Ransomware victim disclosure
← All victimsMoore & Tibbits
listed as moore-tibbits.co.uk · Claimed by Threeam · listed 2 years ago
Status timeline
- ListedFeb 27, 2024
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Business Services
- Listed on leak site
- Feb 27, 2024
About the victim
AI dossier — public-source company profileMoore & Tibbits is a solicitors' firm based in Warwick with over 190 years of legal service. They offer personal legal services (conveyancing, family law, wills/probate, court of protection), business services (commercial property, employment law, business disputes), and community care/NHS continuing healthcare funding advice. They hold Law Society Conveyancing Quality Scheme membership and LEXCEL practice management accreditation.
- Industry
- Legal Services
- Address
- Westgate House, Warwick, United Kingdom
- Founded
- 1836
Attack summary
Severity: medium — The firm handles sensitive personal and legal data (court of protection matters, health information, financial records). However, the leak post provides no evidence of actual exfiltration, no proof files or screenshots are advertised, and no data size is stated. The group has only republished the firm's own website content. Without published proof, the claim remains unverified.The Threeam group claims to have attacked Moore & Tibbits and compromised their systems. The leak post provides no specific detail on what data was exfiltrated or the scope of encryption; the post consists only of the company description copied from their public website.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal records
- Personal data (names, addresses, contact details)
- Financial information
- Court of Protection case files
- Health & welfare information
- Conveyancing documentation
What the group claims
Moore & Tibbits is a well respected law firm, with more than 188 years of legal service in the centre of Warwick. Our reputation is based on a reliable, flexible, personal, first class service combined with the use of modern technology which...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

