Ransomware victim disclosure
← All victimsESO Partners CPA
listed as esopartnerscpa · Claimed by ZaWoo · listed 21 hours ago
Status timeline
- ListedAug 30, 2026
- Data leakeddate unknown
At a glance
- Group
- ZaWoo
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 30, 2026
About the victim
AI dossier — public-source company profileESO Partners CPA is a certified public accounting firm providing professional accounting and tax services. No public website or detailed company information is available in open sources.
- Industry
- Accounting & Tax Services
Attack summary
Severity: medium — Confirmed data publication by the group, but no proof files, file count, or specific sensitive data types (e.g., PII at scale, SSNs, financial account details) are visible in the leak post. The lack of detail and proof artifacts prevents a higher severity rating; however, a CPA firm typically handles regulated tax and financial client information, which elevates it above 'low'.ZaWoo claims to have compromised ESO Partners CPA and published data. The leak post provides minimal detail on the scope of exfiltration or encryption; the group's message only references a login-gated file directory with no explicit description of what data was stolen or systems affected.
Data the group says was taken
AI dossier — extracted from the leak post- accounting records
- client files
- tax documents
What the group claims
[Unpublished]
The leak post
captured from the group's sitePlease login to view files. After login, the directory tree will be loaded. Click to start, or Cancel to abort.
Sources
Source
Indexed 21 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

