Key Takeaways

  • Anubis alleges it stole 82 GB of data from Gaedke & Partner Steuerberatung GmbH.
  • The claim includes a threat to publish the material within 1 to 2 days.
  • Neither Gaedke & Partner Steuerberatung GmbH nor authorities have independently confirmed the incident.

FalconFeeds.io reported on September 22, 2026, that the Anubis ransomware group had allegedly compromised Gaedke & Partner Steuerberatung GmbH, an Austria-based tax consulting and accounting business. According to the threat-intelligence post, Anubis claimed to have obtained 82 GB of data and threatened to publish it within 1 to 2 days.

The allegation remains unverified. Gaedke & Partner Steuerberatung GmbH has not publicly confirmed the reported compromise, the volume or nature of any affected data, or whether its systems experienced operational disruption. Authorities have not independently validated the Anubis claim either. That distinction matters because ransomware leak sites and related announcements are controlled by criminal operators, whose statements can be incomplete, exaggerated, or strategically timed.

Other incident-tracking services have begun recording the allegation. Breachsense listed the reported Gaedke & Partner Steuerberatung GmbH incident on September 23, while retaining the attribution to Anubis. Such listings can provide early visibility, but they do not substitute for forensic findings or an official disclosure. At this stage, 82 GB is an attacker-supplied figure rather than an independently established measure of exposure.

Still, the target profile is notable. Tax advisers and accounting practices can hold concentrated collections of client correspondence, financial documents, payroll information, identity records, contracts, and access credentials. An intrusion into one professional-services provider may therefore create risks extending beyond its own operations. Clients may face follow-on phishing, impersonation, invoice fraud, or attempts to exploit information found in stolen files. Whether any of those risks apply here depends on what, if anything, was actually taken.

Encryption is no longer the only pressure point in many ransomware cases. Attackers increasingly copy data before demanding payment, then use threatened publication as additional leverage. A sector7 summary of the BSI Lagebericht 2025 noted that Germany’s BSI recorded about 950 ransomware incidents from July 2024 through June 2025, with approximately 80% involving small and medium-sized enterprises. The BSI also found that exfiltration or threatened publication accompanied most incidents.

Germany’s figures do not establish what happened in Austria, but they illustrate the wider regional environment facing professional-services businesses. ENISA’s 2025 threat landscape similarly identified ransomware as the most impactful cyber threat after examining 4,875 incidents disclosed between July 2024 and June 2025. Meanwhile, Bitkom reported that 34% of surveyed German companies had experienced ransomware-related damage during the preceding year. Groups including Anubis, Akira, and Qilin have all been associated with contemporary ransomware activity in Europe.

What should clients watch for next? The most informative developments would include a statement from Gaedke & Partner Steuerberatung GmbH, notification to affected customers, confirmation from an Austrian authority, or evidence that Anubis published sample files. Even samples require careful validation because criminals can recycle documents, mislabel victims, or combine material from different sources.

For incident responders, the immediate priorities typically include preserving forensic evidence, isolating affected assets, reviewing identity and remote-access activity, rotating potentially exposed credentials, and determining whether data left the environment. Regulatory deadlines can move quickly. As Noerr’s NIS2 briefing explains, covered EU entities may face a 24-hour early warning and a 72-hour incident notification, depending on sector, organizational scope, and the incident’s significance. Until Gaedke & Partner Steuerberatung GmbH or authorities provide further evidence, the Anubis posting should be treated as a serious but unconfirmed ransomware allegation.