BDO Perú Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
BDO Perú was listed by the incransom ransomware group on August 20, 2025, after internal files were exfiltrated in a ransomware attack. Anyone connected to BDO Perú should verify whether their information was exposed and take protective steps if necessary.
On August 20, 2025, the ransomware group known as incransom listed BDO Perú on its leak site, claiming to have carried out a ransomware attack that involved the exfiltration of internal files. Public details remain limited: the number of people affected is unknown, and independent confirmation of the full scope has not been disclosed. The listing itself constitutes a claim by the group rather than verified evidence of compromise.
For an organisation operating in professional services, any such claim raises questions about the potential exposure of sensitive business and client information. What is known so far rests on the group's own statements and the fact of the listing; further technical or official details have not been made public.
Breaking down the breach
According to the available record, BDO Perú was listed by incransom on August 20, 2025. The group asserts that internal files were exfiltrated during a ransomware attack. No public information has been released regarding the precise timing of any intrusion, the initial access method, the duration of any presence on systems, or the total volume of data involved. The number of individuals potentially affected remains unknown.
The group's accompanying statement claims access to personal data of department heads and their electronic signatures, as well as information and signatures of clients that include accounting data and audit-related materials. It further claims to hold information on more than 500 companies described as partners and clients. These assertions originate solely from the leak-site listing and have not been independently verified in the public record. No ransom demand amount, payment deadline, or confirmation of data publication has been detailed beyond the listing itself.
Who is incransom?
Incransom is a ransomware operation that has appeared in public threat reporting as a group employing double-extortion tactics: encrypting systems while also claiming to steal data and threatening to publish it if demands are unmet. Like many contemporary ransomware actors, it maintains a leak site used to name victims and post purported samples or descriptions of stolen material. Public analyses of the group describe it as opportunistic, targeting organisations across sectors rather than focusing exclusively on one industry, and relying on common initial-access vectors such as phishing, exposed remote services, or compromised credentials.
The group has been associated with listings of various professional-services and mid-sized enterprises. Its public communications typically emphasise the sensitivity of the claimed data and criticise the victim's security posture. In the present case, the listing of BDO Perú follows this pattern; any specific assertions about the contents of the files or the quality of the organisation's defences remain claims made by the group and should be treated as such until corroborated by independent investigation or official statements.
BDO Perú and its sector
BDO Perú operates as the Peruvian member firm of the international BDO network, which provides audit, tax, advisory and related professional services. Firms of this type routinely handle confidential financial statements, tax filings, internal control documentation, client correspondence and, in many cases, personal data of executives and employees. Because the work involves regulated professions and fiduciary responsibilities, the data held is often subject to professional secrecy rules and data-protection obligations under Peruvian and international frameworks.
A breach claim against such an organisation is consequential precisely because of the nature of the information typically processed. Clients entrust accounting firms with materials that can reveal commercial strategies, financial health and personal identifiers. Even when the exact contents of any exfiltrated set remain unconfirmed, the sector's role as a trusted intermediary means that any credible claim of compromise can affect multiple downstream parties—clients, partners and individuals whose data appear in audit or advisory files.
What data was at risk
The public facts name the exposed material only in general terms as "internal files exfiltrated in ransomware attack." The group's own statement elaborates by claiming possession of personal data belonging to department heads together with their electronic signatures, client information and signatures that encompass accounting data and audit-related materials, and records concerning more than 500 companies identified as partners and clients. These descriptions are presented as the group's assertions; they have not been independently confirmed, and no inventory, file counts or sample listings have been released in the available record.
Organisations in the audit and advisory sector commonly store precisely the categories of information the group describes—executive contact details, digitally signed documents, working papers, financial ledgers and client lists. Whether any or all of those categories were in fact taken remains unconfirmed. Until more detailed forensic findings or official disclosures appear, the precise data types at risk cannot be stated as established fact.
What's at stake
For individuals whose personal data or electronic signatures may have been involved, the concrete risks include potential identity misuse, unauthorised document signing, phishing that leverages accurate personal details, and longer-term exposure of private financial or employment information. For client companies, the possible release of accounting records or audit materials could reveal commercially sensitive figures, contractual terms or internal control weaknesses, creating competitive or regulatory exposure.
For BDO Perú itself, the stakes include reputational damage among clients who rely on confidentiality, potential regulatory scrutiny under data-protection and professional-standards regimes, and the operational cost of investigation, notification and remediation. Because the number of affected people is unknown and the full contents of any exfiltrated set remain unverified, the scale of these risks cannot yet be quantified. The mere listing, however, already places the organisation under public examination of its information-security practices.
What to do if you're exposed
If you are a current or former client, employee or partner of BDO Perú and believe your information may have been involved, begin by monitoring financial accounts and credit reports for unusual activity. Enable multi-factor authentication on email and financial services, and treat any unexpected requests for signatures or payments with heightened caution. Consider placing fraud alerts with relevant credit bureaus where available. Preserve any communications you receive that appear linked to the incident.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan provides an additional, independent signal and can help prioritise further protective steps while official notifications, if any, are awaited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Precise Benefits Group LLC Listed by incransom Ransomware GroupPFMI Listed by incransom Ransomware GroupEvolve Mortgage Services Listed by incransom Ransomware GroupAlios Finance Group Listed by incransom Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the BDO Perú Listed by incransom Ransomware Group →
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.