Ransomware victim disclosure
← All victimsOasis Legal Group
Claimed by Everest · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Everest
- Status
- Data leaked
- Country
- United States
- Sector
- Professional Services
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileOasis Legal Group is a multi-office law firm specializing in business, family, and immigration law. Operating across six locations in Wisconsin, Florida, Texas, and Michigan, the firm represents approximately 10 attorneys and serves clients nationwide in immigration matters and regionally in business and family law.
- Industry
- Legal Services - Immigration, Business & Family Law
- Address
- Multiple locations: Madison (2450 Rimrock Rd, Suite 203, Madison, WI 53713); Milwaukee (1433 North Water Street, Suite 400 & 500, Milwaukee, WI 53202); Miami (8333 NW 53rd Street, Suite 450, Doral, FL 33166); Katy (2717 Commercial Ctr Blvd, Suite E200, Katy, TX 77494); Grand Rapids (250 Monroe Ave. NW, Suite 400, Grand Rapids, MI 49503); Orlando (6900 Tavistock Lakes Blvd, Suite 400, Orlando, FL 32827)
- Employees
- 51-200
Attack summary
Severity: medium — Law firm breach with likely access to privileged client information, case files, and legal work product. However, no proof files or screenshots are advertised, no data size is disclosed, and no specific details of exfiltration are provided. Severity is elevated due to the sensitive nature of legal/immigration client data but tempered by lack of published proof or data inventory details.The everest group claims to have compromised Oasis Legal Group. The leak post provided contains no substantive details regarding what data was exfiltrated, encrypted, or the scope of the attack.
Data the group says was taken
AI dossier — extracted from the leak post- Client records
- Attorney work product
- Case files
- Confidential legal documents
Original description
AI-summarised, not from the leak postN/A
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

