Bernath & Rosenberg, a CPA firm, suffered a ransomware attack claimed by the Genesis threat actor group, potentially exposing client tax and financial records including Social Security numbers. The exact number of affected individuals has not been disclosed. Affected individuals should monitor credit reports, place a fraud alert or freeze, and watch for tax fraud immediately.
| Company | Bernath & Rosenberg |
|---|---|
| Industry | Finance |
| Data Types Exposed | Full Names, Social Security Numbers, Tax Return Information, Financial Account Details, Income and Employment Records, Contact Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Bernath & Rosenberg Data Breach?
Bernath & Rosenberg, a full-service accounting firm, has confirmed it was the target of a ransomware attack. A threat actor group known as Genesis has claimed responsibility for breaching the firm’s network. As a result, sensitive client information tied to tax and financial services may have been accessed or stolen.
Details about the exact timeline remain limited. The breach discovery date has not been publicly disclosed. However, ransomware attacks like this one typically begin with attackers gaining unauthorized access to internal systems before deploying malicious software or exfiltrating data. In many cases, the true intrusion date is later than when the attack is finally detected.
Because Bernath & Rosenberg operates as a CPA firm, its systems likely store highly sensitive financial documentation for individual and business clients. Once the firm identified the intrusion, it presumably launched an internal review and brought in outside forensic specialists. This is standard practice for professional services firms facing a ransomware incident of this nature. At this time, the notification date to affected individuals has also not been publicly disclosed.
Who was affected?
The individuals affected by this breach likely include current and former clients of Bernath & Rosenberg. Because the firm provides accounting and tax preparation services, those impacted may include individual taxpayers, small business owners, and other clients who trusted the firm with financial records.
The exact number of affected individuals has not been publicly disclosed. In addition, it remains unclear whether employee records were also compromised alongside client data. Firms like this often maintain payroll and HR files internally, meaning staff members could also face exposure risk.
Given the nature of CPA services, the geographic scope of affected individuals may extend beyond a single state. Clients frequently work remotely with accounting firms, so people across multiple regions of the country could be impacted. Because tax preparation involves detailed financial histories, this breach could carry heightened stakes compared to more generic retail-related incidents.
What Information Was Potentially Exposed?
While a complete list of exposed data fields has not been released, the nature of a CPA firm’s operations suggests certain categories of information were likely stored on the compromised systems. Ransomware groups like Genesis often target firms specifically because they hold valuable financial documentation.
- Full names
- Social Security numbers
- Tax return information
- Financial account details
- Income and employment records
- Contact information such as addresses and phone numbers
If these categories were indeed accessed, the risk to affected individuals could be significant. Social Security numbers and tax records are especially valuable to criminals because they enable fraudulent tax filings. As a result, victims could see fake returns filed in their names before they file their own.
Furthermore, financial account details combined with personal identifiers can enable more sophisticated fraud schemes. Criminals may attempt to open new credit lines, apply for loans, or access existing accounts. Because tax data often includes a fuller financial picture than a typical retail breach, the potential for long-term identity theft is considerable.
What is the company doing?
In response to the attack, Bernath & Rosenberg has presumably taken steps to contain the intrusion and secure its network. Firms facing ransomware incidents typically isolate affected systems, reset credentials, and work with cybersecurity experts to determine the scope of unauthorized access.
Ongoing remediation efforts likely include a continued forensic investigation to confirm exactly which files and client records were compromised. Additionally, the firm may be coordinating with law enforcement, given that the Genesis threat actor group has publicly claimed the attack. At this stage, specific details about credit monitoring or identity protection offers have not been publicly disclosed.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should check their credit reports regularly for unfamiliar accounts or inquiries. This is especially important because financial and tax data can be used to open new lines of credit fraudulently.
You can request free credit reports from all three major credit bureaus. Because early detection often limits damage, reviewing these reports every few months is a smart habit going forward.
Consider a Fraud Alert or Credit Freeze
Given the possible exposure of Social Security numbers, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires lenders to verify your identity before extending new credit in your name.
A credit freeze goes further by restricting access to your credit file entirely. As a result, it becomes much harder for criminals to open new accounts using your information. Both options are free and can be requested directly through each credit bureau.
Watch for Tax-Related Fraud
Because tax records may have been exposed, affected individuals should watch closely for signs of tax fraud. This includes unexpected notices from the IRS about returns you did not file.
If you suspect tax-related identity theft, contact the IRS Identity Protection Specialized Unit right away. In addition, consider requesting an Identity Protection PIN, which adds another layer of security to your tax filings each year.
Stay Alert for Phishing Attempts
Following a breach like this, scammers often send phishing emails or texts pretending to be from the affected company. These messages may try to trick you into revealing passwords or financial details.
Therefore, avoid clicking links in unsolicited messages, even if they appear legitimate. Instead, go directly to official websites or call verified phone numbers if you need to confirm your account status.
Consult a Data Breach Attorney
If you believe your information was compromised, it may help to speak with an attorney who focuses on data breach cases. Many offer free consultations to evaluate whether you qualify for compensation.
Because laws around data breach liability vary by state, professional legal guidance can clarify your options. This is particularly useful if financial harm or identity theft occurs as a direct result of this incident.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
