Ransomware victim disclosure
← All victimsMartin, Cukjati & Tom, LLP
Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMar 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 2, 2026
About the victim
AI dossier — public-source company profileMartin, Cukjati & Tom, LLP is a full-service law firm based in the United States with over 75 years of combined legal experience. The firm specializes in high-stakes litigation for both individuals and businesses, operating with a deliberately limited caseload to provide focused client representation.
- Industry
- Legal Services – Litigation Law Firm
Attack summary
Severity: high — Data has been published by the threat actor from a law firm handling high-stakes litigation; attorney-client privileged communications and sensitive client PII are almost certainly involved, representing significant regulated and confidential data exposure even without a stated volume.The Incransom group claims to have attacked Martin, Cukjati & Tom, LLP and has published data (disclosed status: data_published), suggesting exfiltration of firm and client data; no specific ransom amount or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Case documents
- Attorney-client correspondence
- Business records
- Personally identifiable information (clients/staff)
What the group claims
Martin Cukjati & Tom, LLP is a full service law firm with over 75 years of combined legal experience representing people and businesses in high-stakes litigation. The cornerstone of our success is limiting our case load and dedicating ourselves to serving a select few clients, making sure your case receives the attention it deserves. This allows us to focus on our clients, and work towards achieving the best possible outcome.
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

