Ransomware victim disclosure
← All victimsMarshall Dennehey
Claimed by SilentRansomGroup · listed 8 days ago
Status timeline
- Listed
May 12, 2026
- Data leaked
At a glance
- Group
- SilentRansomGroup
- Status
- Data leaked
- Country
- US
- Sector
- Business Services
- Listed on leak site
- May 12, 2026
About the victim
AI dossier — public-source company profileMarshall Dennehey is a large US defense litigation law firm founded in 1962 and headquartered in Philadelphia, Pennsylvania. The firm specializes in civil defense representation across multiple practice areas including insurance defense, professional liability, and workers' compensation. It operates numerous offices across the eastern United States and employs hundreds of attorneys and staff.
- Industry
- Legal Services & Defense Litigation
- Address
- 2000 Market Street, Philadelphia, PA 19103, United States
- Employees
- 500-1000
- Founded
- 1962
Attack summary
Severity: critical — Marshall Dennehey is a major law firm whose data inherently contains attorney-client privileged communications, PII of clients and staff at scale, and sensitive litigation records. The disclosed status is 'data_published', confirming actual exfiltration and public release of highly sensitive regulated data, and the failed $100,000 negotiation confirms the threat actor possessed genuinely sensitive material.SilentRansomGroup claims to have exfiltrated data from Marshall Dennehey and published the data after the firm allegedly offered $100,000 to prevent publication, implying a failed ransom negotiation resulting in full data release.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Attorney-client privileged communications
- Case records and litigation documents
- Employee personal information
- Financial records
- Internal communications
What the group claims
They offered $100,000 to keep the data from being published. Founded in 1962 and headquartered in Phil…
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
