Ransomware Group rhysida Hits: Gress Clark Young and Schoepper
Summary
In the latest cybersecurity news, Gress Clark Young & Schoepper — an organization based in US — has fallen victim to a ransomware attack conducted by the group rhysida. This data breach, discovered on 2026-10-10T12:46:50.865750+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | Gress Clark Young & Schoepper |
| Threat Group | rhysida |
| Summary | Gress Clark Young & Schoepper 167,804 files / ~166.4 GBBanking details – of the firm and its clients.SSNs + signatures of clients/witnesses; W-9, I-9 forms with DL/SSN card copies; W-4 forms.BIIA case-management procedures (Board of Industrial Insurance Appeals): default orders (Order of Default), internal ‘Conference Questions’, consulting-fee payments to experts.Firm finances: the firm’s QuickBooks company file, VOID checks bearing signatures, expert-payment records, SaaS invoices.Medical photos and imaging; hundreds of pages of PHI/APF (Activity Prescription Forms) – X-rays, complete medical records.’Coaching’ letters to doctors – including a letter to the physician in the Jachacy matter with wording indicative of steering a medical opinion (‘coaching letter’) – a potential ethics violation regarding witness handling.Credentials/access to the SPC e-file system (court e-filing).Disciplinary action against partner Daniel W. Gress. More |
| Date of Breach | 2026-10-10T12:46:25.165608+00:00 |
| Discovery Date | 2026-10-10T12:46:50.865750+00:00 |
| Business Sector | Professional Services |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- phishing simulation — close the gap attackers exploit.
- security awareness training — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
