LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lawsonlundell Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

Lawsonlundell Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 3, 2023
Lawsonlundell Listed by alphv Ransomware Group

Reported September 3, 2023.

HIGH
Severity
September 3, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Lawsonlundell Listed by alphv Ransomware Group (reported September 3, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target professional-services firms that hold concentrated stores of client and corporate information, turning law practices into high-value pressure points in the broader cyber-extortion economy. In early September 2023 one such listing appeared on a dark-web leak site operated by the group known as alphv, naming the Canadian business-law firm Lawsonlundell.

Public reporting on 3 September 2023 stated that alphv claimed to have exfiltrated internal files from Lawsonlundell in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been released. For clients, counterparties and staff of a full-service firm operating across Western and Northern Canada, the claim alone raises concrete questions about what may have left the firm’s systems and what practical steps follow.

Breaking down the breach

According to the available record, Lawsonlundell was listed by the alphv ransomware group on or about 3 September 2023. The group asserted that internal files had been exfiltrated during a ransomware attack. No public figure has been given for the volume of data, the number of individuals whose information may be involved, or the precise date the intrusion began. Technical details of the initial access method, dwell time, or encryption impact have not been disclosed in the material provided. The listing itself constitutes an unverified claim by the threat actor; organisations named on such sites sometimes negotiate, sometimes dispute the assertion, and sometimes confirm limited impact only after internal investigation. At the time of the report, none of those outcomes had been publicly detailed for this incident.

Inside alphv

Alphv, also tracked in open reporting as BlackCat, emerged as a prominent ransomware-as-a-service operation in late 2021. The group has typically recruited affiliates who gain initial access, deploy the ransomware payload, and share extortion proceeds with the core developers. Its operators have favoured double-extortion tactics: encrypting systems while simultaneously copying data and threatening to publish it on a dedicated leak site if payment is not made. Alphv has been observed using custom ransomware written in Rust, flexible encryption options, and polished negotiation portals. Prior public activity has included attacks on a range of sectors—manufacturing, logistics, professional services and critical infrastructure—often accompanied by countdown timers and staged file releases intended to increase pressure. Because the group’s leak-site posts are self-reported claims, each listing must be treated as an assertion rather than independently verified fact unless the victim organisation or law-enforcement agencies later corroborate it. Nothing in the present record indicates that alphv published sample files or a full archive specifically attributed to Lawsonlundell beyond the initial listing notice.

Who is Lawsonlundell?

Lawson Lundell LLP is a full-service business law firm with offices in Vancouver, Calgary and Yellowknife, serving clients across Western and Northern Canada and internationally. The firm’s public materials describe a practice that spans corporate, commercial, energy, natural resources, litigation and related advisory work for industry leaders and institutions. Law firms of this type routinely hold privileged correspondence, transaction documents, due-diligence materials, personal data of clients and employees, and confidential commercial strategies. A breach affecting such an organisation is consequential because the information is often sensitive by nature, subject to professional secrecy obligations, and potentially useful to competitors, litigants or criminals seeking leverage. Even when the precise contents of any exfiltrated set remain unconfirmed, the mere possibility that internal files left the firm’s control creates lasting uncertainty for those whose matters were handled there.

The information in question

The only data description supplied in the public summary is “internal files exfiltrated in ransomware attack.” No inventory of file types, client names, employee records or financial documents has been released. Organisations in the legal sector typically maintain matter files, emails, contracts, identity documents collected for know-your-client checks, billing records and internal administrative data. Whether any of those categories were among the material alphv claims to hold is unconfirmed. Readers should therefore treat every specific data element as unverified until the firm or competent authorities provide a clearer accounting.

What's at stake

For individuals, the practical risks centre on misuse of personal or financial details that may have been present in internal files—identity fraud, targeted phishing that references real legal matters, or reputational harm if sensitive personal circumstances become public. For corporate clients the exposure could include competitive intelligence, negotiation positions or unfinished transactions. For the firm itself the stakes include regulatory notification duties, potential civil claims, erosion of client trust, and the operational cost of investigation and remediation. Because the scale remains unknown, the prudent assumption is that anyone who has been a client, employee or close counterparty in recent years should monitor for unusual activity rather than assume they were unaffected. None of these consequences has been established as having materialised; they are the ordinary downstream possibilities that follow an unverified exfiltration claim of this kind.

What to do if you're exposed

If you have reason to believe your information may have been held by Lawsonlundell, begin by enabling multi-factor authentication on email and financial accounts, and watch for unexpected password-reset messages or invoices that reference real legal matters. Consider placing a fraud alert with credit bureaus if you are in a jurisdiction that offers that service, and retain any suspicious correspondence for later reference. Free exposure-scan tools can check whether your email address already appears in indexed breach data sets; running such a scan provides a quick, low-effort baseline. Finally, follow any official guidance the firm itself issues once its investigation advances, and report confirmed identity theft to local authorities promptly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLawsonlundell security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Lawsonlundell’s full breach history →

More recent breaches

Wesgar Inc Listed by alphv Ransomware GroupDecember 28, 2023royaleinternational.com Listed by alphv Ransomware GroupDecember 2, 2023Lisa Mayer CA, Professional Corporation Listed by alphv Ransomware GroupDecember 2, 2023Vertex Resource Group Listed by alphv Ransomware GroupNovember 27, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Lawsonlundell Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram