On February 5, 2026, French accounting and consulting network Exco appeared on the leak site of the sinobi ransomware group. The listing indicates that internal files were exfiltrated during a ransomware attack on the firm, which serves businesses across France and internationally with accounting, audit, tax, HR, legal, and corporate management services.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Exco
Get alerted the next time Exco files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Exco’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the sinobi leak site describes the incident as a successful ransomware deployment followed by data exfiltration. The exposed material consists of internal files. The exact number of people whose personal information appears in the files remains unknown. No confirmed timeline of initial access or precise volume of records has been published. The leak site listing itself serves as the primary public evidence of the breach.
Why This Matters for You and Your Family
When an accounting firm like Exco is breached, client records containing names, addresses, tax identifiers, financial details, and correspondence can be exposed. If you or your family have ever used an accountant, auditor, or business advisor connected to the Exco network, your information may now sit in an attacker-controlled archive. Financial and tax data is especially valuable because it can be used for identity theft, fraudulent loan applications, or targeted scams that feel personal and credible. Ordinary families rarely discover these leaks until months later when unexpected bills or tax notices arrive.
The Doxxing and Identity-Chain Implications
Stolen internal files often contain more than spreadsheets. They can include email addresses, phone numbers, client notes, and references to spouses, children, or business partners. Attackers chain these fragments together: an email from one record links to a reused password from an earlier breach, which leads to a gaming account or social-media handle, which reveals home addresses and family relationships. This identity-chain effect turns a single corporate breach into long-term personal exposure. Credential leaks like this one frequently cascade into account takeovers, including gaming accounts belonging to you or your children.