Richard W. Fuller CPA Listed by 8base Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Richard W. Fuller CPA Listed by 8base Ransomware Group (reported December 27, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On December 27, 2022, the accounting firm Richard W. Fuller CPA was listed by the ransomware group known as 8base. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further specifics about the incident have not been disclosed.
For clients and others who may have shared financial or personal information with the firm, the listing raises practical questions about what data left the organisation’s systems and what steps are warranted. Detail in the public record is limited; what follows rests only on the reported facts and established background on the actor and the sector.
Breaking down the breach
According to the available record, Richard W. Fuller CPA appeared on 8base’s listings on December 27, 2022. The reported description states that internal files were exfiltrated in a ransomware attack. No confirmed figure has been given for the number of individuals affected. The precise method of initial access, the duration of any unauthorised presence on the network, the volume of data taken, and any ransom demand or negotiation outcome are undisclosed in the public facts.
A leak-site listing by a ransomware group is a claim by that group. It does not, by itself, constitute independent confirmation of every asserted detail. Organisations named in such listings sometimes later issue their own notices; in this case, the facts provided do not include a separate victim confirmation or a detailed forensic summary. What is known is therefore narrow: the firm was named, the date of the report is December 27, 2022, and the data characterisation is limited to internal files taken in a ransomware incident.
The group behind it: 8base
8base is a ransomware operation that became more visible in 2022 and 2023. Like other groups in this category, it has typically combined encryption of victim systems with data theft, then used public leak sites to pressure organisations by threatening or carrying out the release of stolen material. Public reporting on 8base has described a double-extortion model: victims face both operational disruption from encryption and the risk of exposure of confidential files if they do not pay.
The group has been associated with attacks across multiple sectors, often smaller and mid-sized organisations that may hold concentrated stores of client or employee data. Tactics commonly attributed to such actors in open sources include phishing, exploitation of exposed remote-access services, and the use of commodity or custom ransomware payloads after initial access. None of that general pattern should be read as a verified play-by-play of the Richard W. Fuller CPA incident; the facts for this case state only the listing and the exfiltration of internal files. Claims made on a leak site about any particular victim remain the group’s assertions unless corroborated elsewhere.
Richard W. Fuller CPA and its sector
Richard W. Fuller CPA is described in its own public materials as a firm serving clients throughout New York’s Capital District and the North Country. It presents itself as providing personalised tax and financial services, with an office address in Glens Falls, New York. Accounting and tax practices of this kind routinely handle sensitive client information in the ordinary course of work: tax returns, supporting financial statements, identification details needed for filings, correspondence with tax authorities, and related business or personal records.
A breach affecting a CPA firm is consequential because the data such firms hold is often sufficient to enable identity misuse, tax fraud, or targeted social engineering. Even when the exact contents of a theft are not published, the nature of the profession means that both individual clients and small businesses may have entrusted the firm with information they would not share lightly. The firm’s stated emphasis on local, ongoing client relationships underscores that the potential impact is not abstract; it concerns people and entities who relied on the practice for core financial matters.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as specific document types, client lists, employee records, or categories of personal data—has been disclosed in the material provided. The number of people affected is unknown.
Organisations in the accounting and tax sector typically maintain client contact details, tax identification numbers, income and asset information, prior-year returns, bank or payment references used for filings or fees, and internal working papers. Employee or contractor records may also exist on the same systems. It is reasonable to note that these are the kinds of data such a firm would ordinarily hold; it is not established fact that every such category was present in the exfiltrated set. Exact contents remain unconfirmed. Readers should treat any assumption about their own records as provisional until the firm or a regulator provides a clearer inventory.
The real-world impact
For individuals, the primary risks after a professional-services breach of this type include fraudulent tax filings, account takeover attempts that use personal or financial details, and phishing that appears to come from a familiar accountant or tax preparer. Even limited internal files can contain enough context—names, addresses, filing status, or prior correspondence—to make social-engineering messages more convincing. Credit and identity monitoring, careful scrutiny of tax transcripts, and caution toward unexpected requests for information are proportionate responses when exposure is possible but unconfirmed in detail.
For the organisation, consequences can include operational disruption from the ransomware event itself, costs of investigation and recovery, notification and support obligations where applicable, and erosion of client trust. Because public detail on scale and content is thin, the full scope of harm cannot be measured from the listing alone. The absence of a published headcount or data inventory does not mean the risk is zero; it means affected parties must proceed on a precautionary basis rather than on a precise map of what was taken.
Were you affected?
If you have been a client or employee of Richard W. Fuller CPA, consider reaching out to the firm through known official channels to ask whether your information was involved and whether any notice or guidance has been issued. Monitor tax accounts and financial statements for unfamiliar activity, and treat unsolicited requests for personal or payment details with scepticism even when they reference the firm. Place fraud alerts or credit freezes if you believe sensitive identifiers may have been exposed, and document any suspicious contacts.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step does not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant the same practical precautions.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Neighborhood Progress Fund Listed by 8base Ransomware GroupPrint Globe Listed by 8base Ransomware GroupConklin Benham Listed by 8base Ransomware GroupNORTCON Listed by 8base Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Richard W. Fuller CPA Listed by 8base Ransomware Group →
Publicly posted by 8base — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.