LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › kap.co.th Listed by lockbit5 Ransomware Group

HIGH severityUnverified claimHow we verify

kap.co.th Listed by lockbit5 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·November 10, 2025
kap.co.th Listed by lockbit5 Ransomware Group

Reported November 10, 2025.

HIGH
Severity
November 10, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

kap.co.th has been listed by the lockbit5 ransomware group, which claims to have exfiltrated internal files; the listing was reported on November 10, 2025. Anyone who has shared data with kap.co.th should verify whether their information was exposed and take steps to protect their accounts.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who have dealt with Kudun and Partners, a Thai law firm operating as kap.co.th, may now face uncertainty about whether their personal or business information has been taken. On 10 November 2025 the ransomware group lockbit5 listed the firm on its leak site, claiming to have stolen internal files. The number of people affected remains unknown, and public detail about exactly what was taken is limited. For clients, staff and counterparties, that uncertainty itself creates practical risk: documents held by a law firm often contain sensitive personal, financial and legal material that can be misused long after the initial incident.

This article sets out only what has been reported, places the claim in context, and outlines the concrete steps anyone who may be affected can take. No confirmed confirmation of the breach has been issued beyond the group’s listing, so the account below treats the listing as an unverified claim.

Breaking down the breach

According to the available record, kap.co.th was listed by the lockbit5 ransomware group on 10 November 2025. The group claims that internal files were exfiltrated during a ransomware attack. No further public detail has been released about the date the intrusion began, the method of entry, the volume of data taken, or whether systems were encrypted in addition to the claimed theft. The number of people whose information may be involved is listed as unknown. The only data type named is “internal files.” Beyond that single description, the contents of the claimed haul remain undisclosed.

Because the information originates from a ransomware leak-site listing rather than from a confirmed disclosure by the firm or an independent investigator, it must be treated as a claim until verified. No ransom demand figure, no sample file dumps, and no timeline of negotiations have been made public in the material available for this report.

Inside lockbit5

LockBit is a well-documented ransomware-as-a-service operation that has operated for several years under successive rebrands and affiliate models. The group typically gains initial access through phishing, compromised credentials or unpatched remote services, then deploys encryption tools while simultaneously copying data for double-extortion leverage. Victims who refuse to pay are threatened with publication of the stolen material on a dedicated leak site. Affiliates share profits with the core developers, which has allowed the brand to persist even after law-enforcement disruptions of earlier iterations.

Public reporting on LockBit variants, including later numbered releases such as lockbit5, shows a consistent pattern: high-volume targeting of mid-sized professional-services firms, law practices and other organisations that hold large volumes of confidential client data. The group’s leak sites have historically listed victims with brief descriptions of the claimed data and occasional sample files. In this instance the listing for kap.co.th follows that established pattern, but no additional claims specific to this victim—beyond the assertion that internal files were exfiltrated—have been recorded in the facts available.

Who is kap.co.th?

kap.co.th is the online presence of Kudun and Partners, a law firm established in Thailand in 2015. Like most commercial law practices, it advises corporate and individual clients on transactions, disputes, regulatory matters and related legal work. Firms of this type routinely hold client identification documents, contracts, correspondence, financial records, litigation files and other material that is both commercially sensitive and personally identifiable.

A breach at a law firm is consequential because the data it stores is rarely limited to a single individual; it often includes information about counterparties, employees, family members and business partners. Even when the precise contents of a claimed theft remain unconfirmed, the mere possibility that such material has left the firm’s control raises legitimate concerns for anyone who has shared confidential information with the practice.

What was likely exposed

The only data type named in the public record is “internal files exfiltrated in ransomware attack.” No inventory of specific document categories, no count of records, and no confirmation of personal identifiers have been released. Organisations of this kind typically maintain client files containing names, contact details, national identification numbers, bank or payment information, contracts, emails and case-related documents. Whether any of those categories were among the files claimed by lockbit5 is unconfirmed.

Until the firm or an independent source publishes a verified list, it is not possible to state with certainty what was taken. Readers should therefore treat any assumption about particular data types as speculative.

Why it matters

For individuals whose information may be involved, the practical risks include identity fraud, targeted phishing that references real legal matters, and the unauthorised disclosure of private disputes or financial arrangements. Even incomplete files can be pieced together with data from other breaches to create convincing social-engineering attacks. For the firm itself, the incident—if confirmed—can damage client trust, trigger regulatory scrutiny under Thailand’s personal-data protection rules, and impose costs for forensic investigation, notification and remediation.

Because the number of affected people is unknown and the exact contents remain undisclosed, the scale of these risks cannot yet be quantified. The absence of detail does not eliminate the possibility of harm; it simply means affected parties must act on the basis of prudent caution rather than precise knowledge.

What to do if you're exposed

If you have been a client, employee or counterpart of Kudun and Partners, begin by monitoring bank and credit accounts for unusual activity and by treating any unexpected emails or calls that reference your legal matters with heightened suspicion. Consider placing fraud alerts with relevant credit bureaus where available, and change passwords on any accounts that may have shared credentials with the firm. Keep records of any suspicious contact so they can be reported to local authorities or the firm’s designated contact point if one is published.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can indicate whether your details are circulating more widely and help you prioritise further protective steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companykap.co.th security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See kap.co.th’s full breach history →

More recent breaches

amc.co.th Listed by lockbit5 Ransomware GroupJune 20, 2026saico.co.th Listed by lockbit5 Ransomware GroupJune 17, 2026ritta.co.th Listed by lockbit5 Ransomware GroupMay 1, 2026gccservices.eu Listed by lockbit5 Ransomware GroupDecember 25, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the kap.co.th Listed by lockbit5 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lockbit5 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram