Ransomware victim disclosure
← All victimsMartin Cukjati & Tom, LLP
listed as mcfirm.com · Claimed by Incransom · listed 3 months ago
Status timeline
- ListedMar 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 2, 2026
About the victim
AI dossier — public-source company profileMartin Cukjati & Tom, LLP is a full-service law firm based in the United States with over 75 years of combined legal experience. The firm specializes in high-stakes litigation representing both individuals and businesses. It operates with a deliberately limited caseload to provide focused attention to a select client base.
- Industry
- Legal Services
Attack summary
Severity: high — The data_published status confirms exfiltration and public release of data from a law firm, which inherently holds privileged attorney-client communications, sensitive personal and business litigation records, and potentially financial data — constituting significant sensitive business and personal data exposure.The Incransom group claims to have attacked Martin Cukjati & Tom, LLP and has published data from the firm, as indicated by the 'data_published' disclosure status. No specific details on encryption or the precise nature of exfiltrated data are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Case documentation
- Business records
- Potentially privileged attorney-client communications
What the group claims
Martin Cukjati & Tom, LLP is a full service law firm with over 75 years of combined legal experience representing people and businesses in high-stakes litigation. The cornerstone of our success is limiting our case load and dedicating ourselves to serving a select few clients, making sure your case receives the attention it deserves. This allows us to focus on our clients, and work towards achieving the best possible outcome.
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

