Cohn Lifland Pearlman Herrmann and Knopf Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Cohn Lifland Pearlman Herrmann and Knopf was listed by the Akira ransomware group on April 25, 2025, after internal files were taken in a ransomware attack. An undisclosed number of people may have been affected; anyone who has shared data with the firm should verify their status and monitor their accounts.
Cohn Lifland Pearlman Herrmann and Knopf, a law firm, was listed by the Akira ransomware group on April 25, 2025, as the target of a ransomware attack in which internal files were allegedly exfiltrated. Public details remain limited: the number of people affected is unknown, and independent confirmation of the full scope has not been released. The listing itself represents a claim by the group rather than a verified disclosure from the firm.
Incidents of this kind matter because law firms routinely handle sensitive personal and financial records belonging to clients. When such material is taken, the potential for identity misuse, privacy harm, and operational disruption rises, even if the precise contents and volume stay unconfirmed outside the attackers’ statements.
Inside the incident
According to the available record, the firm was named on Akira’s leak site on April 25, 2025. The group asserts that it carried out a ransomware attack and removed a large volume of internal files. No independent timeline of the intrusion, no confirmed entry method, and no verified total of affected individuals have been published. The firm’s own public statements on the matter, if any, are not part of the provided facts, so the precise sequence of events remains undisclosed.
The attackers claim they obtained 110 GB of material and that the firm declined to pay a ransom despite holding an active cyber-insurance policy. They further state they intend to upload the files. These assertions originate solely from the group and have not been corroborated by external reporting in the given facts. What is established is only that internal files were described as exfiltrated in a ransomware incident and that the firm was publicly listed.
The group behind it: akira
Akira is a ransomware operation that has been active in public reporting since 2023. The group typically follows a double-extortion model: it encrypts systems while also copying data, then threatens to publish the stolen material if payment is refused. Akira has been observed targeting organizations across multiple sectors, including professional services, and often posts victim names and sample files on a dedicated leak site to increase pressure. Its operators have historically claimed large data volumes and have advertised the presence of personal and financial records to underscore the threat of exposure.
In this case, the group claims it took 110 GB of files containing client personal information and firm financial documents, and that the firm chose not to pay. No further statements attributed specifically to this victim beyond those claims appear in the facts. As with other Akira listings, the appearance of a name on the leak site is an unverified assertion until confirmed by the victim or by independent investigation.
Who is Cohn Lifland Pearlman Herrmann and Knopf?
Cohn Lifland Pearlman Herrmann and Knopf is a law firm. Firms of this type provide legal services that routinely require the collection and storage of client identity documents, correspondence, financial records, and other confidential materials. Such organizations operate under professional and regulatory expectations of confidentiality, and a breach can therefore affect both the firm’s clients and its own internal operations.
Because law firms sit at the intersection of personal privacy and commercial secrecy, any unauthorized removal of their files carries heightened consequences. Clients may include individuals and businesses whose sensitive information is entrusted to the firm for litigation, estate matters, or transactional work. The listing by a ransomware group therefore raises questions about the security of that entrusted data, even while the exact extent of exposure remains unconfirmed.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. Beyond that designation, the detailed inventory comes from the attackers’ own claims. Akira asserts that the 110 GB haul includes passports, driver’s licenses, birth and death certificates, correspondence, addresses, contacts, financial statements, and other confidential firm documents. These specific categories are presented as the group’s description; they have not been independently verified in the available record.
Organizations of this kind typically hold precisely the sorts of records the group names—identity documents, contact details, and privileged communications—because such material is necessary for legal representation. Until the firm or a regulator confirms what was actually taken, the exact contents remain unconfirmed. Readers should treat the attackers’ list as a claim rather than established fact.
What's at stake
For individuals whose information may have been among the files, the practical risks include identity theft, fraudulent account openings, and targeted social-engineering attempts that exploit knowledge of personal details. Documents such as passports or driver’s licenses, if genuine and exposed, can be used to impersonate someone or to bypass verification checks. Correspondence and contact lists can enable more convincing phishing or harassment.
For the firm itself, the stakes include potential regulatory scrutiny, client attrition, and the cost of investigation and remediation. Confidential financial statements and internal documents, if released, could reveal business strategies or create liability under professional-conduct rules. Because the number of affected people is unknown and the data types are unconfirmed outside the group’s statements, the full scale of harm cannot yet be measured. The absence of confirmed payment or non-payment details also leaves open questions about whether any decryption keys or deletion assurances were obtained.
Were you affected?
If you have been a client of Cohn Lifland Pearlman Herrmann and Knopf or have otherwise shared personal documents with the firm, treat the possibility of exposure seriously until more information emerges. Monitor financial accounts and credit reports for unusual activity, place fraud alerts if appropriate, and be cautious of unsolicited communications that reference personal details. Change passwords on any accounts that may have used similar credentials, and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can indicate whether your information has surfaced elsewhere and help you prioritize further protective steps. Continue to watch for official notices from the firm or from regulators as more verified details become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Milliman Financial Risk Management LLC (Milliman, Inc. subsidiary) Listed by akira Ransomware GroupSouthwood Financial,SWF FUNDING LLC, EduCap Inc. Listed by akira Ransomware GroupEdge Solutions | Stone Ridge Payments Listed by akira Ransomware GroupTrubee Wealth Advisors Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.