LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Huber , Erickson & Bowman Listed by akira Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Huber , Erickson & Bowman Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 30, 2025
Huber , Erickson & Bowman Listed by akira Ransomware Group

Reported October 30, 2025.

HIGH
Severity
October 30, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Huber, Erickson & Bowman was listed by the Akira ransomware group on October 30, 2025, with internal files reportedly taken in the attack; the date of the intrusion itself has not been established. Individuals connected to the firm should review any notices from Huber, Erickson & Bowman and consider protective steps such as monitoring accounts and changing passwords.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID/financial data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Huber, Erickson & Bowman, a Salt Lake City tax and accounting firm also known as HEB Advisors, was listed by the Akira ransomware group on or around October 30, 2025. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope is limited. The listing matters because the firm holds sensitive financial and personal records for clients and staff, creating potential exposure risks if the claims hold.

The group has stated it will upload 66 GB of corporate documents and asserts it took large volumes of personal information from clients and employees along with detailed accounting and internal confidential files. These details come from the threat actor’s own claims rather than verified disclosures by the firm.

Breaking down the breach

According to available public information, Huber, Erickson & Bowman was listed by the Akira ransomware group with a report date of October 30, 2025. The incident is described as a ransomware attack involving the exfiltration of internal files. No confirmed timeline for the initial intrusion, method of access, or total volume of data beyond the group’s statements has been disclosed in the provided record. The number of individuals affected is listed as unknown.

The Akira group claims it will soon upload 66 GB of corporate documents and that it obtained an “incredibly large amount” of personal information belonging to clients and employees, including addresses, phone numbers, dates of birth, driver’s licenses, Social Security cards, credit cards, and similar items, plus detailed accounting information and internal confidential files. These assertions appear on the group’s leak site and have not been independently verified in the facts available. Public detail on whether ransom negotiations occurred or whether systems were encrypted remains limited.

The group behind it: akira

Akira is a well-documented ransomware operation that emerged in 2023 and has conducted numerous double-extortion campaigns. The group typically gains access through compromised credentials or unpatched systems, encrypts victim networks, and simultaneously steals data to pressure payment by threatening public release. It maintains a dedicated leak site where it posts victim names and sample files, often followed by larger data dumps if demands are unmet. Akira has targeted organizations across professional services, manufacturing, and other sectors, frequently focusing on mid-sized firms that hold valuable financial or personal records. Its tactics align with other ransomware-as-a-service models, emphasizing data theft alongside encryption. In this case, the listing of Huber, Erickson & Bowman and the accompanying statements about 66 GB of documents and personal data constitute claims by the group rather than What's Publicly Reported about the incident.

About Huber , Erickson & Bowman

Huber, Erickson & Bowman operates as HEB Advisors, described as Salt Lake City’s premier full-service tax and accounting firm with more than 45 years of experience. It serves individuals, small and mid-sized businesses, government entities, and non-profit organizations. Firms of this type routinely handle tax returns, financial statements, payroll data, and supporting personal identification documents required for compliance and advisory work. Because the practice deals with both private clients and institutional entities, a breach can affect a wide range of people whose records are stored for professional services. The firm’s role in managing sensitive financial and identity-related information makes any unauthorized access consequential for those who rely on its confidentiality.

What was likely exposed

The facts state that internal files were exfiltrated in the ransomware attack. The Akira group claims it obtained an incredibly large amount of personal information of clients and employees—specifically listing addresses, phones, dates of birth, driver’s licenses, Social Security cards, credit cards, and similar items—along with detailed accounting information and internal confidential files, and that it plans to upload 66 GB of corporate documents. These data types are presented as the group’s assertions. Exact contents and the full set of records involved remain unconfirmed by independent sources. Organizations in the tax and accounting sector typically hold tax filings, bank details, Social Security numbers, contact information, and internal workpapers; however, whether every category claimed by the group was actually taken cannot be verified from the available record. The precise scale of exposure for any individual is therefore unknown.

Why it matters

If the claimed data were released or misused, affected clients and employees could face identity theft, fraudulent tax filings, unauthorized credit activity, or targeted phishing that references real personal details. Accounting records may also reveal business finances, vendor relationships, or non-profit funding that could be exploited for further fraud or competitive harm. For the firm itself, the incident raises operational, reputational, and potential regulatory concerns common to professional-services breaches, though no specific legal findings or costs are reported here. Because the number of people affected is unknown and the data types rest on the group’s claims, the practical impact for any single person depends on whether their records were among those taken—an assessment that cannot yet be made from public facts alone. The combination of personal identifiers and financial documents heightens the long-term monitoring burden for those potentially involved.

What to do if you're exposed

Anyone who has been a client or employee of Huber, Erickson & Bowman should monitor financial accounts and credit reports for unusual activity, place fraud alerts if warranted, and be cautious of unsolicited communications that reference personal or tax details. Consider requesting free annual credit reports and reviewing recent tax transcripts for anomalies. Change passwords on related accounts and enable multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official notifications from the firm, if issued, should be followed for any specific guidance or credit-monitoring offers. Remaining vigilant over the coming months is the most practical step while fuller details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyHuber , Erickson & Bowman security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Huber , Erickson & Bowman’s full breach history →

More recent breaches

Phillips Scales Listed by akira Ransomware GroupDecember 18, 2025Adelman & Gettleman Listed by akira Ransomware GroupDecember 17, 2025Rodenburg Law Firm Listed by akira Ransomware GroupDecember 9, 2025The Minor Firm Listed by akira Ransomware GroupDecember 4, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Huber , Erickson & Bowman Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram