Ransomware victim disclosure
← All victimsNapolin Law Firm
Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMar 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Mar 4, 2026
About the victim
AI dossier — public-source company profileNapolin Law Firm is a California-based personal injury law practice led by attorney Alexander D. Napolin. The firm operates exclusively on a plaintiff-side basis, representing injured individuals and never defending insurance companies or corporations. It is described as a top-rated practice focused solely on personal injury advocacy.
- Industry
- Personal Injury Law
Attack summary
Severity: critical — A plaintiff-side personal injury law firm almost certainly holds highly sensitive regulated data including client PII, medical records, and privileged legal communications at scale. Data has been confirmed published, making this a critical-severity disclosure.The Incransom group claims to have compromised Napolin Law Firm and has published data ('data_published' status), though specific claims of encryption or exfiltration volume are not detailed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client personal injury case files
- Client PII (names, contact details)
- Medical records and injury documentation
- Legal correspondence and case strategies
- Financial and settlement records
What the group claims
Alexander D. Napolin is a top-rated, 100% plaintiff-side California personal injury attorney, exclusively advocating for injured individuals – never defending insurance companies or corporations.
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

