Ransomware victim disclosure
← All victimsUnknown (Law Firm - US)
Claimed by Rhysida · listed 3 hours ago
Status timeline
- ListedSep 23, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Sector
- Legal Services
- Listed on leak site
- Sep 23, 2026
- Data size
- 710.6 GB
- Records
- 338,542 files
About the victim
AI dossier — public-source company profileA US-based law firm operating a practice-management system with ~10,000 active matters, client trust accounts, and partnerships. The firm handles insurance defense, mass litigation, and settlement administration across multiple practice areas.
- Industry
- Legal Services
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive regulated financial data (IOLTA client trust accounts, banking credentials, ACH authorizations), at-scale PII of employees and plaintiffs/defendants, confidential attorney-client privileged correspondence, and sensitive litigation strategy documents. IOLTA account compromise poses direct financial and fiduciary harm to clients.Rhysida claims to have exfiltrated 710.6 GB of data (338,542 files) from the law firm, including complete financial records, client trust accounts, employee personal data, and confidential litigation files spanning thousands of client matters. No encryption-only claim is stated; the post advertises data for sale.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate bank accounts (routing, SWIFT, ACH/EFT authorizations)
- Client trust account (IOLTA) statements
- Partner corporate credit card statements
- Positive Pay register (all firm payments)
- Settlement wire confirmations
- Employee SSNs, home addresses, DOBs, marital status
- Direct-deposit forms with bank details
- ADP payroll journals (partners and staff)
- Practice-management database backups (~10,000 matters)
- Partner PST archives (confidential correspondence, settlement authority)
- 1,000+ litigation files of insurance clients (pleadings, depositions, discovery)
- Plaintiff/defendant PII from litigation matters
- Internal partnership lawsuit documents
- Litigation-funding correspondence
- HR folders (offer letters, health insurance invoices)
What the group claims
An unnamed US law firm with extensive financial, HR, and litigation data including client trust accounts, payroll, partner records, and major insurance client litigation files.
The leak post
captured from the group's siteThe Kreishandwerkerschaft Borken is the official trade association and advocacy organization representing local craft enterprises (Handwerksbetriebe) in the Borken district of Germany.1,382,523 files, 1.31 TBhealth data (disability lists with ID numbers, GdB medical ruling with diagnosis)sick leave, absence records, pension ruling2026 payslip (tax ID, social-security no., IBAN) and staff rostersigned contracts/terminations, CV with religionmember and creditor IBANsSCHUFA credit checks, court enforcement order, debtor affidavitMail and databases in full (Exchange, PST, SQL backups) + access/infrastructure slide (2FA secrets, S-FIRM code) With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only owner! MPA Pharma GmbH is an internationally active, rapidly growing company specializing in the import and trade of high-quality pharmaceuticals, including both patented and generic products. 2,899,290 files, ~5.8 TBPharmaceutical companyCategories: accounting records and database backups, government audits (customs / corporate tax / …
Data the group says was taken
- corporate bank account details
- routing numbers
- SWIFT codes
- ACH/EFT forms
- EIN
- IOLTA statements
- ACH/EFT authorizations
- settlement wire confirmations
- check copies
- Positive Pay register
- corporate credit card statements
- HR folders
- SSNs
- home addresses
- personal phones
- DOB
- marital status
- direct-deposit forms
- employee bank details
- ADP payroll journals
- offer letters
- self-evaluations
- health insurance invoices
- practice-management DB backups
- partner PST archives
- litigation files
- settlement agreements
- litigation-funding correspondence
- payroll records
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

