CASEPOINT pt2 Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The CASEPOINT pt2 Listed by alphv Ransomware Group (reported June 8, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target organisations that sit close to sensitive investigations, legal work and law-enforcement support, treating internal files as leverage in double-extortion schemes. Listings on criminal leak sites have become a routine pressure tactic, even when independent confirmation of the underlying intrusion remains limited. Against that backdrop, the appearance of CASEPOINT pt2 on an alphv-associated site in June 2023 fits a familiar pattern of claimed data theft paired with public threats to release material.
What is known so far is narrow: the organisation was listed by the alphv ransomware group on or around 8 June 2023, with the group asserting that internal files had been exfiltrated. The number of people affected is unknown, and public detail beyond the group's own claims is limited. The incident matters because the material the group says it holds touches investigative and operational records that, if authentic and released, could affect individuals named in those files and the integrity of related work.
Inside the incident
According to the available record, CASEPOINT pt2 was listed by the alphv ransomware group with a report date of 8 June 2023. The listing characterises the event as a ransomware attack in which internal files were allegedly exfiltrated. The group further claimed that “very sensitive data” had been uploaded and specifically referenced Operation Blooming Onion information, a Cellebrite report, agent and supervisor names, and additional material, directing readers to a fuller post for more detail.
No independent public confirmation of the intrusion method, the precise date of initial access, the volume of data taken, or the number of individuals affected has been supplied in the facts available here. Scale and technical entry path remain undisclosed. The listing itself functions as an unverified claim by the threat actor; it should be treated as such until corroborated by the organisation or other authoritative sources.
The group behind it: alphv
Alphv, also widely known in public reporting as BlackCat, has operated as a ransomware-as-a-service operation. Affiliates typically gain access to victim networks, deploy encrypting malware, and exfiltrate data before encryption so they can threaten publication if a ransom is not paid. The group has been associated with a range of high-profile incidents across sectors and has used dedicated leak sites to name victims and, in some cases, drip or dump stolen files.
Its public tradecraft has included double extortion, pressure campaigns timed around leak-site posts, and claims of possessing sensitive internal documents. None of that established background proves the specific assertions made about CASEPOINT pt2. Those assertions—that internal files were taken and that particular categories of material were among them—remain claims advanced by the group on its listing, not independently Reported Facts in the record provided here.
About CASEPOINT pt2
CASEPOINT pt2 appears in the breach record as the named organisation. Publicly, Casepoint is known as a provider of e-discovery and legal-technology platforms used to manage large volumes of documents, communications and evidence in litigation, investigations and regulatory matters. Organisations in this sector commonly handle case files, discovery productions, forensic exports, personnel identifiers tied to investigations, and other material that is sensitive by nature.
A breach affecting such an environment is consequential because the data under management often relates to third parties—litigants, witnesses, agents, supervisors or subjects of inquiry—rather than solely to the organisation’s own employees. Even when the exact corporate structure or the meaning of the “pt2” designation is not elaborated in public breach summaries, the sector context explains why claimed exposure of investigative or forensic material draws attention.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. The alphv listing claims the uploaded material includes very sensitive data, Operation Blooming Onion information, a Cellebrite report, agent and supervisor names, and more. Those specifics originate with the threat actor’s post and are not independently confirmed in the available record.
Exact contents, file counts and the full scope of any exposure remain unconfirmed. Organisations that support e-discovery, digital forensics or investigative workflows typically hold case-related documents, device extraction reports, identity and role information for personnel involved in matters, and internal operational records. Whether any of those categories were in fact allegedly taken from CASEPOINT pt2, and in what volume, is not established beyond the group’s claims. Readers should treat named data types as alleged rather than proven.
The real-world impact
For people whose names or roles appear in investigative or supervisory records, unauthorised exposure can mean unwanted attention, social-engineering risk, or complications in ongoing matters. Agent and supervisor identifiers, if genuine and released, could be misused for targeted phishing or harassment. Forensic or operation-related files, again if authentic, could compromise the confidentiality of inquiries or create secondary risks for individuals connected to those files.
For the organisation, a public ransomware listing brings operational disruption, potential legal and contractual notification duties, reputational strain with clients who entrust it with sensitive matters, and the cost of investigation and remediation. Because the number of people affected is unknown and the precise data set is unconfirmed, the full human and institutional impact cannot yet be quantified from public facts alone. The risk is real but bounded by what has actually been verified.
Were you affected?
If you have a connection to CASEPOINT pt2, to matters that may have involved its platforms, or to names and roles of the kind the group claims to hold, treat the situation cautiously. Monitor financial and email accounts for unusual activity, be alert to tailored phishing that references investigations or colleagues, and consider credit or fraud alerts if you believe personal identifiers could be involved. Official confirmation and guidance, if any, would come from the organisation or relevant authorities rather than from criminal leak sites.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm involvement in this specific incident, but it can help you see whether your credentials or personal details appear elsewhere and decide on password changes or further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Advantage Group International Listed by alphv Ransomware GroupLisa Mayer CA, Professional Corporation Listed by alphv Ransomware GroupAQIPA Listed by alphv Ransomware GroupHTC Global Services Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the CASEPOINT pt2 Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.