On November 11, 2025, accounting firm Rhodes Young Black & Duncan appeared on the leak site of the Akira ransomware group. The firm, based in Duluth, is claimed to have had internal files exfiltrated during a ransomware attack. The attackers stated they will soon upload corporate documents containing clients’ scanned passports, drivers’ licenses, Social Security numbers, medical information, HR files, financial records, agreements, contracts, and a small number of military-related files. The number of people affected remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Rhodes Young Black &Duncan RYBD
Get alerted the next time Rhodes Young Black &Duncan RYBD files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Rhodes Young Black &Duncan RYBD’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from Reports
Public reporting on the Akira leak site indicates the CPA consulting firm suffered a ransomware intrusion in which sensitive client and internal data was taken. The posted notice explicitly lists scanned passports, drivers licenses, SSNs, medical information among the records at risk. No exact victim count or precise date of initial compromise has been disclosed. The group gave no public deadline for payment before further publication, though their standard practice is to pressure targets by threatening to release the material.
Why This Matters for You and Your Family
If you or any member of your family worked with Rhodes Young Black & Duncan, your personal documents could now sit on a criminal leak site. A single exposed Social Security number or scanned driver’s license can be used to open accounts in your name, file fraudulent tax returns, or impersonate you with banks and government agencies. Medical information adds another layer of risk, from insurance fraud to blackmail. Even if you are not a direct client, family members or household employees whose records were stored by the firm may be impacted. Ordinary families rarely discover these exposures until creditors or the IRS come calling months later.
The Doxxing and Identity-Chain Risk
Credential leaks like this one rarely stop at the first site. Once SSNs, emails, and scanned IDs appear, other criminals scrape the data and test it across banking, government, and retail systems. The chain often reaches gaming accounts, where children’s usernames and reused passwords become entry points for further harassment or extortion. What begins as an accounting firm breach can quietly link your work identity, home address, family members’ details, and online handles into a single, saleable profile on dark-web markets.