Ransomware victim disclosure
← All victimsBernath & Rosenberg
Claimed by Genesis · listed 1 day ago
Status timeline
- ListedSep 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Genesis
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Sep 14, 2026
About the victim
AI dossier — public-source company profileBernath & Rosenberg is an accounting firm offering a full range of accounting, tax, and financial services to business clients. No further public details are available.
- Industry
- Accounting & Tax Services
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive regulated data at scale: client financial records, tax data, payroll information for multiple companies, and contractual documents. This represents material PII and financial data exposure affecting multiple third parties.The group claims to have exfiltrated 4.5 TB of data from the company's file servers, including accounting records, financial and tax data belonging to the firm's clients, payroll information, contracts, NDAs, and internal management folders.
Data the group says was taken
AI dossier — extracted from the leak post- Accounting data
- Financial and tax records (client)
- Payroll data (multiple companies)
- Contracts and NDAs
- Property management data
- Network user folders
- Management folders
What the group claims
A full service CPA firm
The leak post
captured from the group's siteAn accounting firm that provides a full range of services. ``` - 4.5 Tb of accessible data. - Accounting Data. - Financial and Tax Data of Company Clients. - Payroll Data of Various companies - Contracts and Non-disclosure Agreements. - Property Management Data. - Network users folders. - Management folders. - Data exfiltrated from company file servers. ```
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

