Kassin & Carrow Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Kassin & Carrow has been listed by the lynx ransomware group, which claims to have exfiltrated internal files. The listing appeared on 18 January 2025; an undisclosed number of individuals may be affected, and anyone connected to the firm should verify whether their data is involved and follow any guidance the organisation issues.
Ransomware groups continue to target professional services firms that hold concentrated stores of personal and legal information, using double-extortion tactics that combine encryption with public leak-site pressure. Against that backdrop, the law firm Kassin & Carrow appeared on a listing associated with the lynx ransomware group in mid-January 2025, drawing attention to the exposure risks faced by smaller regional practices and their clients.
Public reporting indicates that Kassin & Carrow was listed by the lynx ransomware group on or about 18 January 2025. The listing claims that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been made public. For clients and former clients of a personal-injury practice serving the St. Louis and Metro East Illinois region, the development raises practical questions about what information may have been taken and what steps are warranted.
Inside the incident
According to available public information, Kassin & Carrow was listed by the lynx ransomware group with a reported date of 18 January 2025. The group’s claim states that internal files were exfiltrated as part of a ransomware attack. No further technical details—such as the initial access vector, the duration of any intrusion, the volume of data taken, or whether systems were encrypted—have been disclosed in the material provided. The number of individuals potentially affected is listed as unknown. Beyond the group’s own listing, independent verification of the claims has not been reported in the facts available. As with many such incidents, the precise timeline and method remain undisclosed.
The group behind it: lynx
Lynx is a ransomware operation that has been publicly documented since mid-2024. Like other contemporary groups, it is understood to operate a ransomware-as-a-service model and to rely on double extortion: encrypting systems while also threatening to publish stolen data on a dedicated leak site if payment is not made. Public reporting on lynx has noted its use of standard initial-access techniques common to the broader ransomware ecosystem, including exploitation of exposed remote services and credential-based entry, followed by data staging and exfiltration before encryption. The group has previously listed a range of mid-sized organizations across professional services, manufacturing, and other sectors. In this case, the listing of Kassin & Carrow constitutes a claim by the group; the facts do not confirm independent validation of the volume or content of any stolen material beyond the assertion that internal files were exfiltrated.
Who is Kassin & Carrow?
Kassin & Carrow is a law firm that provides personal representation focused on clients in the St. Louis and Metro East Illinois area. Public description of the practice emphasizes individualized attention rather than high-volume case handling, with offices in Edwardsville, Illinois, and St. Peters, Missouri. The firm has served clients from surrounding communities including Wentzville, Warrenton, St. Charles, and Kirkwood. As a personal-injury and related civil practice, it operates in a sector that routinely collects and retains sensitive personal, medical, financial, and case-related information necessary to represent individuals seeking compensation or benefits. A ransomware incident affecting such a firm is consequential because the data held is often highly personal and because clients may have limited visibility into how their records are secured once entrusted to counsel.
The information in question
The facts state that the exposed material consists of “internal files exfiltrated in ransomware attack.” No more granular inventory—such as specific categories of documents, client lists, medical records, or financial data—has been publicly named. Organizations of this type typically maintain case files, correspondence, medical and billing records, identification details, and contact information for clients and opposing parties. Because the exact contents remain unconfirmed, it is not possible to state with certainty which of these categories, if any, were among the files claimed to have been taken. Readers should treat any assertion of precise data types beyond the general description of internal files as unverified.
What's at stake
For individuals whose information may have been among the internal files, the primary risks are identity-related misuse, targeted phishing or social-engineering attempts that reference real case details, and the longer-term possibility of fraud involving medical or financial records. Even when full data sets are not published, the mere fact of exfiltration can leave clients uncertain about exposure. For the firm itself, the incident carries operational disruption, potential regulatory and professional-responsibility obligations, reputational effects, and the cost of investigation and remediation. Because the number of affected people is unknown and the precise data types are not detailed, the scale of individual impact cannot be quantified from public information alone. The situation underscores the concentrated sensitivity of legal-practice data even when the victim organization is a regional rather than national firm.
What to do if you're exposed
If you are a current or former client of Kassin & Carrow, or believe your information may have been held by the firm, begin by monitoring financial and medical accounts for unusual activity and by treating unexpected communications that reference legal matters with heightened caution. Consider placing fraud alerts with major credit bureaus and reviewing any free annual credit reports for anomalies. Preserve any notices you receive from the firm and follow official guidance once it is issued. As a practical first check, you can run a free exposure scan of your email address against known breach data sets to determine whether your contact information has already appeared in previously documented incidents. Remain alert for phishing that exploits the publicity of the listing, and avoid sharing additional personal details in response to unsolicited requests.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ccedarvalleyservices.org Listed by lynx Ransomware GroupBounds Gillespie Killebrew Tushek Architects Listed by lynx Ransomware Groupwww.simmonsboardman.com Listed by lynx Ransomware GroupDavies, Mcfarland & Carroll Listed by lynx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Kassin & Carrow Listed by lynx Ransomware Group →
Publicly posted by lynx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.