Frank Rim & Associates Data Breach

Alleged

Settra ransomware claim involving Frank Rim & Associates

Published: Aug 11, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Frank Rim & Associates
Industry
Business Services
Threat Actor
Settra
Date of Incident
Aug 11, 2026

Executive Summary

Frank Rim & Associates, a professional services firm based in the United States, has been targeted by the Settra ransomware group. The listing occurred on August 11, 2026, and was identified through SOCRadar’s Dark Web Monitoring service. This incident aligns with Settra’s recent activity, which has frequently targeted American professional services firms. The nature of such businesses, dealing with sensitive client data and operating in a digital environment, makes them potential targets for ransomware and extortion attacks. Settra has named 25 other victims in the preceding 60 days, indicating a consistent operational pace. The group primarily targets the business services, technology, and consumer services sectors, with a strong concentration of victims in the United States, followed by Germany and the UK. Recent US victims in similar sectors include Green Valley Financial Services Inc., Joy Construction Corp, Wilfley, and R.C. Fields & Associates. Frank Rim & Associates fits squarely within Settra’s established pattern of targeting US-based service-oriented organizations.

Technical Analysis

SOCRadar’s investigation identified a correlation between Frank Rim & Associates and the domain advancedtaxsolutions[.]com. However, a query against this specific domain within the analyzed stealer-log dataset returned no records. This finding is subject to several important caveats. The queried domain, advancedtaxsolutions[.]com, is not an immediately obvious subdomain or direct match for “Frank Rim & Associates,” meaning the correlation relies on the accuracy of the mapping between the organization and this specific domain as its primary online presence. Furthermore, the query was performed on a paginated and filtered sample of the dataset. This means that credentials associated with Frank Rim & Associates might exist under alternate corporate domains, use personal email aliases, or reside in data feeds not covered by this specific query. Additionally, any compromised credentials may have already been used and rotated before being indexed in the dataset, or the data may not have been indexed yet. The absence of records in this limited query does not confirm that the organization is unaffected by credential compromise. Infostealer-harvested credentials are a common entry vector for ransomware groups like Settra. Threat actors or access brokers often source these credentials from dark web markets, validate them for access to corporate accounts, and then utilize them to infiltrate systems via platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. A null result from a stealer-log query does not rule out this type of initial access. Organizations should continue monitoring for relevant activity, confirm all associated corporate domains, and conduct proactive credential hygiene checks, including password rotation and multi-factor authentication reviews, rather than relying solely on the absence of evidence in a limited dataset as a sign of being unaffected.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.