LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Law Offices of the Public Defender - New Mexico Listed by rhysida Ransomware Group

HIGH severityUnverified claimHow we verify

Law Offices of the Public Defender - New Mexico Listed by rhysida Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 19, 2024
Law Offices of the Public Defender - New Mexico Listed by rhysida Ransomware Group

Reported July 19, 2024.

HIGH
Severity
July 19, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Law Offices of the Public Defender - New Mexico Listed by rhysida Ransomware Group (reported July 19, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target public-sector and legal organisations that hold sensitive case and client records, using double-extortion tactics that combine encryption with the threat of data publication. In this landscape, listings on criminal leak sites have become a common way for attackers to pressure victims and advertise their activity. On 19 July 2024, the Law Offices of the Public Defender - New Mexico appeared on a site operated by the Rhysida ransomware group, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail about the incident is limited.

Because the organisation serves as New Mexico’s primary public defender for low-income defendants, any compromise of its systems raises concrete questions about the confidentiality of criminal-defence materials and the privacy of the people it represents. What follows is a factual account of what has been reported, what is known about the claimed actor, and the practical implications for those who may be affected.

Inside the incident

According to the available record, the Law Offices of the Public Defender - New Mexico was listed by the Rhysida ransomware group on 19 July 2024. The group’s claim states that internal files were exfiltrated in a ransomware attack. No further technical details—such as the initial access method, the duration of any intrusion, the volume of data taken, or whether systems were encrypted—have been publicly disclosed. The number of individuals whose information may have been involved is listed as unknown. Public reporting has not confirmed independent verification of the group’s claims, so the listing itself remains an unverified assertion by the attackers.

Organisations facing such listings typically receive ransom demands and a deadline before any data is published. Whether negotiations occurred, whether a ransom was paid, or whether any files have been released has not been stated in the public facts surrounding this incident. As a result, the precise scope and current status of the claimed breach cannot be established from available information.

Inside rhysida

Rhysida is a ransomware operation that emerged publicly in 2023 and has since been documented targeting a range of sectors, including healthcare, education, government, and professional services. Like many contemporary groups, it typically employs a double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. The group has been observed using phishing, exploitation of remote-access services, and other common initial-access techniques, though specific methods vary by campaign.

Rhysida maintains a Tor-based leak site where it posts victim names, sample files, and countdown timers. Listings are presented as proof of successful intrusion and data theft; however, independent confirmation of each claim is not always available. The group has previously listed public-sector and legal entities, reflecting a broader pattern in which ransomware operators seek organisations that hold regulated or highly sensitive personal data and that may face pressure to restore operations quickly. Nothing in the public facts for this incident goes beyond the group’s claim that the Law Offices of the Public Defender - New Mexico was a victim and that internal files were exfiltrated.

Who is Law Offices of the Public Defender - New Mexico?

The Law Offices of the Public Defender - New Mexico is the state’s largest law firm dedicated to representing low-income people facing criminal charges. Public-defender offices of this kind provide constitutionally required legal counsel to defendants who cannot afford private attorneys. Their work involves case files, investigative materials, client communications, court records, and related administrative data. Because they handle criminal-defence matters, the information they hold is often highly sensitive and subject to attorney-client privilege and other confidentiality obligations.

A breach affecting such an organisation is consequential for two reasons. First, the people served are frequently among the most vulnerable: they may already face legal jeopardy, limited resources, and heightened privacy concerns. Second, compromise of defence-related records can undermine trust in the justice system and create risks that extend beyond ordinary identity theft, including exposure of personal circumstances, witness details, or strategy materials. The organisation’s role as a statewide public defender amplifies the potential reach of any incident, even when exact numbers remain unknown.

The information in question

The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of data types—such as names, dates of birth, Social Security numbers, case numbers, medical records, or financial details—has been publicly named. Public detail is therefore limited to the general description of “internal files.”

Organisations of this kind typically maintain client intake records, case files, correspondence, court filings, investigative notes, and administrative documents that may contain personal identifiers and sensitive narrative information. Whether any of those categories were among the files claimed by Rhysida has not been confirmed. Readers should treat the exact contents as unconfirmed pending further official disclosure.

Why it matters

For individuals whose information may have been involved, the primary risks are misuse of personal data for fraud, social-engineering attacks that reference real case details, and long-term privacy harm if sensitive legal matters become public. Even without confirmed publication, the mere possibility that defence-related records left the organisation’s control can create lasting anxiety and practical complications for clients and their families.

For the organisation itself, a ransomware incident can disrupt case work, strain limited public resources, and require costly recovery and notification efforts. Reputational damage and potential regulatory or ethical scrutiny may follow, regardless of whether the attackers’ claims are fully verified. Because public-defender offices serve people who often lack alternative legal options, operational disruption can also affect access to counsel and the timely handling of criminal cases. These consequences are concrete even when the precise scale of the incident remains undisclosed.

Were you affected?

If you have been a client or have otherwise shared personal information with the Law Offices of the Public Defender - New Mexico, treat the situation cautiously until more official detail is available. Monitor financial accounts and credit reports for unexpected activity, be alert to unsolicited contacts that reference your legal matters, and consider placing fraud alerts or credit freezes if you believe sensitive identifiers may have been exposed. Preserve any official notices you receive from the organisation and follow their guidance on next steps.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Doing so provides one additional data point, though it cannot confirm or rule out involvement in this specific incident. Stay informed through official channels rather than relying solely on unverified claims circulating online.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLaw Offices of the Public Defender - New Mexico security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Law Offices of the Public Defender - New Mexico’s full breach history →

More recent breaches

The White Center Community Development Association Listed by rhysida Ransomware GroupAugust 13, 2024Southold Town Senior ServicesSouthold Police Department Listed by rhysida Ransomware GroupMarch 2, 2026United Keetoowah Band of Cherokee Indians in Oklahoma Listed by rhysida Ransomware GroupDecember 12, 2025The Maryland Department of Transportation Listed by rhysida Ransomware GroupSeptember 24, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Law Offices of the Public Defender - New Mexico Listed by rhysida Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by rhysida — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram