On March 1, 2024, accounting firm SBM & Co appeared on the leak site of the alphv ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. The firm, established in 1993, provides accounting, taxation, and specialist advisory services to owner-managed businesses, individuals, and entities listed on the London Stock Exchange. The number of people whose data was taken remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch SBM & Co
Get alerted the next time SBM & Co files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about SBM & Co’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The alphv leak site entry states that SBM & Co suffered a ransomware incident in which attackers successfully exfiltrated internal files. The disclosure does not quantify the volume of records involved, list specific data types beyond “internal files,” or state whether client records, financial documents, or personal information were included. It also does not provide a ransom demand or payment deadline. The listing simply presents the victim’s name, a brief company description, and proof-of-exfiltration samples.
Why This Matters for You and Your Family
If you or any member of your family has used SBM & Co for accounting, tax preparation, or financial advice, your personal or business information may now sit in an attacker’s archive. Internal files from an accounting practice routinely contain names, addresses, dates of birth, National Insurance numbers, bank details, tax returns, and correspondence. Even a single leaked document can give criminals enough to open accounts, file fraudulent tax returns, or impersonate you with HMRC or banks. Because the disclosure gives no count of affected records, every client must assume their information could be exposed.
Doxxing and Identity-Chain Risks
Exposed accounting data rarely stays isolated. Attackers combine it with credential leaks, social-media handles, and gaming accounts to build detailed identity chains. A tax return might list your child’s name and school alongside your email address; that email may already appear in earlier breaches tied to an Xbox or Roblox login. Once linked, the chain allows doxxing, targeted phishing, or account takeovers that affect the entire household. Credential leaks like this one cascade into gaming account takeovers when the same password or recovery email is reused.