VORANT. Threat Intelligence Sign in Create a free account

Rhysida claims breach of Italian firm NEAD Pro

elevated threat financial-services

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Ransomware group Rhysida lists Italian legal/accounting firm NEAD Pro as a victim, claiming theft of ~575,000 files (253GB) including client tax, bank, and legal records.

Ransomware.live has indexed a listing from the Rhysida ransomware group naming NEAD Pro, a multidisciplinary professional firm (accounting and law practices NEAD SRL and NEAD PRO) based in Gorizia/Udine, Italy, as a victim. The claimed leak comprises roughly 575,000 files totaling about 253GB, covering the shared network drive of both entities: civil, criminal, and bankruptcy case files, tax filings (ISA/IRAP, 730, F24), client master data, 44-52 Entratel .P12 electronic signature keys used to sign clients' tax returns, and a firm credential spreadsheet containing SPID/PEC/bank logins plus full PAN and CVC for two payment cards and a safe code.

Additional exposed material reportedly includes bank statements (2020-2024), SEPA mandates with IBANs and signatures, scanned bank cards and PINs, a client's full phone backup (Facebook/Gmail/Telegram data), passports of foreign shareholders, and documents relating to a real-estate enforcement proceeding including auction participants' ID cards. Some records may fall under GDPR Article 9 special category data (medical documents). No technical intrusion details, exploited vulnerability, or malware artifacts are described in this listing.

For defenders, this is a data-exposure/extortion notice rather than a technical advisory: no IOCs, CVEs, or TTP chain are disclosed. Organizations using similar shared-drive structures for storing signing keys, client credentials, and financial data should review access controls, rotate any exposed credentials/keys, and consider this a reminder to encrypt or restrict PAN/CVC and digital signature key storage. Clients and counterparties named in the leak (banks, leasing firms, tax agency, court) may face secondary fraud/phishing risk.

Mentioned in this report

Threat actors rhysida
Malware Rhysida

Source reporting: https://www.ransomware.live/id/TkVBRCBQcm9Acmh5c2lkYQ==

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,806 reports from 152 sources, 1,531 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs