Ransomware victim disclosure
← All victimsCorona Law Firm, P.A.
listed as coronapa.com · Claimed by Incransom · listed 2 months ago
Status timeline
- ListedApr 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Apr 3, 2026
About the victim
AI dossier — public-source company profileCorona Law Firm, P.A. is a full-service law firm established in 1997 and based in Miami, Florida, serving Miami-Dade, Broward County, and surrounding South Florida communities. The firm handles a broad range of practice areas including personal injury, immigration, criminal defense, family law, bankruptcy, civil litigation, estate planning, and real estate. The firm is bilingual, serving both English- and Spanish-speaking clients.
- Industry
- Legal Services – Personal Injury & General Practice Law Firm
- Address
- 6700 SW 38th St, Miami, FL 33155
- Founded
- 1997
Attack summary
Severity: critical — A law firm holds highly sensitive regulated data including client PII, privileged legal communications, immigration records, criminal defense files, financial/bankruptcy records, and estate documents. Confirmed data publication by ransomware group exposes clients to serious legal, financial, and personal harm at scale.The incransom group claims to have attacked Corona Law Firm, P.A. and has disclosed data (status: data_published), indicating exfiltration of firm and client data. No specific ransom amount or precise data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Personal injury case records
- Immigration case documents
- Criminal defense records
- Family law records
- Bankruptcy filings
- Estate planning and probate documents
- Client personally identifiable information (PII)
What the group claims
Corona Law Firm is a proud excellent client service and skillful representation. Established in 1997, well-known in the Florida legal community.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

