Ransomware victim disclosure
← All victimsLaw Offices of Rakesh Mehrotra
listed as ImmigrationOnline · Claimed by TRIPLE X · listed 3 hours ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- TRIPLE X
- Status
- Data leaked
- Sector
- Legal/Immigration
- Listed on leak site
- Aug 10, 2026
- Data size
- 1.5 TB
- Records
- 24,900 passport files
About the victim
AI dossier — public-source company profileLaw Offices of Rakesh Mehrotra is an immigration law firm based in the United States (phone: 703-230-6800 indicates Virginia area) specializing in visa, green card, and immigration/nationality law for over 30 years. The firm represents individuals and companies across industries including IT, biotech, financial services, and healthcare throughout the U.S. and internationally.
- Industry
- Immigration Law
- Founded
- 1994
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII including passports, SSNs, financial records, and attorney-client privileged communications. Law firm clients typically include vulnerable populations (visa applicants, immigrants). Regulatory obligations (legal privilege, client confidentiality) severely violated.TRIPLE X claims to have exfiltrated approximately 1.5 TB of data from ImmigrationOnline/Law Offices of Rakesh Mehrotra, citing server overload and lack of security updates. The group alleges extraction of client passports, tax forms, ID cards, driver's licenses, confidential court cases, financial/banking information, and private attorney-client correspondence.
Data the group says was taken
AI dossier — extracted from the leak post- Passport files (24,900 alleged)
- Tax forms (employees and clients)
- ID cards and driver's licenses
- Court cases and legal documents
- Financial and banking information
- Social Security numbers
- Home addresses and contact information
- Attorney-client correspondence and emails
- Client account details and contracts
What the group claims
Immigration law firm with server overload and lack of updates exposing sensitive client data including financial, tax, and personal documents.
The leak post
captured from the group's site1 terabytes of people's data https://henshawlawak.com/ Henshaw Law, Despite repeated recommendations, no action was taken. The problem remains unresolved, the system is full of bugs, people's documents are at risk, and they won't take any responsibility. Multiple people could commit suicide, what important information has been leaked about them, and who is responsible for why the recommendations weren't taken seriously. what data will leak ? -Personal family files -Passports and licenses -Court ruling and public complaint forms -Documents scans -Forms and emails scans sample : Full download data link : ## Bank of Baroda bigest indian bank bankofbaroda.bank.in 1 terabytes of people's data https://bankofbaroda.bank.in/ Imagine I'm going to the bank to open an account. and due to the bank's weak password and mistake, my personal data should be leaked, and fraudsters should use my resources in scam people and verify exchangers shops and fraudulent schemes. How many years should I be held responsible to the police and for complaints? its fair ? Yes, approximately 100 to 300 thousand forms from people who had given their personal information/documents to the bank for opening accounts f…
Data the group says was taken
- Passport files
- Tax forms
- ID cards
- Driver's licenses
- Confidential court cases
- Financial and banking information
- Intellectual property documents
- Private correspondence
- Emails
- Social Security numbers
- Home addresses
- Banking details
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

