Ransomware victim disclosure
← All victimsCiraNet
listed as CiraNet / CiraBooks · Claimed by Rhysida · listed 1 hour ago
Status timeline
- ListedSep 30, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Sep 30, 2026
- Data size
- 1.84 TB
- Records
- 2,478,837 files
About the victim
AI dossier — public-source company profileCiraNet is a software provider serving hundreds of American homeowners' associations (HOAs) and property management firms. The company operates database systems (RM_Warehouse, RM_Sales, RM_Portals, CiraBooks_GL) that store financial records, tenant/homeowner data, and banking information for HOA clients across the United States.
- Industry
- Property Management / HOA Services Software
Attack summary
Severity: critical — Confirmed exfiltration of regulated personal and financial data at massive scale: SSNs, tax identification numbers, banking credentials (ACH routing/account numbers), mortgage documents, and assessment/bankruptcy records affecting thousands of homeowners. Data includes PII, financial account identifiers, and tax records — all subject to strict privacy/financial regulations.Rhysida claims to have exfiltrated 2.478.837 files totalling 1.84 TB from CiraNet's systems. The data includes tax records (W-9s, 1099 forms), homeowners' banking credentials (ACH files, routing numbers, account details), personal financial documents (HUD-1 settlements), and complete SQL Server databases containing portal accounts and general ledger records for hundreds of HOAs and thousands of homeowners.
Data the group says was taken
AI dossier — extracted from the leak post- W-9 forms with SSNs and signatures
- IRS 1099-MISC/NEC e-file transmissions (2014–2025)
- ACH debit files with routing and account numbers
- Brokerage statements (USAA)
- Signed bank signature cards
- HOA assessment records and bankruptcy notices
- HUD-1 home purchase settlements
- HOA election ballots with voter names
- SQL Server databases (RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity, CiraBooks_GL)
- Mail and document archives (CiraMail, CiraDocs, SalesDocs)
- Portal account credentials
What the group claims
HOA management company with data covering hundreds of American HOAs and thousands of homeowners, including tax, banking, and debt information. Full SQL Server databases, mail and document flow systems, and extensive personal financial data.
The leak post
captured from the group's site2.478.837 files1.84 TBThe tax, banking and debt secrets of hundreds of American HOAs and thousands of homeowners - complete with SSNs, account numbers and signatures.Genuine W-9 forms with Social Security numbers, addresses and signatures; IRS 1099-MISC/NEC e-file transmissions for 2014�2025 - thousands of vendor TINs/SSNsHomeowners' banking keys: ACH debit files with routing and account numbers, USAA brokerage statements, signed bank signature cardsPeople's debts by name: assessments through September 2026, bankruptcies, late-fee waivers, hardship letters from debtors begging for payment plansPersonal documents: HUD-1 home purchase settlements (names, prices, mortgages), signed waivers with addresses, HOA election ballots with voter namesFull SQL Server databases: RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity (portal accounts), CiraBooks_GL (general ledger)Mail and document flow: CiraMail$, CiraDocs$, SalesDocs$ With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Contents. A complete dossier of the firm's…
Data the group says was taken
- SSNs
- bank account numbers
- routing numbers
- ACH debit files
- W-9 forms
- IRS 1099-MISC/NEC filings
- TINs
- brokerage statements
- bank signature cards
- HUD-1 settlement documents
- HOA election ballots
- bankruptcy records
- SQL databases
- general ledger data
- portal accounts
Screenshot of the leak post

Sources
Source
Indexed 1 hour agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

