Ransomware victim disclosure
← All victimsCFGI
listed as CFGI Management (cfgi.com) · Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 9, 2026
- Records
- 800K records
About the victim
AI dossier — public-source company profileCFGI is a US-based accounting advisory and financial consulting firm serving CFOs, private equity clients, and organizations across multiple industries. The firm offers a broad range of services including technical accounting, financial reporting, valuation, tax, forensic accounting, transaction advisory, and restructuring. CFGI operates multiple offices worldwide and counts numerous global clients.
- Industry
- Accounting Advisory & Financial Consulting
- Address
- 1185 6th Ave, Midtown Manhattan, New York, NY (recently relocated office; additional offices worldwide)
Attack summary
Severity: critical — Over 800,000 records of PII have been confirmed exfiltrated and published by the threat actor. As an accounting and financial advisory firm, the data likely includes sensitive financial and personally identifiable information of clients and investors at significant scale, meeting the threshold for critical severity.ShinyHunters claims to have exfiltrated over 800,000 records containing PII and internal corporate data from CFGI, stating that the company declined to reach a ransom agreement. The data has been published as the disclosed status indicates.
Data the group says was taken
AI dossier — extracted from the leak post- Personally Identifiable Information (PII)
- Internal corporate data
- Client records
- Investor-related data
What the group claims
Over 800k records containing PII and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors. | Updated: 10 Mar 2026 | SHA256: 1dbf6b9a06960cc8c4043de9f94a2494845b96d07a8a14aab89099ced8baef0c
Sources
- Victim sitecfgi.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

