Incident Details
- Victim: Gress Clark Young & Schoepper
- Sector: Professional Services
- Country:
- Actor: rhysida
- Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=282
- Discovered: 2026-10-10T12:46:50.865750+00:00
- Published: 2026-10-10T12:46:25.165608+00:00
Information
- Banking details of the firm and its clients
- SSNs and signatures of clients and witnesses
- W-9 and I-9 forms with DL/SSN card copies
- W-4 forms
- BIIA case-management procedures, including default orders, internal conference questions, and consulting-fee payments to experts
- Firm financial records, including the QuickBooks company file, VOID checks with signatures, expert-payment records, and SaaS invoices
- Medical photos and imaging, along with hundreds of pages of PHI/APF, X-rays, and complete medical records
- Coaching letters to doctors, including a letter with wording suggesting steering a medical opinion
- Credentials and access to the SPC e-file system
- Disciplinary action against partner Daniel W. Gress

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.