Ransomware Group rhysida Hits: NEAD Pro
Summary
In the latest cybersecurity news, NEAD Pro — an organization based in US — has fallen victim to a ransomware attack conducted by the group rhysida. This data breach, discovered on 2026-09-24T18:01:29.579614+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | NEAD Pro |
| Threat Group | rhysida |
| Summary | NEAD Pro Nead Pro is a professional multidisciplinary firm based in Gorizia and Udine, Italy, that provides legal, tax, bankruptcy, and accounting consulting services.What it is: a network share belonging to two Italian professional firms located at Via Roma 20, Gorizia (Friuli-Venezia Giulia):NEAD SRL (NORTH EAST ADVISORS S.R.L.) – an accounting firm, dottore commercialista, P.IVA 01114220310, REA GO-72906;NEAD PRO – PROFESSIONISTI RIUNITI – a law firm, P.IVA 01157140318.Volume: ~575,000 files / ~253 GB. The root contains a single branch Nuova directoryNEAD (plus an empty Documenti folder and a scatter of PDF scans at the root level).Structure and contents:Branch Volume ContentsNEAD PRO SITE – Documenti 231,137 files / 193.5 GB Law firm: 03.PRATICHE (46,620 files: CIVILE 9,665, PENALE 537, SOVRAINDEBITAMENTO 1,208), 04. INCARICHI (85,321: FALLIMENTI 22,492, ESECUZIONI 28,509, ADS 14,547, TRUST, CURATELE), SEGRETERIA with CREDENZIALI VARIE.xlsx (~40 firm accounts: SPID, PEC, banks, 2 cards with full PAN+CVC, safe code), bank scans (BANCOMAT PIN, BCC agreements)NEAD SRL SITE – Documenti 101,125 / 55.3 GB Accounting firm: 03.CLIENTI – 199 active + 184 former client folders (730, CU, F24, contracts), 44 private SOGEI Entratel .P12 keys (signing clients’ tax returns), ISA/IRAP tax filings 2019�2020, client master data, Account.xlsxPRIMA NOTA – Documenti 1,885 / 871 MB Cash books 2019�2026 (21 xlsx): CASSA / CONTO CORRENTE / POS / CARTA / SISTERPOWERBI – Documenti 548 / 627 MB 37 financial BI models .pbix (BI_ISIDE, BI_NEAD, ATHENA, PNAI)ARCHIVIO 921 / 2.6 GB MPS bank statements 2020�2024, NEAD SRL account closure, firm mail archivePOSTA SARDAMAR / PANEGIOCHI / ISIDE / ADMIN SRL ~165+ / ~174 MB Client and firm mail: IVECO Capital leasing, accertamento Agenzia Entrate, Capitaneria di Porto, verbali poliziaES. IMM. 112-2024 10 files Real-estate enforcement proceedings (Tribunale di Gorizia): bank statements and CIE (ID cards) of auction participantsNEAD root ~85 PDF / 127 MB Scanned bank statements, F24 forms, IPZS envelope with the PIN/PUK of a CIE cardMost sensitive data: client dossiers with tax codes (codici fiscali), court case files (civil/criminal/bankruptcy), medical documents (Art. 9 GDPR), the firm’s credential database with full PAN+CVC of two cards and the safe code, 52 Entratel electronic signature keys, ~100 SEPA mandates with IBANs and signatures, client PST archives (7.5 GB), a client’s Huawei phone backup (Facebook/Gmail/Telegram databases), passports of foreign shareholders. More |
| Date of Breach | 2026-09-24T18:01:13.290204+00:00 |
| Discovery Date | 2026-09-24T18:01:29.579614+00:00 |
| Business Sector | Not Found |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- security awareness training — close the gap attackers exploit.
- dark web monitoring — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
