duttonbrock.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The duttonbrock.com Listed by lockbit3 Ransomware Group (reported March 16, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target professional-services firms that hold large volumes of sensitive client and operational data, listing victims on leak sites as a pressure tactic even when the full scope of an intrusion remains unclear. In this landscape, the appearance of a Canadian insurance-litigation practice on a well-known ransomware group's site is a reminder that law firms remain attractive targets because of the confidential material they routinely handle.
On 16 March 2024, the domain duttonbrock.com was listed by the LockBit3 ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack; the number of people affected is unknown and further technical details have not been disclosed. The listing itself is a claim by the group and has not been independently confirmed in the available record.
Inside the incident
According to the public record, duttonbrock.com was listed by LockBit3 on 16 March 2024. The only data description provided is that internal files were allegedly exfiltrated in a ransomware attack. No figure for the number of affected individuals has been released, no specific file names or volumes have been published, and no timeline of the intrusion, encryption event, or negotiation has been made available. Method of initial access, duration of presence inside the network, and whether any ransom demand was paid remain undisclosed. The incident is therefore known only through the group's leak-site claim and the brief accompanying description of internal-file exfiltration.
Inside lockbit3
LockBit3 is a ransomware-as-a-service operation that has been active for several years and is among the most frequently observed groups in public breach reporting. The group typically gains access through phishing, compromised credentials, or unpatched remote-access services, then moves laterally, exfiltrates data, and deploys encryption. Victims are often listed on a dedicated leak site with sample files or full archives if a ransom is not paid. LockBit3 has claimed responsibility for attacks across many sectors, including professional services, manufacturing, and government contractors. Its operators have historically used double-extortion tactics—threatening both encryption and public release of stolen data—to increase pressure. In the present case the group claims that duttonbrock.com was among its victims and that internal files were taken; those assertions rest solely on the leak-site listing and have not been corroborated by independent forensic disclosure.
duttonbrock.com and its sector
Dutton Brock is a Canadian law firm whose practice centers on insurance litigation. Public descriptions of the firm note that its work spans the spectrum of insurance-related disputes and that it has been recognized by Lexpert as the most frequently recommended commercial insurance litigation firm in Canada. Firms of this type routinely hold client files, pleadings, medical and financial records related to claims, correspondence with insurers and opposing counsel, and internal administrative documents. Because insurance litigation often involves personal injury, property damage, and commercial coverage disputes, the material stored by such practices can include highly sensitive personal and commercial information. A breach affecting a firm in this sector therefore carries consequences both for the firm’s clients and for the broader insurance and legal ecosystems that rely on the confidentiality of those files.
What was likely exposed
The only data type named in the public record is “internal files exfiltrated in a ransomware attack.” No further inventory—such as client names, case files, financial records, or employee data—has been released. Organizations of this kind typically maintain litigation files, insurance-policy documents, medical reports, settlement correspondence, billing records, and internal firm communications. Whether any of those categories were among the exfiltrated material remains unconfirmed. Readers should therefore treat the precise contents of the stolen data as unknown pending any official statement from the firm or law-enforcement authorities.
Why it matters
For individuals whose information may have been held by the firm, the principal risks are identity theft, targeted phishing, and the possible misuse of personal or medical details that appear in insurance claims. Even if the files contain only commercial rather than personal data, the exposure of litigation strategy or settlement terms can affect ongoing cases and client relationships. For the firm itself, the incident raises operational, reputational, and regulatory considerations: clients may demand assurances about data security, insurers may reassess coverage, and professional regulators may inquire into the firm’s incident-response measures. Because the scale of the breach remains unknown, the full extent of these risks cannot yet be quantified, but the mere listing by a ransomware group is sufficient to create lasting uncertainty for anyone whose data the firm held.
If your data was in this claimed breach
If you have been a client of Dutton Brock or have reason to believe your information was stored by the firm, monitor financial and insurance accounts for unusual activity, enable multi-factor authentication on email and other critical services, and be alert to phishing messages that reference insurance claims or legal matters. Consider placing fraud alerts with credit-reporting agencies if personal identifiers may have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; such a check will not confirm or rule out involvement in this specific incident, but it can indicate whether your credentials or personal details are circulating more widely.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
fcl.crs Listed by lockbit3 Ransomware Groupnetspectrum.ca Listed by lockbit3 Ransomware Grouplondondrugs.com Listed by lockbit3 Ransomware Groupsierraconstruction.ca Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the duttonbrock.com Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.