# Rhysida claims breach of Italian firm NEAD Pro

Published: 2026-09-24 · Severity: elevated · Sectors: financial-services
Canonical: https://vorant.io/reports/17c6b52f-6dc8-50d8-a975-6aea16932c3c/rhysida-claims-breach-of-italian-firm-nead-pro

> Ransomware group Rhysida lists Italian legal/accounting firm NEAD Pro as a victim, claiming theft of ~575,000 files (253GB) including client tax, bank, and legal records.

Ransomware.live has indexed a listing from the Rhysida ransomware group naming NEAD Pro, a multidisciplinary professional firm (accounting and law practices NEAD SRL and NEAD PRO) based in Gorizia/Udine, Italy, as a victim. The claimed leak comprises roughly 575,000 files totaling about 253GB, covering the shared network drive of both entities: civil, criminal, and bankruptcy case files, tax filings (ISA/IRAP, 730, F24), client master data, 44-52 Entratel .P12 electronic signature keys used to sign clients' tax returns, and a firm credential spreadsheet containing SPID/PEC/bank logins plus full PAN and CVC for two payment cards and a safe code.

Additional exposed material reportedly includes bank statements (2020-2024), SEPA mandates with IBANs and signatures, scanned bank cards and PINs, a client's full phone backup (Facebook/Gmail/Telegram data), passports of foreign shareholders, and documents relating to a real-estate enforcement proceeding including auction participants' ID cards. Some records may fall under GDPR Article 9 special category data (medical documents). No technical intrusion details, exploited vulnerability, or malware artifacts are described in this listing.

For defenders, this is a data-exposure/extortion notice rather than a technical advisory: no IOCs, CVEs, or TTP chain are disclosed. Organizations using similar shared-drive structures for storing signing keys, client credentials, and financial data should review access controls, rotate any exposed credentials/keys, and consider this a reminder to encrypt or restrict PAN/CVC and digital signature key storage. Clients and counterparties named in the leak (banks, leasing firms, tax agency, court) may face secondary fraud/phishing risk.

## Mentioned in this report

- Threat actors: rhysida
- Malware: Rhysida

Source reporting: https://www.ransomware.live/id/TkVBRCBQcm9Acmh5c2lkYQ==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/17c6b52f-6dc8-50d8-a975-6aea16932c3c/rhysida-claims-breach-of-italian-firm-nead-pro.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
