Ransomware victim disclosure
← All victimsTaylor Oballa Murray Leyland LLP
listed as TOMLLAWYERS.COM · Claimed by Clop · listed 5 months ago
Status timeline
- ListedJan 25, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileTaylor Oballa Murray Leyland LLP is an entertainment and media law firm based in Toronto, Ontario, also servicing Vancouver, BC and Canada. Founded in 2006, the firm represents musicians, record companies, film and television producers, songwriters, publishers, actors, writers, directors, and other creative industry clients. The firm handles transactional matters, copyright, trademark, privacy, and regulatory compliance across the entertainment and media sectors.
- Industry
- Entertainment & Media Law
- Address
- Toronto, Ontario, Canada
- Employees
- 1-10
- Founded
- 2006
Attack summary
Severity: high — As a law firm, Taylor Oballa Murray Leyland LLP holds privileged and confidential client data including contracts, personal information of artists and businesses, financial arrangements, and sensitive legal communications. Clop's disclosure status is 'data_published', indicating actual exfiltration and publication of potentially sensitive and privileged legal data affecting numerous third-party clients.The Clop ransomware group claims to have compromised Taylor Oballa Murray Leyland LLP and has listed the firm with a 'data_published' disclosure status, indicating data has been published or made available. The leak post itself provided no specific detail on the volume or nature of data exfiltrated.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Contract documents
- Correspondence
- Personal identifying information of clients
- Intellectual property agreements
- Corporate records
- Financial records
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

