Ransomware victim disclosure
← All victimsANC Legal Office
listed as A** L** Office · Claimed by Nightspire · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Austria
- Sector
- Business Services
- Listed on leak site
- Feb 14, 2026
About the victim
AI dossier — public-source company profileANC Legal Office is an international law firm headquartered in Vienna, Austria, operating under a 'one-stop-shop' advisory concept. Its practice areas include corporate and commercial law, M&A, labour law, e-commerce, compliance and due diligence, intellectual property, and immigration law. The firm serves clients across Europe, Latin America, and the Middle East, offering services in eight languages.
- Industry
- Legal Services (International Law Firm)
- Address
- Vienna, Austria
Attack summary
Severity: high — The victim is a law firm handling sensitive client matters including M&A, compliance/due diligence, immigration, and contracts. A law firm breach typically involves privileged communications and confidential business data. The disclosure status is 'data_published', indicating exfiltration and likely publication of sensitive legal and client records, even though the specific proof count is unavailable.The Nightspire ransomware group claims to have attacked ANC Legal Office and lists the disclosure status as 'data_published'; however, the leak post content is currently unavailable, so specific claims about encryption or exfiltration cannot be confirmed from the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Contract documents
- Corporate and commercial records
- Immigration and compliance documentation
- Potentially privileged attorney-client communications
What the group claims
Data is not available now.
Sources
- Victim siteanc-legal.com
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

