Ransomware victim disclosure
← All victimsGress Clark Young & Schoepper
Claimed by Rhysida · listed 2 hours ago
Status timeline
- ListedOct 11, 2026
Current state: Listed for ransom
At a glance
- Group
- Rhysida
- Status
- Listed for ransom
- Country
- United States
- Sector
- Legal
- Listed on leak site
- Oct 11, 2026
- Data size
- ~166.4 GB
- Records
- 167,804 files
About the victim
AI dossier — public-source company profileGress Clark Young & Schoepper is a law firm based in the United States, founded in 1964. The firm handles industrial insurance appeals, personal injury, and other civil litigation matters.
- Industry
- Legal Services
- Founded
- 1964
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated PII (SSNs, medical records, tax documents, driver's licenses) and privileged legal/medical information. Includes PHI at scale and court filing credentials, representing severe exposure of client confidentiality.Rhysida claims to have exfiltrated approximately 166.4 GB of data (167,804 files) from the firm, including banking details, client SSNs, medical records, court credentials, and firm financial records. The group alleges discovery of potential ethics violations including witness-coaching correspondence.
Data the group says was taken
AI dossier — extracted from the leak post- Banking details (firm and clients)
- Social Security Numbers and signatures
- Tax forms (W-9, I-9, W-4)
- Driver's licenses and identity card copies
- Medical records and imaging (X-rays, PHI/APF)
- Court e-filing credentials
- Firm financial records (QuickBooks, void checks)
- BIIA case files and procedural documents
- Expert payment records
What the group claims
Law firm with data including banking details, client SSNs and signatures, BIIA case-management procedures, firm finances including QuickBooks files and VOID checks, medical photos and PHI, coaching letters to doctors potentially indicating ethics violations, court e-filing credentials, and disciplinary action against partner Daniel W. Gress.
The leak post
captured from the group's site[Gress Clark Young & Schoepper](https://www.gressandclarklaw.com)
167,804 files / ~166.4 GBBanking details - of the firm and its clients.SSNs + signatures of clients/witnesses; W-9, I-9 forms with DL/SSN card copies; W-4 forms.BIIA case-management procedures (Board of Industrial Insurance Appeals): default orders (Order of Default), internal 'Conference Questions', consulting-fee payments to experts.Firm finances: the firm's QuickBooks company file, VOID checks bearing signatures, expert-payment records, SaaS invoices.Medical photos and imaging; hundreds of pages of PHI/APF (Activity Prescription Forms) - X-rays, complete medical records.'Coaching' letters to doctors - including a letter to the physician in the Jachacy matter with wording indicative of steering a medical opinion ('coaching letter') - a potential ethics violation regarding witness handling.Credentials/access to the SPC e-file system (court e-filing).Disciplinary action against partner Daniel W. Gress.
With just 7 days on the clock, seize the opportunity to bid on exclusive, unique, and impressive data. Open your wallets and be ready to buy exclusive data. We sell only to one hand, no reselling, you will be the only …Data the group says was taken
- banking details
- SSNs
- signatures
- W-9 forms
- I-9 forms
- driver license copies
- W-4 forms
- BIIA case-management records
- QuickBooks company file
- VOID checks
- expert payment records
- SaaS invoices
- medical photos
- medical imaging
- PHI
- Activity Prescription Forms
- X-rays
- medical records
- coaching letters
- court e-filing credentials
- disciplinary records
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

