Davidoff Hutcher & Citron Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Davidoff Hutcher & Citron Listed by alphv Ransomware Group (reported August 21, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On August 21, 2023, the New York law firm Davidoff Hutcher & Citron was listed by the alphv ransomware group, which claimed to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited beyond the group's listing and the description of internal files as the data involved. For a firm that handles commercial litigation, transactional work, government relations, and public affairs, any unauthorized access to internal material raises clear concerns for clients, partners, and others whose information may have been held in firm systems.
What is confirmed in available reporting is the attribution claim by alphv and the reported nature of the intrusion as a ransomware event with data removal. No independent confirmation of the full scope, method, or precise contents has been detailed in the facts at hand. The episode matters because law firms routinely manage sensitive legal, commercial, and personal information; even a claimed listing can prompt scrutiny of exposure risk and response steps for those connected to the practice.
What happened
According to the reported record, Davidoff Hutcher & Citron appeared on an alphv leak-site listing dated August 21, 2023. The group is associated with a ransomware attack in which internal files were described as having been exfiltrated. Public facts do not disclose the initial access method, the duration of any intrusion, whether encryption was deployed alongside theft, any ransom demand, or whether negotiations occurred. The number of individuals affected is listed as unknown. No file counts, specific document titles, or dollar figures appear in the available facts. The core public claim is therefore the listing itself together with the characterization of internal files taken in a ransomware attack; further operational detail remains undisclosed.
Inside alphv
Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has functioned on a ransomware-as-a-service model. Affiliates have typically gained access to victim networks, moved laterally, exfiltrated data, and then deployed encryption while threatening to publish or auction stolen material if payment is not made—a double-extortion pattern documented across many incidents attributed to the group. The operation has been linked in open sources to Russian-speaking actors and has targeted organizations across multiple sectors and countries. Listings on its leak infrastructure have served as pressure mechanisms and as public claims of successful intrusion. Those listings are claims by the group; they are not, by themselves, independent verification of every asserted detail about a given victim. In this case, the facts record alphv's listing of Davidoff Hutcher & Citron and the associated description of internal-file exfiltration, without additional confirmed statements unique to this victim beyond that claim.
About Davidoff Hutcher & Citron
Davidoff Hutcher & Citron LLP is described in available material as a mid-size firm founded in 1975, with a practice spanning commercial litigation, transactional law, government relations, and public affairs. It maintains offices in New York City, Albany, Washington, D.C., White Plains, and Palm Beach, Florida. The firm presents itself as combining multi-discipline legal work with government-relations and lobbying matters ranging from routine to complex. Law firms of this type typically hold client correspondence, case files, contracts, billing records, personnel information, and materials related to regulatory or legislative work. A breach claim against such an organization is consequential because the confidentiality of legal and government-relations work underpins client trust and professional obligations; exposure of internal files can affect not only the firm but also clients, counterparties, and individuals named in those materials.
What data was at risk
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files included client matter data, employee records, financial documents, email archives, or government-relations work product—is provided. The number of people affected is unknown. Organizations in the legal and government-relations sector commonly store privileged communications, contracts, personal identifiers of clients and staff, billing and trust-account information, and sensitive strategy documents. Because the exact contents in this incident are unconfirmed beyond the description of internal files, it is not possible to state specific data categories as established fact. Readers should treat the scope as limited to what has been publicly claimed and reported.
What's at stake
For individuals whose information may have been present in firm systems, risks can include unwanted contact, attempts at fraud or social engineering that reference real legal or business matters, and longer-term misuse of personal or financial details if such data were among the files. For corporate or organizational clients, exposure of internal legal strategy, contracts, or government-relations materials could affect ongoing matters, negotiations, or competitive position. For the firm itself, a claimed ransomware incident with data exfiltration can bring operational disruption, regulatory and professional-ethics scrutiny, notification duties where applicable, and reputational pressure. None of these outcomes is asserted here as having already occurred in full; they are the concrete categories of harm that typically follow when internal law-firm files are taken. The absence of a confirmed count of affected people and of a detailed data inventory means the precise scale of individual impact remains unknown.
What to do if you're exposed
If you have a past or present relationship with Davidoff Hutcher & Citron—as a client, employee, vendor, or other party—and you are concerned your information may have been involved, begin with practical steps. Monitor financial and credit accounts for unfamiliar activity and consider a fraud alert or credit freeze through the major credit bureaus if you believe personal identifiers could be at risk. Be cautious of unexpected emails, calls, or messages that reference legal matters, the firm, or personal details; verify any such contact through known official channels rather than links or numbers supplied in the message. Change passwords on related accounts, especially if you reused credentials, and enable multi-factor authentication where available. Retain any official notice you receive from the firm and follow instructions it provides regarding support or monitoring services. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which can help you decide what to prioritize next. Public detail on this incident remains limited; staying alert to official updates from the firm and to your own accounts is a measured way to respond.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Advantage Group International Listed by alphv Ransomware GroupLisa Mayer CA, Professional Corporation Listed by alphv Ransomware GroupAQIPA Listed by alphv Ransomware GroupHTC Global Services Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.