Ransomware victim disclosure
← All victimsIshbia & Gagleard, P.C.
Claimed by AUR0RA · listed 43 minutes ago
Status timeline
- ListedSep 30, 2026
- Data leakeddate unknown
At a glance
- Group
- AUR0RA
- Status
- Data leaked
- Country
- United States
- Sector
- Legal
- Listed on leak site
- Sep 30, 2026
- Data size
- 5.7 GB
- Records
- 360+ client/matter folders, 25+ SSNs, 55+ employee files, 100+ tax returns, 11 email archive files
About the victim
AI dossier — public-source company profileIshbia & Gagleard, P.C. is a boutique law firm founded in 1999 in Birmingham, Michigan, serving high-net-worth individuals and closely held entities. The firm practises real estate, corporate, estate planning, personal injury, medical malpractice, and commercial litigation.
- Industry
- Legal Services
- Address
- Birmingham, Michigan, US
- Founded
- 1999
Attack summary
Severity: critical — Confirmed exfiltration of attorney-client privileged communications at scale, full SSNs and PII for 25+ individuals, Protected Health Information from named hospitals, tax returns spanning 21 years, and materials related to a publicly-traded company CEO. Multiple categories of regulated and highly sensitive data across legal, financial, and medical domains.AUR0RA claims to have exfiltrated the complete attorney-client privilege corpus spanning 360+ client matters, including litigation strategy memos, settlement agreements, and deposition notes. The group also published full Social Security Numbers for 25+ individuals, Protected Health Information from multiple hospitals, 55+ employee files from a sexual health clinic client, 100+ client tax returns (2003–2024), and 11 years of unfiltered attorney email archives (PST/OST).
Data the group says was taken
AI dossier — extracted from the leak post- Attorney-client privilege documents (litigation strategy, settlements, case assessments)
- Full Social Security Numbers (25+ individuals, including scanned cards)
- Protected Health Information (hospital admission records)
- Employee files from sexual health clinic client (55+ files with SSNs)
- Client tax returns (100+, spanning 2003–2024)
- Email archives (11 PST/OST files)
- Personal legal matters of Mat Ishbia (CEO of publicly-traded UWM Holdings)
What the group claims
Boutique law firm in Birmingham, Michigan, founded in 1999 by Jeffrey A. Ishbia and Michael A. Gagleard. Practises real estate, corporate, estate planning, personal injury, medical malpractice, and commercial litigation for high-net-worth individuals and closely held entities.
The leak post
captured from the group's site[ Ishbia & Gagleard, P.C. — a boutique law firm in Birmingham, Michigan, founded in 1999 by Jeffrey A. Ishbia and Michael A. Gagleard. The firm practises real estate, corporate, estate planning, personal injury, medical malpractice, and commercial litigation for high-net-worth individuals and closely held entities. The exposed material includes: 360+ client/matter folders — the complete attorney-client privilege corpus: litigation strategy memos, settlement agreements, case assessments, deposition notes, correspondence with opposing counsel. <redacted> <redacted> Full Social Security Numbers for 25+ identified individuals — trust beneficiaries, family members, employees of client businesses, and a scanned Social Security card. Protected Health Information — hospital admission records from Oakwood Hospital, University of Michigan Hospital, and William Beaumont Hospital. Also: 55+ employee files from a sexual health clinic client with SSN searches and scanned SS cards. 100+ client tax returns spanning 2003–2024, each containing SSNs, EINs, and income data. 11 email archive files (PST/OST) containing years of unfiltered attorney correspondence. Personal legal matters of Mat Ishbia — C…
Data the group says was taken
- attorney-client privileged documents
- litigation strategy memos
- settlement agreements
- deposition notes
- Social Security Numbers
- Protected Health Information
- hospital records
- employee files
- tax returns
- email archives (PST/OST)
- personal legal matters
Screenshot of the leak post

Sources
Source
Indexed 43 minutes agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

