Coole Bevis Solicitors Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Coole Bevis Solicitors Listed by alphv Ransomware Group (reported March 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to single out professional-services firms because the data those organisations hold is both sensitive and difficult to replace. In that landscape, the appearance of a UK law practice on a criminal leak site is a familiar but still serious development. On 21 March 2023, the ransomware group alphv publicly listed Coole Bevis Solicitors, claiming it had exfiltrated internal files and published them.
Public detail remains limited: the number of people affected is unknown, and independent confirmation of the full scope has not been released. What is known is the group’s assertion that internal material was taken in a ransomware attack and made available. For clients, staff and counterparties of a solicitors’ firm, that claim alone is enough to warrant careful attention.
Inside the incident
According to the listing reported on 21 March 2023, alphv stated that it had conducted a ransomware attack against Coole Bevis Solicitors and exfiltrated internal files. The group’s own summary declared that “ALL DATA PUBLISHED AND AVAILABLE FOR EVERYONE!!!” No further technical particulars—such as the initial access method, the duration of unauthorised access, or the precise volume of data—have been disclosed in the available record. The number of individuals whose information may have been involved is likewise unknown.
Because the primary source is the threat actor’s own leak-site claim, the incident should be treated as an unverified assertion of compromise and data theft unless and until the firm or regulators provide corroborating detail. What can be stated with certainty is only what appears in the public report: a listing by alphv, a reference to internal files taken in a ransomware attack, and the group’s declaration that the material had been published.
The group behind it: alphv
Alphv, also widely known as BlackCat, is a ransomware operation that has been active since late 2021. It functions as a ransomware-as-a-service enterprise, supplying affiliates with malware and infrastructure in exchange for a share of any ransom proceeds. The group is noted for double-extortion tactics: encrypting systems while simultaneously copying data and threatening to release it if payment is not made. Affiliates have targeted organisations across healthcare, manufacturing, professional services and government, often posting victims on a dedicated leak site to increase pressure.
Alphv has historically favoured customisable rust-based ransomware, strong encryption and public shaming of non-paying victims. Its listings frequently include samples or full archives of stolen files once a deadline passes. In the present case, the group claims to have published the Coole Bevis material; that claim originates solely from the actors themselves and has not been independently verified in the facts available here. No specific ransom demand, negotiation detail or proof package beyond the general assertion of publication is recorded in the public summary.
About Coole Bevis Solicitors
Coole Bevis Solicitors is a United Kingdom law firm. Firms of this type routinely handle conveyancing, litigation, family matters, wills, probate and commercial work. In the ordinary course of business they collect and retain large volumes of personal and confidential information: identity documents, financial records, medical or social-work reports, correspondence, contracts and details of third parties. That material is often subject to legal professional privilege and to strict regulatory duties under data-protection and solicitors’ conduct rules.
A breach affecting such a practice is consequential precisely because the data is both intimate and long-lived. Clients entrust solicitors with information they would not share lightly; counterparties and experts may also appear in the files. Even when the exact contents of a given incident remain unconfirmed, the sector’s typical holdings mean that any successful exfiltration carries elevated risk of identity misuse, fraud, or exposure of private legal affairs.
What data was at risk
The only data description provided in the report is “internal files exfiltrated in ransomware attack.” No itemised list of document types, no count of records, and no confirmation of whether client matter files, employee records, financial systems or email archives were included has been made public. The threat actor’s statement that “all data” was published is a claim, not an independently audited inventory.
Organisations in the legal sector typically hold names, addresses, dates of birth, national-insurance or passport details, bank and mortgage information, health or family particulars, and privileged correspondence. It is reasonable to assume that some subset of such material could have been present on internal systems, yet it would be inaccurate to assert that any specific category was definitely exposed. Exact contents remain unconfirmed.
The real-world impact
For individuals whose information may have been among the taken files, the practical risks include targeted phishing, identity fraud, and the unwanted disclosure of private legal matters. Once documents circulate on criminal forums or are re-shared, they can be used for years. Even if the firm restores operations quickly, the confidentiality of past advice or personal circumstances cannot be restored in the same way.
For the organisation itself, consequences may include regulatory scrutiny, notification obligations, potential claims from affected clients, reputational harm, and the operational cost of investigation and remediation. Because the number of people affected is unknown and the precise data set is undisclosed, the scale of these effects cannot yet be quantified. The incident nonetheless illustrates why professional-services firms remain high-value targets: the combination of sensitive data and the expectation of confidentiality raises both the leverage available to attackers and the downstream harm to ordinary people.
Were you affected?
If you are a current or former client, employee or counterparty of Coole Bevis Solicitors, treat the alphv claim as a prompt to act cautiously rather than as confirmed proof that your own file was taken. Monitor bank and credit accounts for unusual activity, be alert to unexpected messages that reference legal matters or request personal details, and consider placing fraud alerts with relevant UK services if you believe your identity documents may have been involved. Retain any correspondence from the firm about the incident.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. That step will not confirm or rule out involvement in this specific event, but it provides a practical starting point for understanding your wider exposure and deciding what further monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Navigation Financial Group Listed by alphv Ransomware GroupTipalti Listed by alphv Ransomware GroupFidelity National Financial Listed by alphv Ransomware GroupMeridianLink Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Coole Bevis Solicitors Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.