VORANT. Threat Intelligence Sign in Get the full feed

Ransomware.live lists Bernath & Rosenberg breach

routine threat

A ransomware.live listing shows law firm Bernath & Rosenberg compromised, with over 390 user accounts and third-party credentials exposed by a group tracked as 'genesis'.

This is a minimal victim-listing entry from ransomware.live, an aggregator that tracks claims and leak-site postings from ransomware operators. The entry references an organization identified as 'Bernath & Rosenberg' and attributes the listing to a group referenced as 'genesis' in the source identifier. The posting includes summary statistics: zero directly compromised employees, 394 compromised users, 188 third-party employee credentials, and 3 external attack surface findings, alongside a leak screenshot (not reproduced here).

No technical indicators, exploited vulnerabilities, malware samples, or intrusion details are provided in this source — it is a leak-site tracking summary rather than a technical intrusion report. Defenders associated with, or doing business with, an entity of this name should treat this as a signal to check for credential exposure (particularly third-party/vendor credentials) and review external attack surface exposure, but should seek corroborating technical reporting before taking further action, as no confirmed TTPs, IOCs, or CVEs are available from this listing alone.

Mentioned in this report

Threat actors genesis

Source reporting: https://www.ransomware.live/id/QmVybmF0aCAmIFJvc2VuYmVyZ0BnZW5lc2lz

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free