Federis Abogados Listed by Booba Project Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On August 24, 2026, the Booba Project ransomware group listed Federis Abogados in connection with a data breach involving personal data of an undisclosed number of individuals. Those who may have been affected should check the firm’s notices and monitor their accounts for unusual activity.
A ransomware group known as Booba Project has listed Federis Abogados on its leak site, claiming it holds data tied to the law practice and describing a volume of about 61 GB. As of writing, Federis Abogados has not publicly confirmed the claim, and independent verification is not reflected in the material available for this report. For clients, counterparties, employees, and others who may have shared sensitive information with a law firm, the practical stake is straightforward: if the claim were accurate, confidential legal and personal material could be at risk of misuse even when the full picture remains unproven.
Public detail is limited. The listing is an accusation by an extortion crew, not a claimed breach notice from the firm or a regulator. What follows separates what the group claims from what is known about such actors and about the kind of data law practices typically handle, so readers can judge risk without treating an unverified post as settled fact.
Inside the listing
According to the listing attributed to Booba Project, Federis Abogados appears as a claimed victim, with the group describing the matter in summary terms as involving a law practice and “stolen data” sized at 61 GB. The report date associated with this listing is August 24, 2026. The number of people potentially affected is unknown. Specific data types said to be involved are not disclosed in the facts available here.
Method of access, timing of any alleged intrusion, internal systems involved, and whether any files were actually published are not established in the provided record. Booba Project has listed the firm on its leak site; that is the core public claim. Nothing in the available facts confirms that the company has validated the accusation, negotiated with the group, or released its own incident notice. Readers should treat scale figures and labels on leak sites as the group’s assertions, which may be incomplete, recycled, or overstated, until corroborated by the organisation or another authoritative source.
Who is Booba Project?
Booba Project is known in public reporting as a ransomware and data-extortion style actor: groups in this category typically claim to have encrypted or copied systems, then pressure organisations by threatening to publish alleged data on a dedicated leak site if demands are not met. Like other extortion crews, they often post victim names, short descriptions, and claimed data volumes to create urgency and reputational pressure. Their listings are marketing and leverage tools for the attackers, not audited inventories.
Well-documented patterns for such groups include timed countdowns, staged sample releases in some campaigns, and broad claims about what was taken. None of that general pattern proves what happened in any single case. For Federis Abogados specifically, the only incident-linked assertions in the facts are that Booba Project listed the firm, framed it as a law practice matter, and claimed roughly 61 GB of data. No further quotes, file lists, or technical indicators unique to this listing are provided here, and inventing them would go beyond the record.
Federis Abogados and its sector
Federis Abogados is identified in the listing context as a law practice. Legal firms, as a sector, routinely handle information that is sensitive by nature: client identities, case strategies, contracts, correspondence, billing and payment details, and often identity or contact data for individuals involved in disputes, transactions, or advice. Even routine matter files can include documents that were never meant for public circulation.
A leak-site claim against a law firm is consequential because trust and confidentiality are central to legal work. That does not establish that any particular firm failed in its duties, and it does not prove that systems at Federis Abogados were compromised. It does explain why clients and partners pay attention when a named practice appears on an extortion site: the sector’s typical holdings make the hypothetical downside serious if a claim later proved accurate. What a listing establishes is only that a group chose to name the organisation and attach a claimed data volume; what it does not establish is confirmation, scope, or fault.
What data was at risk
The facts do not name exposed data types. The listing summary refers to a law practice and a claimed 61 GB figure, but it does not inventory contents. Exact contents are therefore unconfirmed.
If files from a law practice were ever taken, firms in this sector typically hold materials such as client and matter records, legal correspondence, contracts and pleadings, identity and contact details, and financial or billing information related to services. Those categories are sector norms, not a verified description of this claim. Because Booba Project’s description functions as attacker messaging rather than a confirmed catalogue, no reader should assume that any specific document or personal field about them is in the group’s hands solely on the basis of the listing.
The real-world impact
For people who may be connected to the firm, impact remains conditional. If sensitive legal or personal data were in an attacker’s possession, risks could include targeted phishing that references real matters, identity misuse, pressure or embarrassment related to private disputes, and fraud attempts that exploit trust in lawyer–client relationships. For the organisation, an unconfirmed listing can still create operational distraction, client concern, and reputational strain while facts are sorted out—without proving that data left its control.
Conversely, leak-site posts sometimes name organisations inaccurately or recycle older material. Until Federis Abogados or another authoritative channel confirms details, the responsible posture is caution without panic: monitor for unusual contact that cites legal matters, and avoid treating the group’s word as a complete account of what, if anything, occurred.
If your data was involved
If you believe you may be connected to Federis Abogados as a client, employee, or counterpart, treat any exposure as hypothetical until confirmed, and take measured steps:
- Be wary of unexpected emails, calls, or messages that reference legal cases, invoices, or personal details and push you to click links, open attachments, or pay urgently.
- Prefer official channels you already trust if you need to ask the firm whether your matter is affected; do not rely on contact details supplied in unsolicited messages.
- Watch financial and identity accounts for unfamiliar activity, and use strong, unique passwords with multi-factor authentication where available.
- If you receive what looks like leaked documents involving you, preserve copies for your own records and seek qualified legal or fraud-advice help rather than negotiating with anonymous extortion contacts.
- You can run a free exposure scan of your email to check whether your information has already surfaced in known breach data sets unrelated or related to public dumps.
Booba Project’s listing of Federis Abogados remains an unverified claim as of the report date associated with this material. Public confirmation from the company is not part of the available facts. Staying alert to conditional risk—and verifying news through primary sources—is the most useful response while the accusation sits unconfirmed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Country-Wide Insurance Listed by Booba Project Ransomware GroupBetz Industries Listed by Booba Project Ransomware GroupOklahoma Manufacturing Alliance Listed by Booba Project Ransomware GroupIncredible Technologies Listed by Booba Project Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Federis Abogados Listed by Booba Project Ransomware Group →
Publicly posted by booba-project — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.