Ransomware victim disclosure
← All victimsWren Law Firm
listed as WRENLAWFIRM.COM · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Jan 25, 2026
About the victim
AI dossier — public-source company profileWren Law Firm is a personal injury and disability law firm based in Little Rock, Arkansas, founded in 1997. The firm specializes in Social Security Disability, Personal Injury, Workers' Compensation, and Employment Law, serving injured individuals throughout Arkansas. Led by attorney Daniel E. Wren, the firm offers free consultations and claims thousands of successful client settlements.
- Industry
- Personal Injury & Disability Law
- Address
- Little Rock, Arkansas, United States
- Founded
- 1997
Attack summary
Severity: critical — Law firm data inherently contains highly sensitive regulated PII including medical records, financial information, Social Security numbers, and confidential legal communications for vulnerable individuals (disability claimants, injured workers, accident victims). Clop's 'data_published' status indicates exfiltrated data has been released publicly.Clop ransomware group claims to have compromised Wren Law Firm and has listed the victim with a 'data_published' status, indicating exfiltration and publication of data. The leak post itself contained no substantive detail, but the disclosed status suggests client and legal case data may have been exfiltrated and published.
Data the group says was taken
AI dossier — extracted from the leak post- Client personal information
- Legal case files
- Social Security Disability records
- Workers' compensation case data
- Personal injury case records
- Employment law documents
- Financial/settlement records
Original description
AI-summarised, not from the leak post"N/A"
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

