Garlick & Markison Listed by losttrust Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Garlick & Markison Listed by losttrust Ransomware Group (reported September 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Garlick & Markison, a boutique U.S. law firm focused on patent portfolio work, was listed by the ransomware group losttrust in a claim reported on September 26, 2023. Public detail remains limited: the number of people affected is unknown, and the only description of what was taken refers to internal files said to have been exfiltrated in a ransomware attack. The listing itself is an unverified claim by the group.
For clients, counterparties, and anyone whose information may have been held by the firm, the incident raises ordinary but serious questions about what was exposed and what practical steps follow. No confirmed scale, method, or full inventory of records has been made public.
Breaking down the breach
According to the reported summary, Garlick & Markison appeared on a losttrust leak-site listing dated September 26, 2023. The group claims that internal files were exfiltrated as part of a ransomware attack. No further operational detail—how access was obtained, how long the intrusion lasted, whether encryption was also deployed, or whether any ransom demand was paid—has been disclosed in the available record.
The number of individuals or entities affected is listed as unknown. No file counts, data volumes, or specific document categories beyond the general reference to “internal files” have been published. Because the sole public signal is the group’s own listing, the claim that a breach occurred and that data left the firm’s systems remains unverified by independent confirmation in the facts provided.
Who is losttrust?
losttrust is a ransomware operation that has appeared in public reporting as a double-extortion actor. Groups of this type typically gain access to a victim network, exfiltrate data, and then threaten to publish or auction the material if a ransom is not paid. They commonly maintain leak sites where they name victims and, in some cases, release sample files to pressure payment.
Public documentation of losttrust activity shows the familiar pattern of claiming responsibility for intrusions, posting victim names, and asserting that internal data has been stolen. Nothing in the available facts indicates that losttrust made additional specific statements about Garlick & Markison beyond the listing itself and the assertion that internal files were exfiltrated. That listing should be treated as the group’s claim rather than as independently verified fact.
About Garlick & Markison
Garlick & Markison is described as a boutique law firm that specializes in building patent portfolios for its clients. Each practitioner is registered with the U.S. Patent and Trademark Office and brings a background in electrical engineering or the software arts. Firms of this kind routinely handle invention disclosures, draft patent applications, manage prosecution before the USPTO, and advise on intellectual-property strategy.
Because the work centers on technical inventions and client competitive positions, the firm necessarily holds confidential technical descriptions, inventor and client identifying information, correspondence, and related legal work product. A breach at such an organization is consequential precisely because the material is often sensitive, long-lived, and of interest both to commercial rivals and to anyone seeking to misuse personal or corporate data.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No itemized list of data types—such as client names, inventor details, patent drafts, financial records, or employee information—has been disclosed. Exact contents therefore remain unconfirmed.
Organizations of this type typically maintain client and inventor contact data, technical invention disclosures, draft and filed patent applications, billing and engagement records, and internal correspondence. Whether any or all of those categories were among the files claimed by losttrust is not established in the public record. Readers should treat the scope of exposure as unknown until more precise information is released by the firm or by regulators.
Why it matters
If internal files from a patent-focused law firm were taken, the practical risks are concrete. Clients could face exposure of unpublished technical ideas, weakening of patent positions, or targeted follow-on phishing that uses genuine case details. Individuals whose names, contact information, or personal identifiers appear in those files could encounter identity-related misuse or social-engineering attempts. The firm itself faces potential regulatory notification duties, reputational harm, and the cost of investigation and remediation.
Because the number of people affected is unknown and the precise data types are undisclosed, it is not possible to quantify the population at risk. The absence of detail does not eliminate the need for caution; it simply means affected parties must rely on general protective steps until clearer inventories emerge.
Were you affected?
If you are a client, inventor, employee, or counterpart who has dealt with Garlick & Markison, treat the possibility of exposure seriously while recognizing that public confirmation is still limited. Practical first steps include:
- Monitor account statements, credit reports, and USPTO or related correspondence for unexpected activity.
- Be alert to phishing or social-engineering messages that reference patent matters, the firm’s name, or technical details only a real insider would know.
- Change passwords on any accounts that may have been used in communications with the firm, and enable multi-factor authentication where available.
- Request information directly from the firm about whether your data was involved once it completes its investigation and any required notifications.
- Consider placing fraud alerts or credit freezes if you believe sensitive personal identifiers may have been held.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That check will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant the same protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Popovici Niu Stoica & Asociaii Listed by losttrust Ransomware GroupCarnelutti Law Firm Listed by losttrust Ransomware GroupSydganCorp Listed by losttrust Ransomware GroupLeiblein & Kollegen Steuerberatungsgesellschaft Listed by losttrust Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Garlick & Markison Listed by losttrust Ransomware Group →
Publicly posted by losttrust — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.