Ransomware victim disclosure
← All victimsJLK Rosenberger LLP
listed as JLK Rosenberger · Claimed by Incransom · listed 5 months ago
Status timeline
- ListedJan 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Jan 28, 2026
- Data size
- 300 GB
About the victim
AI dossier — public-source company profileJLK Rosenberger LLP is a full-service accounting and business advisory firm headquartered in California with offices in Irvine, Glendale, and Dallas, Texas. The firm is recognized as a Top 400 accounting firm by Inside Public Accounting and is one of the largest auditors of insurance entities in the United States, as ranked by Aon and AM Best.
- Industry
- Certified Public Accounting & Business Advisory
- Address
- Offices in Irvine, CA; Glendale, CA; and Dallas, TX, United States
Attack summary
Severity: critical — 300 GB of exfiltrated data from a large CPA firm includes client financial records and personal information at scale, which almost certainly contains regulated PII and sensitive financial data of both individuals and institutional clients (including insurance entities); data_published status and imminent publication threat compound the severity.Incransom claims to have exfiltrated 300 GB of data from JLK Rosenberger LLP, including internal mail, accounting records, and customer information, and has threatened to publish all data imminently.
Data the group says was taken
AI dossier — extracted from the leak post- Internal email communications
- Accounting records
- Customer/client information
What the group claims
JLK Rosenberger LLP, Certified Public Accountants: A full service accounting and business advisory firm with offices in Irvine and Glendale, California and Dallas, Texas. The firm is recognized as a Top 400 Firm by Inside Public Accounting and one of the largest auditors of insurance entities in the United States as ranked by Aon and AM Best We have 300GB of data. Internal mail, accounting, company customer information and we will publish all the information next week.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

