Ransomware victim disclosure
← All victimsButler, Lavanceau & Sober
Claimed by Snatch · listed 2 years ago
Status timeline
- ListedMar 18, 2024
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Financial
- Listed on leak site
- Mar 18, 2024
About the victim
AI dossier — public-source company profileButler, Lavanceau & Sober, LLC is a certified public accounting firm established in 1997 and based in Columbia, Maryland. They provide tax preparation, accounting, and business consulting services to small businesses and individuals across the mid-Atlantic region, with over 200 years of combined expertise among their accountants.
- Industry
- Accounting & Tax Services
- Address
- 10450 Shaker Drive, Suite 112, Columbia, MD 21046
- Founded
- 1997
Attack summary
Severity: high — A CPA firm handles sensitive client financial and tax records (likely including PII, income statements, and business financial data). Confirmed data publication by ransomware group indicates exfiltration of regulated/sensitive information affecting multiple clients, even without specific proof counts or data inventory details disclosed in this excerpt.Snatch claims to have attacked Butler, Lavanceau & Sober and published data from the breach. The group's post does not specify whether data was exfiltrated, encrypted, or both, nor does it detail what categories of data are at stake.
What the group claims
Butler, Lavanceau & Sober, LLC is a certified public accounting firm centrally located in Columbia, Maryland. Our seasoned accountants have over 200 years of combined expertise and are ready to meet your individual and business accounting, tax, and consulting needs.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

