LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › gregjoneslaw.com Listed by Settra Ransomware Group

HIGH severityUnverified claimHow we verify

gregjoneslaw.com Listed by Settra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 22, 2026
gregjoneslaw.com Listed by Settra Ransomware Group

Occurred September 2026 · publicly disclosed September 22, 2026.

HIGH
Severity
September 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

gregjoneslaw.com was listed by the Settra ransomware group on 22 September 2026. Individuals whose information may have been obtained should check the organisation’s site or contact it directly for guidance.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to pressure organisations by posting names on leak sites before any independent confirmation exists. In that climate, a listing is a public claim, not a verified incident report. On September 22, 2026, the group known as Settra listed gregjoneslaw.com on its leak site. The company has not publicly confirmed the claim as of writing. For clients, staff, and others who may have dealt with Greg Jones & Associates, P.A., the practical question is what a leak-site claim does and does not establish, and what cautious steps make sense if sensitive material were ever involved.

Public detail in the listing is thin. The number of people potentially affected is unknown, and the types of data the group says it holds are not disclosed in the material available for this account. What appears is a partial document-oriented description referencing Greg Jones & Associates, P.A., and fragmentary text that reads like the opening of a file rather than a full inventory. That is marketing language from an extortion channel, not a claimed breach record.

Inside the listing

According to the listing, Settra has named gregjoneslaw.com and associated the entry with documents tied to Greg Jones & Associates, P.A. The reported summary fragment begins along the lines of a “PROLOGUE” and mentions an anonymous $250,000 loan from “Skeeter,” then cuts off. No full file list, no volume figures, no method of intrusion, and no confirmed timeline beyond the September 22, 2026 report date are provided in the facts at hand.

Settra’s listing is therefore best read as an unverified claim that the group possesses material and may publish or auction it unless its demands are met. Leak-site posts are sometimes exaggerated, recycled from older incidents, or false. Nothing in the available record confirms that systems were compromised, that files left the firm, or that any particular client matter is in third-party hands. The company has not publicly confirmed the claim as of writing.

The group behind it: Settra

Settra is known in public reporting as a ransomware and extortion actor that follows a familiar pattern: encrypt or exfiltrate data, then threaten publication on a dedicated leak site to coerce payment. Groups in this category typically post victim names, countdown timers, and sample files or descriptions meant to prove access. Those samples and descriptions are controlled by the claimant; they are not independent audits.

Well-documented behaviour across similar crews includes double-extortion messaging, pressure on professional-services firms that hold confidential client work, and periodic dumps if negotiations stall. For this specific listing, only what appears on the Settra page about gregjoneslaw.com should be attributed to the group: it claims association with documents from Greg Jones & Associates, P.A., and offers a truncated narrative snippet. No further Settra statements about this victim are established in the facts provided here.

Who is gregjoneslaw.com?

gregjoneslaw.com is the web presence associated with Greg Jones & Associates, P.A., a law firm. Firms of this kind handle client intake, case files, correspondence, billing, and often identity and financial details needed for representation. Legal practices are attractive targets for extortion groups because confidentiality is central to the work and because even the appearance of exposure can unsettle clients.

A leak-site listing naming a law firm matters because trust and privilege expectations are high, not because any particular allegation has been proven. Consequence here is conditional: if client or firm records were ever taken, the sensitivity would be real; if the listing is empty theatre, the main harm is reputational noise and anxiety. Public confirmation from the firm or a regulator would be required before treating the event as established fact.

The information in question

The facts state that data types named as exposed are not disclosed. The listing’s own summary points at “documents” and a fragmentary prologue text; that is the attacker’s framing, not a verified catalogue. It is not established which files, if any, were copied, nor whether the fragment is genuine, complete, or representative.

If files from a law practice were taken, organisations in this sector typically hold materials such as client contact data, case narratives, contracts, discovery, invoices, and sometimes government ID or banking details used in matters. Those categories are sector norms, not a statement of what Settra holds in this case. Exact contents remain unconfirmed. Readers should not assume their own matter is included.

What's at stake

For individuals, the conditional risks are familiar: if personal or case-related information may have been exposed, possible outcomes include targeted phishing that references real matter details, attempts at identity misuse, or embarrassment if private disputes became public. None of that is confirmed for this listing. For the firm, stakes include client concern, possible regulatory or ethical inquiries if a breach were later substantiated, and the operational cost of investigation—again, only if the claim proves substantive.

A leak-site name alone does not prove negligence, does not prove exfiltration, and does not inventory victims. It establishes that a known extortion brand chose to publish an accusation on a given date. Treating the claim as settled fact would overstate the evidence and could mislead people about their own exposure.

Steps worth taking either way

If you have been a client or employee of Greg Jones & Associates, P.A., sensible precautions do not require accepting Settra’s claim as true. Watch for unexpected messages that cite your case, the firm, or personal details you have only shared in confidence; verify any payment or document requests through a channel you already trust. Consider placing fraud alerts with major credit bureaus if you have reason to worry about identity data, and keep records of unusual contact. The firm’s own notices, if any appear, should take priority over criminal leak-site text.

Either way, it is reasonable to check whether your email addresses already appear in known breach corpora from unrelated incidents. Free exposure scans of your email can show whether your information has surfaced in previously documented dumps, which helps separate general internet risk from this specific, still-unconfirmed listing. Stay calm, treat Settra’s post as a claim, and respond to verified guidance from the organisation or official authorities if they issue any.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companygregjoneslaw.com security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See gregjoneslaw.com’s full breach history →

More recent breaches

quantummarketing-group.com Listed by Settra Ransomware GroupSeptember 22, 2026universalautogroup.com Listed by Settra Ransomware GroupSeptember 22, 2026lakebeverage.com Listed by Settra Ransomware GroupSeptember 22, 2026moscone.com Listed by Settra Ransomware GroupSeptember 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the gregjoneslaw.com Listed by Settra Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by settra — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram