Chisholm Persson & Ball Data Breach

Alleged

Ransomware claim involving Chisholm Persson & Ball.

Published: Jul 7, 2026 Akira
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Chisholm Persson & Ball
Industry
Business Services
Threat Actor
Akira
Date of Incident
Jul 7, 2026

Executive Summary

Chisholm Persson & Ball, a business services company located in the United States, has been publicly listed as a victim of the Akira ransomware group. The listing appeared on the group’s dark web portal on July 7, 2026, as identified by SOCRadar’s Dark Web Monitoring. The company specializes in professional and legal services, fitting within Akira’s known targeting patterns. Akira has been highly active, claiming numerous victims in recent months, with a pronounced focus on the business services, manufacturing, and hospitality and tourism sectors. Their geographic targeting tends to be concentrated in the United States, the United Kingdom, and Germany. Chisholm Persson & Ball’s inclusion aligns with these trends, as the ransomware group has previously targeted similar professional services firms in the US.

Technical Analysis

SOCRadar’s threat intelligence, utilizing stealer-log telemetry, identified a limited exposure related to the cpblaw.com domain. This exposure consisted of a single credential pair found on a third-party service, suggesting a potential localized endpoint compromise rather than a direct breach of the organization’s core infrastructure. No high-value identity, mail, or VPN endpoints were flagged in this specific instance, indicating a low-volume, yet corporate-relevant, finding. For ransomware groups like Akira, compromised credentials obtained from stealer logs are a common initial access vector. Threat actors often purchase these logs from underground marketplaces, validate the corporate credentials, and then use them to gain unauthorized access to systems, including Microsoft 365, VPNs, or remote access portals. While this specific log does not definitively confirm Akira’s use of this particular credential for the breach, it is consistent with the early stages of the attack kill chain often observed in such incidents. Cybersecurity threat intelligence (CTI) teams are advised to treat this exposed account as a potential access path and prioritize actions such as credential rotation, session invalidation, and a thorough review of associated sign-in activities.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.