On September 15, 2025, the Professional Trust Company appeared on the leak site of the Everest ransomware group. The company, which manages trusts, estates, and sensitive financial records for individuals and families, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of people affected remains unknown, anyone whose documents, personal data, or financial details were held by the firm could now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Professional Trust
Get alerted the next time Professional Trust files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Professional Trust’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involved a successful ransomware deployment followed by data exfiltration. The Everest group published a listing on its dark-web leak site on September 15, 2025, claiming to hold internal files stolen from the Professional Trust Company. No specific volume of records or list of exposed data types has been publicly detailed beyond the broad description of internal files. The company has not yet issued a public statement confirming the breach or notifying affected individuals.
Why This Matters for You and Your Family
When a trust company is breached, the information at risk often includes names, addresses, Social Security numbers, bank account details, beneficiary records, and estate planning documents. If your family has ever used a trust, set up a will, transferred property, or worked with a professional fiduciary, your data may have been stored in the compromised systems. Once exfiltrated, this information does not disappear. It can be sold, traded, or used to build detailed profiles that make identity theft, fraudulent loan applications, or targeted scams far easier. Children’s records linked to family trusts are especially vulnerable because they often remain unchanged for years.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one company. A single exposed email or phone number can be cross-referenced with credentials from earlier breaches, creating an identity chain that links your online handles, gaming accounts, family member names, and physical address. Public reporting shows these chains frequently lead to doxxing, account takeovers, and extortion attempts. Credential leaks like this one routinely cascade into gaming platforms, where children’s accounts become entry points for further targeting because parents often reuse passwords or security questions tied to family trusts.