Ransomware victim disclosure
← All victimsO'Farrell
Claimed by crypto24 · listed 3 days ago
Status timeline
- Listed
May 18, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileO'Farrell is a leading full-service law firm based in Argentina, described as having the longest track record in the country. The firm operates in the legal sector providing comprehensive legal services. No further detail is available from the public site.
- Industry
- Legal Services – Full-Service Law Firm
Attack summary
Severity: high — A full-service law firm holds highly sensitive client communications, privileged legal documents, and potentially regulated PII; exfiltration of such data from a legal practice constitutes significant exposure of confidential and potentially regulated information, warranting a high severity rating even without a confirmed exact volume for this specific victim.The group crypto24 claims to have successfully acquired and exfiltrated 700GB of proprietary data from victims listed in the same post; the specific volume attributable to O'Farrell alone is not stated, but the firm is listed among confirmed exfiltration targets.
Data the group says was taken
AI dossier — extracted from the leak post- Proprietary business data
- Legal case files (inferred)
- Client records (inferred)
What the group claims
A leading full service law firm in Argentina, with the longest track record.
The leak post
captured from the group's site## Qatar Biomedical Research Institute (QBRI) QBRI is a premier research institute under Hamad Bin Khalifa University focused ... Rowad Modern Engineering (RME) is a leading Egyptian construction conglomerate s ... We have successfully acquired and exfiltrated 700GB of proprietary data from the ... Founded in 1993 in Monterrey, Mexico, Katcon is a leading global Tier 1 supplier ... ActionPower is an AI innovation company that automates documentation through 'da ... O'Farrell is a leading full service law firm in Argentina, with the longest trac ...
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
