Ransomware victim disclosure
← All victimsA.R.Ge.Co
Claimed by anubis · listed 8 days ago
Status timeline
- Listed
May 13, 2026
- Data leaked
At a glance
- Group
- anubis
- Status
- Data leaked
- Country
- IT
- Sector
- Business Services
- Listed on leak site
- May 13, 2026
About the victim
AI dossier — public-source company profileA.R.Ge.Co is an Italian accounting firm operating in the business services sector. Based on the sector classification and the leak post description, the firm provides accounting and related professional services. No further details about scale or specific location are available from public sources.
- Industry
- Accounting & Business Services
Attack summary
Severity: high — An accounting firm breach with confirmed data publication strongly implies exposure of sensitive financial and client PII records; the 'data_published' status confirms exfiltration rather than encryption-only.The Anubis ransomware group claims to have breached A.R.Ge.Co, describing it as an accounting firm data breach; the disclosure status indicates data has been published, suggesting exfiltration of firm data.
Data the group says was taken
AI dossier — extracted from the leak post- Accounting firm data
What the group claims
Accounting firm data breach.
The leak post
captured from the group's siteAnubis blog ANUBIS NEWS FAQ ABOUT RULES English English Español Русский 中文 Deutsch Download A.R.Ge.Co The subject of today’s article is A.R.Ge.Co , a French company operating in the field of accounting services, serving a wide range of clients from artisans to small and medium-sized businesses. Its role is to bring order to other people’s numbers, and today we will take a look at whether its own numbers are in order. Within this dataset, you will find extensive financial and accounting information concerning both the company itself and its clients. This includes comparative accounting statements, balance sheet reports, information on clients’ pooled accounts, and much more.
Sources
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
