Law Offices of R. David Williams, P.A. Listed by Rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Law Offices of R. David Williams, P.A. was listed by the Rhysida ransomware group on September 30, 2026. The group claims to hold data on an undisclosed number of people; anyone who may have been a client should review their own records and consider protective steps.
Rhysida, a ransomware and extortion group, has listed Law Offices of R. David Williams, P.A. on its leak site, according to a report dated September 30, 2026. The listing presents the firm as a target and describes purported practice materials; it does not constitute independent confirmation that systems were compromised or that any files left the firm’s control. As of writing, the firm has not publicly confirmed the claim.
Public detail is limited. The number of people affected is unknown, and the listing does not supply a verified inventory of what, if anything, was taken. For clients, opposing counsel, and others who may have dealt with a criminal-defense practice, a leak-site claim still warrants attention because of the sensitivity of the records such firms typically handle—if any were obtained.
Inside the listing
The available report states that Rhysida listed Law Offices of R. David Williams, P.A., with a headline framing the firm as listed by the group. The reported summary on the listing claims “Law Offices of R. David Williams, P.A. Contents” and describes what it calls a complete dossier of the firm’s criminal defense practice covering roughly 175 or more clients. According to that same listing text, the claimed material includes references to felonies (with named matters the group associates with undercover activity involving a minor, domestic violence and robbery involving a young child, felony DUI, and fraud), a core caseload of about ten DUI matters (including an arrest the listing ties to low breath readings and SCRAM alcohol monitoring), violations of probation, FDLE expungement packets with FD-258 fingerprint cards, a “red flag” Risk Protection Order, two clients said to be in ICE custody, and a material witness.
Timing of any intrusion, method of access, ransom demand, proof packages, and whether files were actually exfiltrated are not disclosed in the facts provided. Scale beyond the listing’s own marketing language is unconfirmed. People affected remain unknown. Data types are recorded as not disclosed in the structured record, even though the group’s summary text markets a narrative about case files; that narrative is the claimant’s description, not a confirmed catalogue. Nothing in the public record supplied here establishes that the named matters or individuals’ files were in fact copied or published.
Who is Rhysida?
Rhysida is a known ransomware operation that has appeared in public reporting since 2023. Like other double-extortion crews, it has typically encrypted victim environments and threatened to publish stolen data on a dedicated leak site if payment is not made. Listings on such sites are pressure tools: they name organizations, sometimes post sample files, and set countdowns to encourage negotiation. Attribution on a leak site is a claim by the operators; it is not the same as a regulator finding, a company admission, or a forensic confirmation.
Public coverage of Rhysida has associated the group with attacks across sectors, including healthcare, education, government-adjacent entities, and professional services, often using phishing or exposed remote access as initial vectors in broader industry reporting. Those patterns describe how the group has operated elsewhere. They do not prove what happened in this specific listing. For Law Offices of R. David Williams, P.A., the only incident-specific assertion in the given facts is that Rhysida listed the firm and published the summary language described above. No confirmed technical indicators, negotiation timeline, or independent validation are included in those facts.
About Law Offices of R. David Williams, P.A.
Law Offices of R. David Williams, P.A. is identified in the report as a law practice. Firms of this type commonly represent individuals in criminal and related matters. In general, criminal-defense practices may hold charging documents, discovery, correspondence with prosecutors and courts, client intake and identity information, financial and bail records, probation and monitoring materials, expungement or sealing packets, and notes that can touch family members, witnesses, and law-enforcement contacts. Immigration-related custody issues and protective orders, when present in a caseload, can add further sensitive personal detail.
A leak-site listing naming such a firm is consequential because the work product, if genuine and if obtained, would often involve people already in contact with the justice system, for whom stigma, safety, and due-process interests are acute. That consequence follows from the nature of the sector and from the group’s claim—not from any verified proof in the facts that particular files moved. The listing does not, by itself, establish negligence, weak controls, or any other judgment about how the firm runs its practice.
What was likely exposed
The structured facts state that data types named as exposed are not disclosed, and the number of people affected is unknown. The Rhysida listing text claims a broad criminal-defense dossier and enumerates categories and matter labels; those are attacker marketing claims, not an audited inventory. It is not established which, if any, records were taken or published.
If files from a criminal-defense practice were obtained, organizations in this sector typically hold client identifying information, case files, court and agency forms, fingerprint cards used in expungement processes, monitoring and probation records, and materials that may reference minors, domestic situations, immigration custody, or witnesses. Any discussion of risk for this incident remains conditional: if materials matching the listing’s description were allegedly exfiltrated, those are the kinds of records that would matter; the exact contents here are unconfirmed. Readers should not treat the group’s dossier narrative as a verified list of what is in circulation.
Why it matters
For individuals who have been clients or otherwise appear in defense files, the practical stakes—if data were allegedly stolen and released—can include embarrassment, harassment, doxxing, interference with ongoing cases, or misuse of identity documents and biometric-related paperwork. Mentions of minors, domestic violence, protective orders, or immigration custody raise heightened safety and privacy concerns even when only alleged. Opposing parties, employers, or others who obtain case detail could use it unfairly. None of that is proof that any specific person’s file is exposed in this matter; it is why a claim against a criminal-defense firm draws attention.
For the firm, an extortion listing can mean reputational pressure, client anxiety, and possible regulatory or ethical follow-up if a breach were later confirmed. A leak-site entry alone does not settle those questions. It shows that a known extortion group chose to name the practice and to advertise alleged contents. What a listing establishes is the existence of a public claim and the need for careful, conditional vigilance—not a completed factual finding that data left the firm or that particular clients are affected.
Steps worth taking either way
If you have been a client or had close involvement with the firm, consider practical steps without assuming your information is already public. Watch for unexpected contact that references case details; verify any outreach through known firm channels rather than links or numbers in unsolicited messages. Review financial and identity accounts for unusual activity if you shared sensitive personal data in the course of representation. If you have reason to believe specific sealed, expunged, or safety-related information could be involved, discuss options with counsel you trust. Preserve copies of important notices and avoid circulating unverified “leak” files, which can spread private material further and may be incomplete or fabricated.
The firm has not publicly confirmed this incident as of writing, and public detail on scope remains limited. Treat Rhysida’s listing as an unverified claim. As a general precaution, readers can run a free exposure scan of their email addresses to check whether those addresses have already appeared in other known breach datasets, and can tighten unique passwords and multi-factor authentication on accounts that matter most. Those steps are sensible whether or not this particular listing ever proves out.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
NEAD Pro Listed by Rhysida Ransomware GroupLegis Listed by Rhysida Ransomware GroupKreishandwerkerschaft Borken Listed by Rhysida Ransomware GroupMPA Pharma Listed by Rhysida Ransomware GroupLatest breaches
Publicly posted by rhysida — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.