Blossomland Accounting LLC, a Southwest Michigan accounting firm, suffered a ransomware attack by the Akira group, which claims to have stolen 12GB of data including Social Security numbers, passports, driver’s licenses, and financial records. The breach was discovered in September 2026. Affected individuals should monitor credit reports and consider a credit freeze immediately.
| Company | Blossomland Accounting LLC |
|---|---|
| Industry | Finance |
| Data Types Exposed | Social Security Numbers, Passport Numbers, Driver’s License Numbers, Death Certificates, Financial Account Information, Credit Card Details, Confidential Client Files, Business Contracts and Agreements |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Blossomland Accounting Data Breach?
Blossomland Accounting LLC, a Southwest Michigan firm offering tax preparation, payroll, and financial consulting services, has confirmed a serious cybersecurity incident. A ransomware group known as Akira claims to have infiltrated the firm’s network and stolen a large volume of sensitive files. The Blossomland Accounting data breach came to light after the attackers publicly threatened to release the stolen material.
According to available details, unauthorized access to the firm’s network occurred in September 2026. The Akira group stated it obtained roughly 12 gigabytes of corporate data. This reportedly includes employee personal records, financial documents, and confidential client files. As a result, both staff and clients of the firm may be at risk.
Because Akira is a known ransomware operation, the attack likely involved encrypting internal systems in addition to stealing data. However, the exact intrusion method has not been publicly detailed. Following discovery, the firm presumably began an internal investigation to determine the scope of the compromise. At this time, full forensic findings have not been publicly disclosed.
In response to threats like this, firms typically bring in outside cybersecurity specialists. This helps confirm which systems were touched and which records were copied. Still, affected individuals should treat the threat actor’s claims seriously until official notifications provide further clarity.
Who was affected?
The Blossomland Accounting breach may affect multiple groups connected to the firm. This includes current and former employees, whose personnel files were reportedly targeted. It may also include clients who trusted the firm with their tax, payroll, and financial information.
The exact number of individuals affected has not been publicly disclosed. Given the firm’s role in tax preparation and payroll processing, however, the exposed population could include people across Southwest Michigan and beyond. Because payroll and tax files often include dependents’ information, minors could also be indirectly affected.
In addition, because Blossomland Accounting serves both individual clients and businesses, the breach could reach a wide mix of consumers and companies. This means both personal and corporate financial data may be at risk. Anyone who has worked with or been employed by the firm should consider themselves potentially affected until notified otherwise.
What Information Was Potentially Exposed?
The threat actors claim to have stolen a wide range of highly sensitive data categories. This is especially concerning given the nature of an accounting firm’s records. The stolen files reportedly include both personal identity documents and detailed financial information.
- Social Security numbers
- Passport numbers
- Driver’s license numbers
- Death certificates
- Financial account information
- Credit card details
- Confidential client files
- Business contracts and agreements
Because Social Security numbers and passport data were reportedly involved, affected individuals face a heightened risk of identity theft. Criminals can use this combination to open new credit accounts, file fraudulent tax returns, or apply for loans. This type of exposure is especially dangerous because it rarely expires like a stolen password.
In addition, the reported theft of credit card details and financial account information raises the risk of direct financial fraud. Someone with this data could attempt unauthorized charges or account takeovers. Furthermore, the presence of death certificates suggests estate-related records were included, which could enable fraud against deceased individuals’ estates or surviving family members.
What is the company doing?
Blossomland Accounting has not publicly released a full account of its remediation steps. However, incidents involving ransomware groups like Akira typically prompt an immediate shutdown of affected systems. This is done to prevent further unauthorized access while investigators assess the damage.
Firms in this situation generally work with cybersecurity forensic teams to determine what was accessed. They also typically notify affected individuals once the scope of compromise is confirmed. As of now, the notification timeline for Blossomland Accounting has not been publicly disclosed.
Affected individuals should watch for official letters or emails from the firm in the coming weeks. These notifications often include details on any credit monitoring or identity protection services being offered. Because specifics have not yet been shared publicly, individuals should rely on official communications rather than assumptions.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone connected to Blossomland Accounting should request a copy of their credit report right away. You can get free reports from all three major credit bureaus through AnnualCreditReport.com. Reviewing these reports helps you spot unfamiliar accounts or inquiries quickly.
Because tax and payroll data were reportedly involved, ongoing monitoring is especially important. Fraudulent accounts can sometimes take months to surface. Therefore, checking your reports periodically, rather than just once, gives you a better chance of catching problems early.
Consider a Credit Freeze or Fraud Alert
Since Social Security numbers and financial data were reportedly exposed, placing a credit freeze is a strong protective step. A freeze blocks new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name. You can request a freeze directly with each of the three major bureaus.
Alternatively, a fraud alert is a lighter-touch option that still requires lenders to verify your identity before extending credit. This can be useful if you want to maintain easier access to new credit while still adding a layer of protection. Either option is free to set up under federal law.
Watch for Phishing Attempts
Because attackers now may have personal and financial details, they could use this information to craft convincing phishing emails or calls. Be cautious of any message claiming to be from Blossomland Accounting, the IRS, or your bank. Never click links or share codes with unexpected callers.
Instead, verify any suspicious communication by contacting the organization directly through a known phone number or website. This simple habit can prevent scammers from tricking you into revealing further sensitive information. As a result, staying alert to these tactics is one of the most effective defenses available.
Protect Against Tax and Identity Fraud
Given that this firm handled tax preparation services, affected individuals should also consider filing an Identity Protection PIN with the IRS. This PIN prevents criminals from filing fraudulent tax returns using your Social Security number. It adds an extra verification step that only you can complete.
In addition, keep a close eye on any tax-related notices you receive, especially unexpected letters about returns you did not file. If you notice signs of tax fraud, report it to the IRS immediately. Because passport and driver’s license numbers were also reportedly exposed, consider contacting those issuing agencies if you notice signs of misuse.
Consult a Data Breach Attorney
Given the sensitivity of the data reportedly stolen, affected individuals may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation through a class action or individual claim. Many offer free consultations, so there is little risk in asking questions.
Furthermore, an attorney can help you track deadlines for filing a claim, which can vary based on your state and the specifics of the breach. Acting sooner rather than later ensures you do not miss an opportunity for potential compensation. This is especially useful if you experience financial losses tied to the breach.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
