On November 26, 2024, EQ Chartered Accountants appeared on the leak site operated by the qilin ransomware group. The listing states that the firm suffered a ransomware attack in which attackers exfiltrated more than 800 GB of internal files, most of it client data. The group gave the company 48 hours to make contact or face full publication of the stolen material. The exact number of individuals whose records were taken remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch EQ Chartered Accountants
Get alerted the next time EQ Chartered Accountants files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about EQ Chartered Accountants’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Listing
The qilin leak page, mirrored on ransomware.live, explicitly lists EQ Chartered Accountants as a victim and claims the data was taken during a ransomware intrusion. It describes the stolen material as internal files with the majority consisting of client records. The disclosure does not specify the precise data fields exposed, such as names, addresses, tax returns, financial statements, or identification numbers. It also does not quantify how many clients or employees are affected. The posting includes a countdown timer and threatens to release the full 800 GB archive if the firm does not negotiate.
Why This Matters for You and Your Family
If you or any member of your family has used EQ Chartered Accountants for tax preparation, business accounting, payroll, or personal financial advice, your sensitive information may now sit inside a ransomware gang’s archive. Client data from accounting firms routinely includes Social Security numbers, bank account details, tax transcripts, income records, and correspondence that can be used for identity theft or fraudulent loan applications. Even if you are not a current client, former clients from years past are often included in these large extractions. The uncertainty around the exact scope means you must assume your information could be at risk until proven otherwise.
The Doxxing and Identity-Chain Risk
Accounting records frequently link your real name, home address, date of birth, phone number, email addresses, and employer details in one convenient package. Once published on a ransomware leak site, that bundle becomes raw material for doxxing chains. Criminals can correlate the exposed data with usernames found in other breaches, gaming accounts, or social-media profiles. A single leaked tax document can therefore expose not only your finances but also your children’s names, schools, and even their online gaming handles if those appear in any related family correspondence or payment records. Credential leaks of this type routinely cascade into account takeovers across email, banking, and gaming platforms.