Dubroff, Easley & Lovell, LLP Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Dubroff, Easley & Lovell, LLP was listed by the pear ransomware group on September 15, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of people. Individuals should check the firm’s notifications or contact them directly to determine whether their information was involved and what protective steps are advised.
On September 15, 2025, the law firm Dubroff, Easley & Lovell, LLP was listed by the ransomware group known as pear. Public reporting indicates that the group claims to have conducted a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and further details about the scale or confirmation of the incident have not been disclosed. For clients and others connected to a family-law practice, any unauthorized access to internal materials raises clear concerns about the security of sensitive personal and legal information.
This listing forms the core of what is currently known. No independent verification of the group's claims has been made public, and the firm has not released additional statements in the available record. The episode matters because law firms routinely handle confidential client records; even an unverified claim of exfiltration can create lasting uncertainty for those whose data may have been involved.
What happened
According to the available facts, Dubroff, Easley & Lovell, LLP appeared on the leak site associated with the pear ransomware group on or around September 15, 2025. The group claims that internal files were exfiltrated during a ransomware attack. No information has been released about the precise date of the intrusion, the method of initial access, the volume of data taken, or whether any ransom demand was paid. The number of individuals potentially affected is listed as unknown. Public detail is limited to the group's assertion that internal files were removed from the firm's systems. No further technical indicators, such as malware variants or network vectors, have been disclosed in the record.
Inside pear
Pear operates as a ransomware group that follows the now-common double-extortion model. Publicly documented activity by such groups typically involves encrypting victim systems while simultaneously copying data for later publication or sale if a ransom is not paid. Groups of this type often maintain dedicated leak sites where they list victims and, in some cases, release sample files to pressure organizations. Their tactics generally include phishing, exploitation of unpatched remote-access services, or the use of stolen credentials to gain initial footholds. Once inside a network, operators move laterally, identify valuable data repositories, and exfiltrate material before deploying encryption. Prior public listings by pear and similar actors have targeted professional-service firms, healthcare providers, and other entities that hold large volumes of confidential records. In this instance, the group's listing of Dubroff, Easley & Lovell, LLP constitutes an unverified claim; no independent confirmation of the intrusion or the contents of any stolen files has been provided in the available facts.
About Dubroff, Easley & Lovell, LLP
Dubroff, Easley & Lovell, LLP is described in the reporting as an attorney service focused on family law. Firms of this type advise clients on divorce, child custody, support arrangements, property division, and related domestic matters. In the ordinary course of business they collect and store extensive personal information: names, addresses, financial statements, medical or psychological records, correspondence, court filings, and details about children and other family members. Because family-law matters often involve highly private and sometimes contentious circumstances, the confidentiality of these records is central to the attorney-client relationship and to the ethical obligations of the profession. A breach affecting such a practice therefore carries consequences that extend beyond ordinary business disruption; it can expose individuals to risks that touch their personal safety, financial standing, and family relationships. The firm's listing by a ransomware group underscores the broader exposure faced by legal practices that maintain large digital repositories of sensitive client data.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of the data types has been disclosed. Organizations engaged in family-law practice typically hold client intake forms, financial disclosures, tax returns, bank statements, property records, medical evaluations, emails, draft pleadings, and notes from consultations. These materials frequently contain Social Security numbers, dates of birth, account numbers, and other identifiers. Because the precise contents of the files claimed by pear remain unconfirmed, it is not possible to state with certainty which categories of information, if any, left the firm's control. The only confirmed description is the group's assertion that internal files were taken.
The real-world impact
For individuals whose information may have been among the exfiltrated files, the primary risks include identity theft, financial fraud, and the unauthorized disclosure of private family matters. Exposure of financial documents could enable account takeovers or fraudulent credit applications. Release of custody or medical records could be used for harassment, blackmail, or to influence ongoing legal proceedings. Even if the data is never publicly posted, its possession by criminals creates a persistent threat that may surface months or years later. For the firm itself, the incident can produce operational disruption, regulatory scrutiny under professional-conduct rules and data-protection statutes, potential civil claims from clients, and lasting damage to reputation. Because the number of people affected is unknown and the exact data set is unconfirmed, the full scope of these impacts cannot yet be measured. The uncertainty itself imposes costs: clients may need to monitor accounts, freeze credit, or seek legal advice simply because their information might have been involved.
If your data was in this claimed breach
Anyone who has been a client of Dubroff, Easley & Lovell, LLP or who has shared personal information with the firm should treat the listing as a prompt for caution. Begin by placing fraud alerts or credit freezes with the major credit bureaus, reviewing recent account statements for unfamiliar activity, and changing passwords on any accounts that may have used the same credentials supplied to the firm. Monitor for unexpected communications that reference family-law matters or request further personal details. Because public confirmation of specific data exposure is lacking, these steps remain precautionary. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets elsewhere. Remaining attentive to official notices from the firm or from regulators will provide the most reliable updates as additional facts, if any, become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Gordon Clifford Properties Inc. Listed by pear Ransomware GroupQuinn Jay Patent Listed by pear Ransomware GroupLaw Office of Ronald W. Hillberg Listed by pear Ransomware GroupGerson & Schwartz Accident & Injury Lawyers Listed by pear Ransomware GroupLatest breaches
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.