On January 17, 2025, accounting firm Anders CPAs + Advisors appeared on the leak site of the ransomware group SilentRansomGroup. The firm, which has served clients since 1965 from its headquarters in St. Louis, Missouri, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates that the exposed data includes sensitive client and operational records typical of a CPA and advisory practice.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Anders CPAs + Advisors
Get alerted the next time Anders CPAs + Advisors files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Anders CPAs + Advisors’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Available reporting describes the incident as a ransomware deployment that resulted in both encryption and data theft. Internal files were taken before the attackers posted a listing on their leak site. The exact number of individuals affected remains unknown, and the precise volume or specific categories of client records has not been publicly detailed beyond the broad description of exfiltrated internal documents. Anders has not released an official statement confirming the scope at the time of this writing.
Why This Matters for You and Your Family
If you or your family have used Anders CPAs + Advisors for tax preparation, financial planning, estate work, or business accounting, your personal and financial information may now sit in a ransomware group’s hands. Tax returns, Social Security numbers, bank account details, addresses, and family financial profiles are common in CPA records. Once stolen, this data can fuel identity theft, fraudulent loan applications, or targeted scams against you or your children for years. Even if you are not a current client, vendor records or employee data from the firm could still expose your information.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one company. A single exposed email, phone number, or client identifier can link your professional life to your personal accounts across the internet. Attackers or opportunistic criminals chain these fragments together to build full profiles, locate family members, and target gaming accounts, social media, or school records. Credential leaks like this one frequently cascade into account takeovers because people reuse passwords. Children’s gaming accounts tied to a parent’s email are especially vulnerable because kids rarely use strong, unique credentials.