Ransomware victim disclosure
← All victimsOrrick, Herrington & Sutcliffe
Claimed by SilentRansomGroup · listed 4 months ago
Status timeline
- ListedFeb 23, 2026
- Data leakeddate unknown
At a glance
- Group
- SilentRansomGroup
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileOrrick, Herrington & Sutcliffe is a global law firm founded in 1863 and headquartered in San Francisco, California. The firm advises clients across technology, energy, finance, and other sectors, with offices in major cities across the Americas, Europe, and Asia. It is consistently ranked among the largest and most prominent law firms in the United States.
- Industry
- Legal Services (Law Firm)
- Address
- 405 Howard Street, San Francisco, California 94105, United States
- Employees
- 1000-5000
- Founded
- 1863
Attack summary
Severity: critical — Orrick is a major law firm handling highly sensitive attorney-client privileged communications, regulated PII for potentially thousands of clients, and confidential legal strategies. Data publication by the group represents confirmed exfiltration of regulated and highly sensitive data at scale, including information belonging to numerous third-party clients across multiple industries.SilentRansomGroup claims to have exfiltrated data from Orrick, Herrington & Sutcliffe and has published the data. The disclosed status indicates data has been released, though the specific volume and ransom demand were not stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Client legal files
- Attorney-client privileged communications
- Financial records
- Personally identifiable information (PII)
- Employee records
- Litigation documents
- Contracts and agreements
What the group claims
Founded in 1963 and headquartered in San Francisco, California, Orrick, Herrington & Sutcliffe is a co…
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

