Ransomware victim disclosure
← All victimsUnknown HOA Management Company
Claimed by Rhysida · listed 3 hours ago
Status timeline
- ListedOct 5, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Oct 5, 2026
- Data size
- 1.84 TB
- Records
- 2478837
About the victim
AI dossier — public-source company profileAn unidentified homeowners association management company operating in the United States, managing financial, legal, and administrative functions for multiple HOAs and their residents.
- Industry
- Real Estate/HOA Management
Attack summary
Severity: critical — Confirmed exfiltration of highly regulated PII at massive scale: Social Security numbers, banking credentials (ACH files, account numbers), IRS forms, mortgage settlement documents, and personal financial data on thousands of individuals. This includes identity-theft vectors and regulatory violations under multiple privacy regimes.Rhysida claims to have exfiltrated approximately 1.84 TB of HOA management data including tax records, banking credentials, personal financial information, and databases from hundreds of American HOAs and thousands of homeowners. The group alleges access to Social Security numbers, ACH banking details, IRS forms, settlement documents, and complete SQL Server databases containing resident and financial records.
Data the group says was taken
AI dossier — extracted from the leak post- W-9 forms with Social Security numbers
- IRS 1099-MISC/NEC transmissions (2014–2025)
- ACH debit files with routing and account numbers
- USAA brokerage statements
- Signed bank signature cards
- HOA assessments and delinquency records
- Bankruptcy and hardship letters
- HUD-1 home purchase settlements
- HOA election ballots with voter names
- SQL Server databases (RM_Warehouse, RM_Sales, RM_Portals, CiraNet Identity, CiraBooks_GL)
- Email and document archives (CiraMail, CiraDocs, SalesDocs)
What the group claims
Company managing hundreds of American HOAs and thousands of homeowners, with databases including CiraNet, CiraBooks, CiraMail, CiraDocs.
The leak post
captured from the group's siteSKAFF is a leader in Lebanon in the field of decorative fabrics. Files: 139,377Data volume: ~268 GB**Full HR dossiers - ~40 scans of Lebanese national ID cards (both sides + photos), a director's passport, civil-status extracts.Banking data - employee account files at Byblos Bank (named per person), Cedrus Bank corporate card program with banker contacts, account statements.Payroll violations - unpaid-salary analysis file, payroll module source code, staff leave requests.Employees' private lives - family photo archives on the work server.Commerce � price lists, Four Seasons and Les Galeries proposals, customs/export documents (Dubai, Erbil), customer claims. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! Mat Bao Corporation offers a range of services including domain registration, cloud hosting, professional email solutions, and cloud server storage. Files: 746,108Data volume: 106.8 GBGovernment inspection materials - NEAC inspection decision No. 61/QD (29.04.2025) against the certification authority, worki…
Data the group says was taken
- W-9 forms
- SSNs
- IRS 1099-MISC/NEC filings
- ACH debit files
- bank account numbers
- brokerage statements
- HOA assessments
- bankruptcy records
- HUD-1 settlements
- SQL Server databases
- portal accounts
- general ledger
- mail and documents
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

