Ransomware victim disclosure
← All victimsSwartz Campbell
Claimed by Interlock · listed 5 months ago
Status timeline
- Listed
Dec 22, 2025
- Data leaked
At a glance
- Group
- Interlock
- Status
- Data leaked
- Country
- United States
- Sector
- Not Found
- Listed on leak site
- Dec 22, 2025
About the victim
AI dossier — public-source company profileSwartz Campbell LLC is a multi-location law firm headquartered in Philadelphia, Pennsylvania, with offices across the East Coast. Founded in 1921, the firm specializes in areas including class action litigation, employment law, medical malpractice, and divorce. It operates as a full-service civil defense and litigation practice serving clients across multiple states.
- Industry
- Legal Services (Law Firm)
- Address
- Philadelphia, Pennsylvania, United States
- Founded
- 1921
Attack summary
Severity: critical — A law firm handling medical malpractice, employment, class action, and divorce cases holds highly sensitive attorney-client privileged communications and PII at scale. Data publication by the threat actor confirms exfiltration of regulated and sensitive personal and legal data affecting potentially many clients.The Interlock ransomware group claims to have exfiltrated data from Swartz Campbell LLC and has published the data. No ransom amount was stated and no data size was specified, but the disclosed status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Case records
- Personally identifiable information (PII)
- Medical malpractice case documents
- Employment litigation records
- Divorce and family law records
- Attorney-client privileged communications
What the group claims
Swartz Campbell LLC is a law firm with multiple locations across the East Coast specializing in areas including class action, employment, medical malpractice, and divorce. The law firm was founded in 1921 and is headquartered in Philadelphia, Pennsylvania.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
