LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lawsoft Listed by thegentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

Lawsoft Listed by thegentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 19, 2025
Lawsoft Listed by thegentlemen Ransomware Group

Reported February 19, 2025.

HIGH
Severity
February 19, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Lawsoft was listed by thegentlemen ransomware group on 19 February 2025 after internal files were exfiltrated in a ransomware attack; the actual date of the intrusion has not been established. Individuals connected to the company should review any notifications from Lawsoft and consider changing credentials or enabling additional account protections.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details sit inside systems used by police, fire and emergency services may now have reason to pay attention. On February 19, 2025, the ransomware group known as thegentlemen listed Lawsoft as a victim, claiming it had exfiltrated internal files. Public reporting does not yet confirm how many individuals are affected or exactly what records left the company’s control, but the nature of Lawsoft’s work means any exposure could reach beyond the company itself into the agencies that rely on its software.

What is known so far is limited to the group’s claim and the fact that internal files are said to have been taken during a ransomware attack. No independent confirmation of the volume, the precise contents, or the method of intrusion has been published. For anyone who has ever interacted with a law-enforcement or emergency-services system that uses Lawsoft products, the practical question is whether their data was among those files and what that could mean for them.

Inside the incident

According to the public listing, Lawsoft was named by thegentlemen ransomware group on February 19, 2025. The group asserts that internal files were exfiltrated as part of a ransomware attack. Beyond that claim, key details remain undisclosed. The number of people affected is unknown. The exact date the intrusion began, how long the attackers remained inside the network, and whether encryption of systems occurred alongside the theft of data have not been confirmed in available reporting. No technical indicators of compromise or ransom demands have been released publicly. The incident is therefore known primarily through the group’s own leak-site entry rather than through verified forensic disclosure by the company or independent investigators.

Inside thegentlemen

thegentlemen is a ransomware operation that has appeared in public reporting as a group that combines data theft with encryption threats, a pattern commonly described as double extortion. Like other actors in this category, the group typically publishes victim names on a dedicated leak site and claims to hold stolen material that it will release if its demands are not met. Public accounts of the group’s activity describe the use of common initial-access techniques and the subsequent exfiltration of files before any ransom note is presented. Specific claims the group makes about any single victim, including Lawsoft, must be treated as unverified assertions until corroborated. Nothing in the available facts establishes that thegentlemen has released Lawsoft material or that its description of the stolen files is accurate; the listing itself is simply the group’s public statement that it holds data from the company.

Who is Lawsoft?

Lawsoft, also referred to as LawSoft, Inc., develops software used by law-enforcement and emergency-services agencies. Its products include Computer-Aided Dispatch systems, Records Management Systems, and Fire EMS platforms. These tools are designed to handle call-taking, incident reporting, records storage and data integration, often incorporating information from older legacy systems so that agencies can maintain a single operational picture. The company markets scalable and customizable solutions and emphasizes continuous U.S.-based support. Because its software sits inside the daily workflow of police, fire and medical-response organizations, Lawsoft systems routinely process operational records, personnel details and, in many cases, information about members of the public who interact with those agencies. A compromise at a vendor of this type therefore carries implications not only for the vendor’s own staff and contractors but also for the agencies that depend on its platforms and for the citizens whose data those agencies collect.

The information in question

The only data type named in connection with the incident is “internal files” said to have been exfiltrated during the ransomware attack. No further breakdown—such as employee records, customer contracts, source code, agency configuration files, or personally identifiable information belonging to the public—has been confirmed. Organizations that supply CAD, RMS and Fire EMS software typically hold a mixture of proprietary code, system configuration data, support tickets, employee information and, depending on contractual arrangements, copies or extracts of operational records supplied by client agencies. Whether any of those categories were among the files claimed by thegentlemen remains unconfirmed. Public detail is limited to the group’s assertion that internal material left Lawsoft’s control; the precise contents have not been independently verified or itemized.

What's at stake

For individuals, the practical risks depend entirely on what was actually taken. If employee or contractor records were included, those people face the ordinary consequences of credential and personal-data exposure: targeted phishing, identity-related fraud, or social-engineering attempts that reference their workplace. If any operational or citizen-related data from client agencies was present, the exposure could extend to people who have never heard of Lawsoft but whose names, addresses or incident details sit inside systems the company supports. For Lawsoft itself and for the agencies that use its products, the stakes include possible disruption of support services, loss of confidence among clients, and the need to examine whether any shared credentials or integration points were compromised. Because the scale and exact contents remain unknown, the full extent of these risks cannot yet be measured; they are real but currently unquantified.

What to do if you're exposed

Anyone who believes their information may have been held by Lawsoft or by an agency that uses its software should treat the situation as a possible exposure rather than a confirmed one. Begin by monitoring financial and government accounts for unusual activity and by enabling multi-factor authentication wherever it is available. Be alert to unexpected messages that reference law-enforcement or emergency-services matters, as these can be used in follow-on social-engineering attempts. If you are an employee or contractor of Lawsoft or a client agency, follow any guidance issued by your organization regarding password resets and device checks. Finally, you can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets; such a check will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant attention.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLawsoft security record
79/100
DoxxScan™ · Moderate doxx risk
B- 75Above-average record

2 reported incidents on record.

See Lawsoft’s full breach history →
RelatedMore incidents at Lawsoft

More recent breaches

InjectSense Listed by thegentlemen Ransomware GroupFebruary 19, 2025Hooke Laboratories Listed by thegentlemen Ransomware GroupJuly 1, 2026KlearNow.AI Listed by thegentlemen Ransomware GroupFebruary 8, 2026Infinite Tiers Group Listed by thegentlemen Ransomware GroupFebruary 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Lawsoft Listed by thegentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram