breach of Italian professional confidentiality obligations and EU privacy law. High regulatory and reputational impact.Rhysida claims to have exfiltrated ~253 GB (575,000 files) from shared network storage belonging to both firms. The breach encompasses complete client dossiers, case files, tax returns, banking credentials, court filings, and sensitive personal data of hundreds of clients and third parties across civil, criminal, bankruptcy, and tax matters.
Data the group says was taken
AI dossier — extracted from the leak post- Law firm case files (civil, criminal, bankruptcy, debt restructuring)
- Client tax returns and filings (730, CU, F24 forms)
- Client tax codes (codici fiscali) and personal identification data
- Medical documents subject to GDPR Art. 9
- Banking credentials and account information
- Credit card PAN and CVC numbers
- Court-sealed criminal case details
- Client financial statements and account records
- Real-estate enforcement proceedings with ID card scans
- SOGEI Entratel .P12 keys for tax return signing
- Firm email archives and client correspondence
- Bank statements (MPS) 2020–2024
What the group claims
Multidisciplinary professional firm based in Gorizia and Udine, Italy, providing legal, tax, bankruptcy, and accounting consulting services. Includes law firm case files (civil/criminal/bankruptcy), accounting client dossiers, tax filings, credential databases with full PAN+CVC, Entratel electronic signature keys, SEPA mandates, client email archives, and sensitive personal data.
The leak post
captured from the group's siteWith more than 40 employees, the agency manages national and international online projects of companies from a wide range of industries. Based in Berlin, Dresden, Munich and Cologne, has been a specialist in online marketing for more than twelve years. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! [Law Offices of R. David Williams, P.A.](https://www.dwilliamslaw.com) Contents. A complete dossier of the firm's criminal defense practice covering ~175+ clients: felonies (an undercover sex sting involving a minor - Ramirez; domestic violence robbery - Valderrama, involving a 4-year-old child; felony DUI - Segula; fraud - B. Williams), a core caseload of ~10 DUI matters (including an arrest at breath readings of 0.011 and SCRAM alcohol monitoring), violations of probation (VOP), FDLE expungement packets with FD-258 fingerprint cards, a 'red flag' Risk Protection Order (RPO), 2 clients in ICE custody, and a material witness under GPS monitoring for 3+ years. Attorney fees range from $750 to $25,000. The case fil…
Data the group says was taken
- legal case files
- tax filings
- bankruptcy records
- client dossiers
- credential databases
- bank card PAN+CVC
- Entratel signing keys
- SEPA mandates with IBANs
- bank statements
- F24 forms
- passports
- medical documents
- phone backup
- financial BI models
- cash books
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

