Ransomware victim disclosure
← All victimsMartin, Cukjati & Tom, LLP
Claimed by INC Ransom · listed 3 months ago
Status timeline
- ListedMar 2, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 2, 2026
About the victim
AI dossier — public-source company profileMartin, Cukjati & Tom, LLP is a full-service law firm based in the United States with over 75 years of combined legal experience. The firm specializes in high-stakes litigation for both individuals and businesses, deliberately limiting its caseload to provide focused, personalized legal representation.
- Industry
- Legal Services – Litigation Law Firm
- Employees
- 1-10
Attack summary
Severity: critical — A litigation law firm handles highly sensitive attorney-client privileged communications, PII, financial records, and confidential case strategies for clients in high-stakes matters. Data publication by INC Ransom of such records constitutes a critical exposure of regulated, privileged, and sensitive personal and legal data at scale.INC Ransom claims to have compromised Martin, Cukjati & Tom, LLP and has published data, suggesting exfiltration of firm and client records; the disclosure status is listed as data_published indicating stolen data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Case documentation
- Attorney-client correspondence
- Business records
- Personally identifiable information (PII) of clients
What the group claims
Martin Cukjati & Tom, LLP is a full service law firm with over 75 years of combined legal experience representing people and businesses in high-stakes litigation. The cornerstone of our success is limiting our case load and dedicating ourselves to serving a select few clients, making sure your case receives the attention it deserves. This allows us to focus on our clients, and work towards achieving the best possible outcome.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

