Ransomware victim disclosure
← All victimsAMS Group
listed as GROUPAMS.CO.UK · Claimed by Cl0p · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Cl0p
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileAMS Group (trading name of AMS Accountants Group Ltd, registered in England and Wales, Company No: 11977633) is a mid-market professional services firm headquartered in Manchester, UK, with 10 offices. The firm provides audit & accounts, tax, and advisory services, reporting 36% year-on-year revenue growth and 98% client satisfaction.
- Industry
- Accounting & Professional Services
- Address
- 1 Hardman Street, Spinningfields, Manchester, M3 3HF, United Kingdom
- Employees
- 210
Attack summary
Severity: high — AMS Group is an accounting and professional services firm handling sensitive client financial, tax, and audit data. Cl0p has marked the status as 'data_published', indicating exfiltration and publication of potentially regulated financial and business data, warranting a high severity rating despite the absence of detailed proof in the truncated post.Cl0p has listed AMS Group as a victim with a disclosed status of 'data_published', claiming data exfiltration; however, the leak post contains no substantive detail, proof files, or description of the specific data compromised.
Data the group says was taken
AI dossier — extracted from the leak post- Client financial records
- Tax documentation
- Audit files
- Employee data
- Business advisory records
Original description
AI-summarised, not from the leak postN/A
Sources
- Victim siteGROUPAMS.CO.UK
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

