On April 27, 2024, the ransomware group Dispossessor added pwc.com to its public leak site, listing the global professional-services firm as a victim of a ransomware attack in which internal files were allegedly exfiltrated. The disclosure indicates that anyone whose personal or financial information passed through PwC systems in recent years may now face heightened exposure, even though the exact number of affected individuals remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch pwc.com
Get alerted the next time pwc.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about pwc.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Dispossessor leak-site listing states that PwC suffered a ransomware intrusion and that attackers successfully removed internal files. No specific volume of records, types of documents, or list of compromised data fields is provided in the posting. The notification does not quantify affected records, nor does it name particular clients or data categories such as tax returns, audit materials, or employee records. What is confirmed is the date of public listing — April 27, 2024 — and the fact that the threat actor claims to possess exfiltrated corporate data from the PwC environment.
Why This Matters for You and Your Family
When a firm the size of PwC is breached, the ripple effects reach far beyond its own employees. Millions of individuals and households entrust the company with sensitive financial, tax, employment, and identity information through audits, consulting engagements, mergers, or payroll services. If your data was included in the stolen files, it could surface in future extortion attempts or be sold quietly on underground markets. The disclosure makes clear that internal files were allegedly exfiltrated, meaning any personal details contained in those files are now outside corporate control and subject to misuse.
For ordinary people this translates into concrete risks: unexpected tax fraud, loan applications opened in your name, or targeted phishing campaigns that reference real details only PwC would know. Children’s records held by family-linked clients are equally vulnerable, especially when parent-child linkages appear in shared financial documents.