Ransom! NEAD Pro (SEP-2026)
NEAD Pro’s Italian law-firm network share (~253 GB across ~575,000 files) was targeted and encrypted by the rhysida ransomware, impacting the firm’s Documenti repositories containing legal case files, client dossiers (including tax identifiers), and sensitive credential/ID data. The compromise also included credential material such as SPID/PEC and bank-related scans, Entratel signing keys, and other high-risk records (e.g., card details and safe codes), affecting #Italy

Incident Details

  • Victim: NEAD Pro
  • Sector: Not Found
  • Country:
  • Actor: rhysida
  • Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=277
  • Discovered: 2026-09-24T18:01:29.579614+00:00
  • Published: 2026-09-24T18:01:13.290204+00:00

Information

  • Multidisciplinary professional firm based in Gorizia and Udine, Italy, providing legal, tax, bankruptcy, and accounting services.
  • Network share tied to two Italian professional firms at Via Roma 20, Gorizia.
  • Includes an accounting firm and a law firm, with a combined volume of about 575,000 files and 253 GB.
  • Main directory contains a single branch plus an empty Documenti folder and scattered PDF scans at the root.
  • Law firm area holds civil, criminal, insolvency, bankruptcy, execution, guardianship, and trust-related case files.
  • Secretarial records include a credentials spreadsheet with many firm accounts, banking access details, two cards with full payment data, and safe access information.
  • Bank scans include card PINs and banking agreements.
  • Accounting firm area contains client folders, tax returns, forms, contracts, and archived client records.
  • Includes many private SOGEI Entratel signing keys used for client tax filings.
  • Contains ISA and IRAP tax filings, client master data, and internal accounting spreadsheets.
  • Cash books cover multiple years and track cash, bank account, POS, card, and related transactions.
  • Financial BI models are stored in Power BI format.
  • Archive includes bank statements, account closure records, and firm email archives.
  • Email repositories contain correspondence related to leasing, tax authority notices, maritime authority matters, and police reports.
  • Real-estate enforcement files include bank statements and identity documents of auction participants.
  • Root-level scans include bank statements, tax forms, and an envelope containing PIN and PUK codes for an ID card.
  • Sensitive material includes client tax identifiers, court files, medical records, credential databases, electronic signature keys, SEPA mandates, client archives, mobile phone backups, and passports.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live