Ransomware victim disclosure
← All victimsCiraConnect (HOA Management)
Claimed by Rhysida · listed 1 hour ago
Status timeline
- ListedSep 30, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Sep 30, 2026
- Data size
- 1.84 TB
- Records
- 2478837 files
About the victim
AI dossier — public-source company profileCiraConnect is a HOA (Homeowners Association) management company that provides financial, administrative, and portal services to hundreds of American HOAs. The company operates tax and banking systems, maintains homeowner records, and manages HOA accounting and communications platforms.
- Industry
- Property Management / Financial Services (HOA Management)
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at massive scale: SSNs, tax filings, banking credentials, and personal financial information affecting hundreds of HOAs and thousands of homeowners. Includes complete SQL databases and full document archives. This represents large-scale PII and financial data exposure with direct regulatory and identity-theft implications.Rhysida claims to have exfiltrated 1.84 TB of data containing 2.48 million files from CiraConnect's systems, including complete HOA tax records, banking information, homeowner personal documents, and full SQL Server databases. The breach exposes sensitive financial and personal data at scale across hundreds of HOAs and thousands of individual homeowners.
Data the group says was taken
AI dossier — extracted from the leak post- W-9 forms with SSNs
- IRS 1099-MISC/NEC filings (2014–2025)
- Vendor TINs and SSNs
- ACH debit files with routing and account numbers
- Brokerage statements (USAA)
- Bank signature cards
- HOA assessments and debt records
- Bankruptcy filings
- HUD-1 home purchase settlements
- HOA election ballots with voter names
- SQL Server databases (RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity, CiraBooks_GL)
- Email archives (CiraMail$)
- Document repositories (CiraDocs$, SalesDocs$)
What the group claims
Tax, banking and debt secrets of hundreds of American HOAs and thousands of homeowners, including SSNs, account numbers, signatures, W-9 forms, IRS 1099-MISC/NEC e-file transmissions, ACH debit files, SQL Server databases, and mail/document shares.
The leak post
captured from the group's site2.478.837 files1.84 TBThe tax, banking and debt secrets of hundreds of American HOAs and thousands of homeowners - complete with SSNs, account numbers and signatures.Genuine W-9 forms with Social Security numbers, addresses and signatures; IRS 1099-MISC/NEC e-file transmissions for 2014�2025 - thousands of vendor TINs/SSNsHomeowners' banking keys: ACH debit files with routing and account numbers, USAA brokerage statements, signed bank signature cardsPeople's debts by name: assessments through September 2026, bankruptcies, late-fee waivers, hardship letters from debtors begging for payment plansPersonal documents: HUD-1 home purchase settlements (names, prices, mortgages), signed waivers with addresses, HOA election ballots with voter namesFull SQL Server databases: RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity (portal accounts), CiraBooks_GL (general ledger)Mail and document flow: CiraMail$, CiraDocs$, SalesDocs$ With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Contents. A complete dossier of the firm's…
Data the group says was taken
- W-9 forms
- SSNs
- IRS 1099-MISC/NEC filings
- ACH debit files
- bank account numbers
- routing numbers
- brokerage statements
- signed bank signature cards
- assessment records
- bankruptcy records
- HUD-1 settlements
- HOA election ballots
- SQL databases
- portal accounts
- general ledger data
- mail archives
Screenshot of the leak post

Sources
Source
Indexed 1 hour agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

