Deadlock ransomware leaks Shaheen Law Group data
The Deadlock ransomware group claims to have stolen 27GB of client data, including SSNs and banking records, from Virginia family law firm Shaheen Law Group.
A ransomware extortion group calling itself Deadlock has posted a leak listing for Shaheen Law Group, a family law and real estate closing firm based in Richmond, Virginia, with offices across four locations. The group claims to have exfiltrated 36,788 files totaling 27GB, including thousands of real estate deeds containing Social Security Numbers, banking statements and email headers from the firm's internal network (revealing internal hostnames, an Exchange server, and a Barracuda appliance IP), client folder structures naming customers and addresses, medical files, and litigation records. The actors published redacted samples of SSNs, deed documents, and internal email headers as proof, and explicitly threatened to sell network access/reconnaissance information ('the map') to other threat actors.
The firm reportedly closes 150+ real estate transactions monthly for major corporate relocation programs, meaning the exposed data likely includes employees relocated by Fortune 500 companies — SSNs, bank wiring details, home addresses, family identities, and in some cases medical clearance information. The extortion post references specific legal exposure under Virginia Code §18.2-186.6 (data breach notification) and Illinois BIPA, and references a public litigation matter (Porchlight Homes v. Almeida & Shaheen) apparently to add credibility and pressure. This is a data-extortion/leak-site posting rather than confirmed evidence of ransomware deployment or encryption; the primary risk to the named victim is client PII/PHI exposure and reputational/regulatory fallout. For third parties, the exposed network details (internal hostnames, IP, mail security appliance) could be leveraged for follow-on targeting if accurate and current.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/U0hBSEVFTiBMQVcgR1JPVVAgUExDIC0gUmljaG1vbmQsIFZpcmdpbmlhLCBVU0FARGVhZGxvY2s=
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free