Rhysida Claims Attack on US Law Firm, Alleges Theft of Client Financial and Medical Records

The ransomware group has listed a Washington-state personal-injury firm on its dark-web site, claiming to hold client tax forms, medical files, and court-filing credentials. The firm has not confirmed any incident.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: A dimly lit open-plan law office at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Rhysida listed Gress Clark Young & Schoepper, a US personal-injury law firm, on its dark-web leak site on 10 October 2026, according to monitoring service Ransomware.live.
  • The group's post claims to hold roughly 167,804 files totalling approximately 166.4 gigabytes, including alleged client banking details, tax identification documents, and medical records.
  • Gress Clark Young & Schoepper has not publicly confirmed any incident, and the claim could not be independently verified at publication time.
  • Ransomware groups publish these listings to pressure companies into paying; the claims are sometimes exaggerated and occasionally false.

Rhysida is a ransomware-as-a-service operation: a core criminal group builds and rents out file-encrypting malware to affiliated attackers who carry out the actual break-ins and split any ransom proceeds. Active since at least mid-2023, it has previously hit hospitals and government bodies across Europe and North America. We covered the group's claim of a 5.79-terabyte theft from Berlin's city government on 31 August.

On 10 October 2026, Rhysida listed Gress Clark Young & Schoepper, a firm whose website describes work in personal-injury and workers-compensation cases, on its dark-web leak site. Ransomware.live, a service that monitors criminal leak sites, first observed the listing.

According to the group's post, the alleged haul runs to around 166.4 gigabytes across 167,804 files. It's the kind of claim that warrants attention even before verification: a personal-injury practice holds tax documents and medical records, exactly what criminals need for identity theft and fraud. The firm has made no public statement. Listings like this are written by criminals to apply pressure and are sometimes inflated or fabricated entirely.

Just the day before, we reported a separate ransomware claim against law firm Baker McKenzie, also unconfirmed. Two unverified law-firm listings in two days doesn't mean the legal sector is suddenly under coordinated attack, but it's a pattern worth watching.

How active is Rhysida right now?

Active enough to keep defenders busy. The group's victim count isn't something Threat Vectr has independently tracked, so treat any circulating figures as the group's own framing until corroborated. What's clear from the Berlin claim in August and this listing is that Rhysida hasn't slowed down.

Should you worry?

If you've ever been a client of Gress Clark Young & Schoepper, treat this as reason for a few precautions, even while the claim stays unverified.

Watch for phishing emails. Criminals who already know your name and case details from another source can use this news as cover to send fake messages impersonating the firm or a regulator. Be especially sceptical of any call or email offering "breach compensation" or asking you to confirm personal details.

Check your credit reports for accounts or inquiries you don't recognise. If you've reused a password across accounts, change the ones that matter most. A practice handling workers-compensation cases holds some of the most sensitive personal information a person can share, so these precautions are proportionate even if the claim ultimately proves false.

© 2026 Threat Vectr