Ransomware victim disclosure
← All victimsBlossomland Accounting LLC
listed as Blossomland Accounting · Claimed by Akira · listed 4 hours ago
Status timeline
- ListedSep 16, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Sector
- Professional Services
- Listed on leak site
- Sep 16, 2026
About the victim
AI dossier — public-source company profileBlossomland Accounting LLC is an accounting firm based in Southwest Michigan that provides tax preparation, payroll services, and financial consulting to small and mid-sized businesses, emphasizing long-term client relationships and personalized service.
- Industry
- Accounting & Tax Services
- Address
- Southwest Michigan
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive regulated data at scale: employee PII including SSNs and identity documents, client financial/tax records, and credit card details. Accounting firms are custodians of sensitive financial and tax information subject to multiple regulatory frameworks.The Akira group claims to have exfiltrated approximately 12 GB of corporate data, including employee personal information (social security numbers, passports, driver's licenses, death certificates), client financial files, credit card details, contracts, and other confidential business records.
Data the group says was taken
AI dossier — extracted from the leak post- Employee SSN numbers
- Passports
- Driver's licenses
- Death certificates
- Client financial files
- Credit card details
- Contracts and agreements
- Corporate financial records
What the group claims
Blossomland Accounting LLC provides a range of accounting services including tax preparation an d planning, payroll services, and consulting in Southwest Michigan. The company focuses on deve loping long-term relationships with clients, offering personalized services tailored to their u nique financial needs. We will upload 12gb of corporate data soon. Employee personal information (SSN numbers, passpor ts, DLs, death certs), financials, confidential clients files, credit card details, projects, c ontracts and agreements and so on.
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

