Ishbia & Gagleard law firm data leaked
A Michigan law firm's ransomware leak exposes 360+ client case files, SSNs, PHI, and tax returns spanning two decades.
Ransomware.live has indexed a leak listing for Ishbia & Gagleard, P.C., a Birmingham, Michigan boutique law firm founded in 1999. The exposed data reportedly includes over 360 client/matter folders covering litigation strategy, settlement agreements, and privileged correspondence, along with more than 25 full Social Security Numbers, a scanned SS card, and protected health information tied to admissions at Oakwood Hospital, University of Michigan Hospital, and William Beaumont Hospital. Additional exposed material includes 55+ employee files from a sexual health clinic client, over 100 client tax returns from 2003–2024 containing SSNs, EINs, and income data, and 11 PST/OST email archives. The listing also references personal legal matters involving Mat Ishbia, CEO of publicly traded UWM Holdings Corp. (NYSE: UWMC).
No ransomware group name, malware family, or specific TTPs are disclosed in the source material; only DNS/SPF records for the firm's domain (Microsoft 365 hosted) are provided. This appears to be a data-leak/extortion listing rather than a technical intrusion writeup, so there is no confirmed exploitation vector, IOC beyond DNS metadata, or attacker attribution available. Given the volume of highly sensitive PII, PHI, and attorney-client privileged material — plus a link to a high-profile public company executive — this incident carries significant downstream risk for affected individuals and organizations, including identity theft, extortion, and litigation exposure, even though the technical details of the compromise remain unreported.
Defenders at law firms and professional services organizations should treat this as a reminder to review email archive retention/encryption practices, audit access to client SSN/PHI data, and monitor for secondary extortion or phishing attempts referencing exposed case details or individuals named in the leak, including any executives or public figures whose personal matters may be referenced.
Source reporting: https://www.ransomware.live/id/SXNoYmlhICYgR2FnbGVhcmQsIFAuQy5AYXVyb3Jh
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free