Ransomware victim disclosure
← All victimsCiraConnect
listed as CiraConnect/HOA Management · Claimed by Rhysida · listed 3 hours ago
Status timeline
- ListedOct 3, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Oct 3, 2026
- Data size
- 1.84 TB
- Records
- 2478837
About the victim
AI dossier — public-source company profileCiraConnect is a property management and HOA (Homeowners Association) financial services provider that manages accounting, billing, and administrative operations for homeowner associations and their residents across the United States.
- Industry
- Property Management & Financial Services
Attack summary
Severity: critical — Confirmed exfiltration of regulated financial and personal data at massive scale: SSNs, banking credentials (routing/account numbers), tax documents, mortgage information, and complete financial records of thousands of homeowners and hundreds of HOAs. This includes PII subject to various financial privacy regulations and exposes individuals to identity theft and financial fraud.Rhysida claims to have exfiltrated 1.84 TB of data from CiraConnect's systems, including complete HOA financial records, homeowner personal and banking information, tax documents, and internal databases containing sensitive personally identifiable information and financial data.
Data the group says was taken
AI dossier — extracted from the leak post- W-9 forms with Social Security numbers
- IRS 1099-MISC/NEC transmissions (2014–2025)
- ACH debit files with routing and account numbers
- USAA brokerage statements
- HUD-1 home purchase settlements
- HOA assessment records and bankruptcies
- SQL Server databases (RM_Warehouse, RM_Sales, RM_Portals, CiraNetIdentity, CiraBooks_GL)
- Homeowner names, addresses, and voter records
- Banking keys and signatures
What the group claims
Provider managing tax, banking and debt records for hundreds of American HOAs and thousands of homeowners, including SQL Server databases.
The leak post
captured from the group's siteMat Bao Corporation offers a range of services including domain registration, cloud hosting, professional email solutions, and cloud server storage. Files: 746,108Data volume: 106.8 GBGovernment inspection materials - NEAC inspection decision No. 61/QD (29.04.2025) against the certification authority, working minutes naming state inspectors and company staff (through December 2025).Corporate core - GPKD business-registration documents bearing the owner's signature, shareholder records, tax commitments (January 2026).Personal data - national ID cards (CCCD) and employee passports with signatures, staff lists.Regulator correspondence - VNNIC, NEAC, the Government Cipher Committee (including RSA-1024 token vulnerabilities).Litigation and operations - the VINASEED dispute, internal investigations, operations-department mail. With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! ElectroHeat industrial furnaces are used in manufacturing industries all over the world.Files: 1,723,527Data volume: 2,55 TBAll intellectual p…
Data the group says was taken
- W-9 forms
- SSNs
- IRS 1099 filings
- ACH debit files
- bank statements
- signed bank signature cards
- bankruptcy records
- HUD-1 settlements
- HOA election ballots
- SQL databases
- general ledger
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

