Vendor dossier // crowe.com
Also known as Crowe Global · Crowe LLP · Crowe Horwath International
New York, United States · Est. 1915 · 40,000+ employees
Key people
Last updated: Aug 12, 2026, 01:47 PM · Partial / limited public data
Conditional
Crowe is a major professional services firm handling sensitive financial and client data. It experienced a confirmed data breach in January 2024 involving the… Limited public data - verify before relying.
Risk Tier
Risk Score
Confidence
partial
Material Incidents
Crowe is a multinational professional services network headquartered in New York, United States, with a Swiss Verein structure registered in Zurich [1]. It is the 8th largest global accounting network by revenue, comprising over 220 member firms with more than 40,000 employees across 150 countries [1]. The US entity, Crowe LLP, maintains its national headquarters in Chicago, Illinois [4]. The firm provides audit, tax, advisory, and consulting services to a wide range of industries including fintech [8]. In 2026, Crowe accelerated its growth trajectory with an investment from KKR.
Crowe offers professional services rather than a single software product, but has launched 'Crowe Studio,' a business unit focused on AI-native capacity and platform-style execution to help clients scale. The firm provides risk consulting, performance consulting, and secure information exchange services [3]. It also offers SOC reporting services to evaluate how clients manage data based on AICPA Trust Services Criteria. Crowe partners with technology providers like Microsoft, Mendix, and Alteryx to deliver solutions [11].
Crowe publishes an Information Security Statement dated July 1, 2025, committing to confidentiality, integrity, and availability of personal data in compliance with GDPR and Data Privacy Frameworks. The firm offers SOC 2 and SOC for Cybersecurity reporting services to clients. However, Crowe experienced a data breach on January 30, 2024, attributed to the LockBit threat actor, affecting crowe.com.za. Additionally, Crowe confirmed it was impacted by the Cl0p MOVEit breach, though the impact was described as limited. These incidents indicate exposure to significant cyber threats.
Evidence class: observed by us
Deterministic outside-in checks run directly against the vendor's domain - not inferred from press or marketing pages.
Last observed: Aug 12, 2026, 01:47 PM
Public status page
No public status page detected
TLS certificate
Certificate expires in 78 days
Security headers
5/6 security headers present
Email authentication (SPF / DMARC)
How this vendor uses AI/ML with customer data - model providers, training stance, subprocessors, and relevant DPA language when publicly documented.
AI exposure tier: Moderate AI Exposure
Crowe offers AI-native capacity through Crowe Studio and provides AI solutions to clients [13] [14]. The firm partners with Alteryx for AI-ready automation [16]. However, specific details about AI data practices, such as whether customer data is used for training models, are not publicly disclosed. The firm's Information Security Statement covers general data protection but does not specifically address AI-specific risks [26].
[funding] KKR Investment
Crowe accelerated long-term growth trajectory with an investment from KKR in June 2026 [19].
Jun 12, 2026, 12:00 AM · Source
[breach] LockBit Ransomware Incident
Crowe's South African entity (crowe.com.za) experienced a data breach attributed to the LockBit threat actor on January 30, 2024.
Jan 30, 2024, 12:00 AM · Source
[breach] Crowe Data Breach
Crowe experienced a data breach on January 30, 2024, attributed to the LockBit threat actor, affecting crowe.com.za [17].
Jan 30, 2024, 12:00 AM · Source
[breach] MOVEit Transfer Impact
Crowe confirmed limited impact from the Cl0p MOVEit transfer breach affecting financial services companies.
- · Source
Fourth parties this vendor relies on - subprocessors, infrastructure, and integrations surfaced from public sources.
Vendors offering a similar product or service - for side-by-side comparison, not a ranking.
EY
ey.com
Internal audit and professional services alternative
Deloitte
deloitte.com
Internal audit and professional services alternative
KPMG
kpmg.com
Internal audit and professional services alternative
Grant Thornton
grantthornton.com
Internal audit and professional services alternative
In 2026, Crowe announced an investment from KKR to accelerate long-term growth. The firm launched Crowe Studio in October 2025 to disrupt legacy professional services models with AI-native solutions. Crowe reported double-digit growth for 2025. The firm has also appointed Josh Cole as Growth Leader to strengthen cross-network collaboration. Crowe continues to expand its AI capabilities, partnering with Alteryx for AI-ready automation.
Content in this section is vendor-supplied and does not alter Vendorisk.ai's risk tier or evaluation.
32 sources · Generated Aug 12, 2026, 01:47 PM
Every verdict stores the public sources retrieved for this run. Read our methodology.
Input sources · retrieved Aug 12, 2026, 01:47 PM
Crowe Global
Company
Leadership and executive team | Crowe
Company
Crowe history | Crowe
Company
AI-generated assessment based on publicly available sources. Verify critical findings before contractual reliance. Analysis is advisory, not a compliance attestation, and is subject to data availability.
Years in Business
111 yrs
Crowe is a major professional services firm handling sensitive financial and client data. It experienced a confirmed data breach in January 2024 involving the LockBit threat actor and was impacted by the widespread Cl0p MOVEit transfer breach. While the firm confirms limited impact for the MOVEit incident, the presence of recent security incidents involving sensitive data handling elevates the risk profile beyond Low Risk. Public security posture disclosures are limited to general statements and service offerings rather than detailed third-party audit reports for their own infrastructure.
DNS presence
Certificate transparency exposure
crt.sh unavailable
Breach database (HIBP)
HIBP_API_KEY not configured
[breach] Crowe MOVEit Impact
Crowe confirmed it was impacted by the Cl0p MOVEit breach, with limited impact reported [18].
- · Source
Profile of Crowe Global and Crowe LLP | Umbrex
Company
Crowe - Smart decisions. Lasting value.
Company
Purpose and values | Crowe
Company
Crowe Global | Crowe Global
Company
Crowe: Audit, Tax, Advisory, and Consulting Services
Company
Compare Crowe ERP Systems
Product
Top Crowe Internal Audit Alternatives & Competitors 2026 | Gartner Peer Insights
Product
Alliances | Crowe
Product
Crowe Global - Company Profile Report | IBISWorld
Product
Crowe Studio | Crowe
Product
Artificial intelligence solutions | Crowe
Product
SOC reporting services | Crowe
Security & risk
[PDF] Information Security Statement - Crowe
Security & risk
New Trust Services Criteria for SOC 2 Reporting | Crowe
Security & risk
Pinecone Trust and Security Center | Powered by SafeBase
Security & risk
3E | Trust Center
Security & risk
Harvey Trust Center | Powered by SafeBase
Security & risk
NETSCOUT Trust Center | Powered by SafeBase
Security & risk
Cyber Security and IT Governance | Crowe UAE
Security & risk
News | Crowe Global
News
News | Crowe
News
Crowe Data Breach in 2024
News
Crowe accounting firm confirms MOVEit impact limited | Cybernews
News
Crowe accelerates long-term growth trajectory with investment from KKR | Crowe
News
Crowe Secure Information Exchange | Crowe
News
Crowe launches Crowe Studio to disrupt professional services model | Crowe
News
Insights | Crowe
News
Crowe: Audit, Tax, Advisory, and Consulting Services
News
Quarterly accounting and financial reporting developments | Crowe
News