HackerFeeds
All ransomware incidents
N

Ransomware group rhysida hits NEAD Pro

HIGH
·Not Found·2026-09-24

NEAD Pro — a not found target has been listed by the rhysida ransomware group on 2026-09-24. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationNEAD Pro
Threat Group
rhysida
SummaryNEAD Pro Nead Pro is a professional multidisciplinary firm based in Gorizia and Udine, Italy, that provides legal, tax, bankruptcy, and accounting consulting services.What it is: a network share belonging to two Italian professional firms located at Via Roma 20, Gorizia (Friuli-Venezia Giulia):NEAD SRL (NORTH EAST ADVISORS S.R.L.) - an accounting firm, dottore commercialista, P.IVA 01114220310, REA GO-72906;NEAD PRO - PROFESSIONISTI RIUNITI - a law firm, P.IVA 01157140318.Volume: ~575,000 files / ~253 GB. The root contains a single branch Nuova directory\NEAD\ (plus an empty Documenti folder and a scatter of PDF scans at the root level).Structure and contents:Branch Volume ContentsNEAD PRO SITE - Documenti 231,137 files / 193.5 GB Law firm: 03.PRATICHE (46,620 files: CIVILE 9,665, PENALE 537, SOVRAINDEBITAMENTO 1,208), 04. INCARICHI (85,321: FALLIMENTI 22,492, ESECUZIONI 28,509, ADS 14,547, TRUST, CURATELE), SEGRETERIA with CREDENZIALI VARIE.xlsx (~40 firm accounts: SPID, PEC, banks, 2 cards with full PAN+CVC, safe code), bank scans (BANCOMAT PIN, BCC agreements)NEAD SRL SITE - Documenti 101,125 / 55.3 GB Accounting firm: 03.CLIENTI - 199 active + 184 former client folders (730, CU, F24, contracts), 44 private SOGEI Entratel .P12 keys (signing clients' tax returns), ISA/IRAP tax filings 2019�2020, client master data, Account.xlsxPRIMA NOTA - Documenti 1,885 / 871 MB Cash books 2019�2026 (21 xlsx): CASSA / CONTO CORRENTE / POS / CARTA / SISTERPOWERBI - Documenti 548 / 627 MB 37 financial BI models .pbix (BI_ISIDE, BI_NEAD, ATHENA, PNAI)ARCHIVIO 921 / 2.6 GB MPS bank statements 2020�2024, NEAD SRL account closure, firm mail archivePOSTA SARDAMAR / PANEGIOCHI / ISIDE / ADMIN SRL ~165+ / ~174 MB Client and firm mail: IVECO Capital leasing, accertamento Agenzia Entrate, Capitaneria di Porto, verbali poliziaES. IMM. 112-2024 10 files Real-estate enforcement proceedings (Tribunale di Gorizia): bank statements and CIE (ID cards) of auction participantsNEAD root ~85 PDF / 127 MB Scanned bank statements, F24 forms, IPZS envelope with the PIN/PUK of a CIE cardMost sensitive data: client dossiers with tax codes (codici fiscali), court case files (civil/criminal/bankruptcy), medical documents (Art. 9 GDPR), the firm's credential database with full PAN+CVC of two cards and the safe code, 52 Entratel electronic signature keys, ~100 SEPA mandates with IBANs and signatures, client PST archives (7.5 GB), a client's Huawei phone backup (Facebook/Gmail/Telegram databases), passports of foreign shareholders. More
Date of Breach2026-09-24
Discovery Date2026-09-24
Region—
Target Domain—
Business SectorNot Found
Severity
HIGH

Claim by rhysida

NEAD Pro Nead Pro is a professional multidisciplinary firm based in Gorizia and Udine, Italy, that provides legal, tax, bankruptcy, and accounting consulting services.What it is: a network share belonging to two Italian professional firms located at Via Roma 20, Gorizia (Friuli-Venezia Giulia):NEAD SRL (NORTH EAST ADVISORS S.R.L.) - an accounting firm, dottore commercialista, P.IVA 01114220310, REA GO-72906;NEAD PRO - PROFESSIONISTI RIUNITI - a law firm, P.IVA 01157140318.Volume: ~575,000 files / ~253 GB. The root contains a single branch Nuova directory\NEAD\ (plus an empty Documenti folder and a scatter of PDF scans at the root level).Structure and contents:Branch Volume ContentsNEAD PRO SITE - Documenti 231,137 files / 193.5 GB Law firm: 03.PRATICHE (46,620 files: CIVILE 9,665, PENALE 537, SOVRAINDEBITAMENTO 1,208), 04. INCARICHI (85,321: FALLIMENTI 22,492, ESECUZIONI 28,509, ADS 14,547, TRUST, CURATELE), SEGRETERIA with CREDENZIALI VARIE.xlsx (~40 firm accounts: SPID, PEC, banks, 2 cards with full PAN+CVC, safe code), bank scans (BANCOMAT PIN, BCC agreements)NEAD SRL SITE - Documenti 101,125 / 55.3 GB Accounting firm: 03.CLIENTI - 199 active + 184 former client folders (730, CU, F24, contracts), 44 private SOGEI Entratel .P12 keys (signing clients' tax returns), ISA/IRAP tax filings 2019�2020, client master data, Account.xlsxPRIMA NOTA - Documenti 1,885 / 871 MB Cash books 2019�2026 (21 xlsx): CASSA / CONTO CORRENTE / POS / CARTA / SISTERPOWERBI - Documenti 548 / 627 MB 37 financial BI models .pbix (BI_ISIDE, BI_NEAD, ATHENA, PNAI)ARCHIVIO 921 / 2.6 GB MPS bank statements 2020�2024, NEAD SRL account closure, firm mail archivePOSTA SARDAMAR / PANEGIOCHI / ISIDE / ADMIN SRL ~165+ / ~174 MB Client and firm mail: IVECO Capital leasing, accertamento Agenzia Entrate, Capitaneria di Porto, verbali poliziaES. IMM. 112-2024 10 files Real-estate enforcement proceedings (Tribunale di Gorizia): bank statements and CIE (ID cards) of auction participantsNEAD root ~85 PDF / 127 MB Scanned bank statements, F24 forms, IPZS envelope with the PIN/PUK of a CIE cardMost sensitive data: client dossiers with tax codes (codici fiscali), court case files (civil/criminal/bankruptcy), medical documents (Art. 9 GDPR), the firm's credential database with full PAN+CVC of two cards and the safe code, 52 Entratel electronic signature keys, ~100 SEPA mandates with IBANs and signatures, client PST archives (7.5 GB), a client's Huawei phone backup (Facebook/Gmail/Telegram databases), passports of foreign shareholders. More

Posted by the rhysida threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Leak post (onion / Tor)

tor

http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=277

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.