Skip to content
Ransomware News

Ransomware Group rhysida Hits: NEAD Pro

Admin
HookPhish team

Summary

In the latest cybersecurity news, NEAD Pro — an organization based in US — has fallen victim to a ransomware attack conducted by the group rhysida. This data breach, discovered on 2026-09-24T18:01:29.579614+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization NEAD Pro
Threat Group rhysida
Summary NEAD Pro Nead Pro is a professional multidisciplinary firm based in Gorizia and Udine, Italy, that provides legal, tax, bankruptcy, and accounting consulting services.What it is: a network share belonging to two Italian professional firms located at Via Roma 20, Gorizia (Friuli-Venezia Giulia):NEAD SRL (NORTH EAST ADVISORS S.R.L.) – an accounting firm, dottore commercialista, P.IVA 01114220310, REA GO-72906;NEAD PRO – PROFESSIONISTI RIUNITI – a law firm, P.IVA 01157140318.Volume: ~575,000 files / ~253 GB. The root contains a single branch Nuova directoryNEAD (plus an empty Documenti folder and a scatter of PDF scans at the root level).Structure and contents:Branch Volume ContentsNEAD PRO SITE – Documenti 231,137 files / 193.5 GB Law firm: 03.PRATICHE (46,620 files: CIVILE 9,665, PENALE 537, SOVRAINDEBITAMENTO 1,208), 04. INCARICHI (85,321: FALLIMENTI 22,492, ESECUZIONI 28,509, ADS 14,547, TRUST, CURATELE), SEGRETERIA with CREDENZIALI VARIE.xlsx (~40 firm accounts: SPID, PEC, banks, 2 cards with full PAN+CVC, safe code), bank scans (BANCOMAT PIN, BCC agreements)NEAD SRL SITE – Documenti 101,125 / 55.3 GB Accounting firm: 03.CLIENTI – 199 active + 184 former client folders (730, CU, F24, contracts), 44 private SOGEI Entratel .P12 keys (signing clients’ tax returns), ISA/IRAP tax filings 2019�2020, client master data, Account.xlsxPRIMA NOTA – Documenti 1,885 / 871 MB Cash books 2019�2026 (21 xlsx): CASSA / CONTO CORRENTE / POS / CARTA / SISTERPOWERBI – Documenti 548 / 627 MB 37 financial BI models .pbix (BI_ISIDE, BI_NEAD, ATHENA, PNAI)ARCHIVIO 921 / 2.6 GB MPS bank statements 2020�2024, NEAD SRL account closure, firm mail archivePOSTA SARDAMAR / PANEGIOCHI / ISIDE / ADMIN SRL ~165+ / ~174 MB Client and firm mail: IVECO Capital leasing, accertamento Agenzia Entrate, Capitaneria di Porto, verbali poliziaES. IMM. 112-2024 10 files Real-estate enforcement proceedings (Tribunale di Gorizia): bank statements and CIE (ID cards) of auction participantsNEAD root ~85 PDF / 127 MB Scanned bank statements, F24 forms, IPZS envelope with the PIN/PUK of a CIE cardMost sensitive data: client dossiers with tax codes (codici fiscali), court case files (civil/criminal/bankruptcy), medical documents (Art. 9 GDPR), the firm’s credential database with full PAN+CVC of two cards and the safe code, 52 Entratel electronic signature keys, ~100 SEPA mandates with IBANs and signatures, client PST archives (7.5 GB), a client’s Huawei phone backup (Facebook/Gmail/Telegram databases), passports of foreign shareholders. More
Date of Breach 2026-09-24T18:01:13.290204+00:00
Discovery Date 2026-09-24T18:01:29.579614+00:00
Business Sector Not Found

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions