# Ransomware.live lists Bernath & Rosenberg breach

Published: 2026-09-14 · Severity: routine
Canonical: https://vorant.io/reports/df617db1-6875-5d98-b5e6-65ab346a2553/ransomware-live-lists-bernath-rosenberg-breach

> A ransomware.live listing shows law firm Bernath & Rosenberg compromised, with over 390 user accounts and third-party credentials exposed by a group tracked as 'genesis'.

This is a minimal victim-listing entry from ransomware.live, an aggregator that tracks claims and leak-site postings from ransomware operators. The entry references an organization identified as 'Bernath & Rosenberg' and attributes the listing to a group referenced as 'genesis' in the source identifier. The posting includes summary statistics: zero directly compromised employees, 394 compromised users, 188 third-party employee credentials, and 3 external attack surface findings, alongside a leak screenshot (not reproduced here).

No technical indicators, exploited vulnerabilities, malware samples, or intrusion details are provided in this source — it is a leak-site tracking summary rather than a technical intrusion report. Defenders associated with, or doing business with, an entity of this name should treat this as a signal to check for credential exposure (particularly third-party/vendor credentials) and review external attack surface exposure, but should seek corroborating technical reporting before taking further action, as no confirmed TTPs, IOCs, or CVEs are available from this listing alone.

## Mentioned in this report

- Threat actors: genesis

Source reporting: https://www.ransomware.live/id/QmVybmF0aCAmIFJvc2VuYmVyZ0BnZW5lc2lz

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/df617db1-6875-5d98-b5e6-65ab346a2553/ransomware-live-lists-bernath-rosenberg-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
