VORANT. Threat Intelligence Research Sign in Create a free account

Rhysida ransomware lists law firm victim

elevated threat

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Rhysida ransomware group added Law Offices of R. David Williams, P.A. to its leak site, claiming theft of extensive criminal case files.

Ransomware.live has indexed a new victim listing from the Rhysida ransomware group's leak site: Law Offices of R. David Williams, P.A., a criminal defense practice. The listing claims exfiltration of a large volume of sensitive legal data covering roughly 175+ clients, including felony case files, DUI records, probation violation documents, FDLE expungement packets with fingerprint cards, Risk Protection Order records, immigration detention details, and material witness monitoring information. The claimed dataset reportedly includes approximately 206 GB of police discovery material such as bodycam video, 911 recordings, jail calls, incident reports, photo line-ups, and FCIC/NCIC law enforcement database forms, along with victim and witness data protected under Marsy's Law.

No technical details of the intrusion vector, malware behavior, or exploited vulnerabilities are provided in this listing; it is a leak-site entry rather than incident analysis. For defenders, this represents a single confirmed Rhysida victim rather than a new campaign or technique. Organizations handling similarly sensitive legal, law-enforcement, or witness-protection data should treat this as a reminder to review data segmentation, backup integrity, and access controls around case management systems containing highly sensitive personal and investigative records, particularly small legal practices that may lack mature security operations.

Mentioned in this report

Threat actors rhysida
Malware Rhysida

Source reporting: https://www.ransomware.live/id/TGF3IE9mZmljZXMgb2YgUi4gRGF2aWQgV2lsbGlhbXMsIFAuQS5Acmh5c2lkYQ==

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,417 reports from 154 sources, 2,066 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs