Ransomware victim disclosure
← All victimsMogren, Glessner & Ahrens, P.S.
Claimed by Pear · listed 2 days ago
Status timeline
- ListedAug 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Pear
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 22, 2026
About the victim
AI dossier — public-source company profileMogren, Glessner & Ahrens, P.S. is a full-service law firm based in the Seattle/King County, Washington area, serving clients since 1942. The firm specializes in family law and divorce, with additional practices in estate planning, probate, criminal defense, personal injury, and adoption.
- Industry
- Legal Services
- Founded
- 1942
Attack summary
Severity: critical — Confirmed exfiltration of client privileged and confidential legal data, PII/PHI at scale, police reports, court files, and evidence—all highly sensitive and regulated information. Law firm data breaches expose attorney-client privilege and sensitive personal/health information.The group claims to have exfiltrated legal and business records from the firm, including client privileged and confidential data, financial records, HR documents, PII and PHI records, police reports, court files, and email correspondence.
Data the group says was taken
AI dossier — extracted from the leak post- Financials
- HR records
- Partners' and vendors' data
- Clients' privileged and confidential data
- PII and PHI records
- Police reports and court files
- Exhibits and evidence
- Email correspondence and mailboxes
What the group claims
Services in family law
The leak post
captured from the group's site| | | | | | **Mogren, Glessner & Ahrens, P.S. ** Law Firms & Legal Services Financials, HR, Partners’ and Vendors’ Data, Clients’ Privileged & Confidential Data, PII & PHI Records, Police Reports & Court Files, Exhibits & Evidences, Mailboxes & Email Correspondence, etc. | | --- | | | | | |
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

