Lawsonlundell Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Lawsonlundell Listed by alphv Ransomware Group (reported September 3, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target professional-services firms that hold concentrated stores of client and corporate information, turning law practices into high-value pressure points in the broader cyber-extortion economy. In early September 2023 one such listing appeared on a dark-web leak site operated by the group known as alphv, naming the Canadian business-law firm Lawsonlundell.
Public reporting on 3 September 2023 stated that alphv claimed to have exfiltrated internal files from Lawsonlundell in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been released. For clients, counterparties and staff of a full-service firm operating across Western and Northern Canada, the claim alone raises concrete questions about what may have left the firm’s systems and what practical steps follow.
Breaking down the breach
According to the available record, Lawsonlundell was listed by the alphv ransomware group on or about 3 September 2023. The group asserted that internal files had been exfiltrated during a ransomware attack. No public figure has been given for the volume of data, the number of individuals whose information may be involved, or the precise date the intrusion began. Technical details of the initial access method, dwell time, or encryption impact have not been disclosed in the material provided. The listing itself constitutes an unverified claim by the threat actor; organisations named on such sites sometimes negotiate, sometimes dispute the assertion, and sometimes confirm limited impact only after internal investigation. At the time of the report, none of those outcomes had been publicly detailed for this incident.
Inside alphv
Alphv, also tracked in open reporting as BlackCat, emerged as a prominent ransomware-as-a-service operation in late 2021. The group has typically recruited affiliates who gain initial access, deploy the ransomware payload, and share extortion proceeds with the core developers. Its operators have favoured double-extortion tactics: encrypting systems while simultaneously copying data and threatening to publish it on a dedicated leak site if payment is not made. Alphv has been observed using custom ransomware written in Rust, flexible encryption options, and polished negotiation portals. Prior public activity has included attacks on a range of sectors—manufacturing, logistics, professional services and critical infrastructure—often accompanied by countdown timers and staged file releases intended to increase pressure. Because the group’s leak-site posts are self-reported claims, each listing must be treated as an assertion rather than independently verified fact unless the victim organisation or law-enforcement agencies later corroborate it. Nothing in the present record indicates that alphv published sample files or a full archive specifically attributed to Lawsonlundell beyond the initial listing notice.
Who is Lawsonlundell?
Lawson Lundell LLP is a full-service business law firm with offices in Vancouver, Calgary and Yellowknife, serving clients across Western and Northern Canada and internationally. The firm’s public materials describe a practice that spans corporate, commercial, energy, natural resources, litigation and related advisory work for industry leaders and institutions. Law firms of this type routinely hold privileged correspondence, transaction documents, due-diligence materials, personal data of clients and employees, and confidential commercial strategies. A breach affecting such an organisation is consequential because the information is often sensitive by nature, subject to professional secrecy obligations, and potentially useful to competitors, litigants or criminals seeking leverage. Even when the precise contents of any exfiltrated set remain unconfirmed, the mere possibility that internal files left the firm’s control creates lasting uncertainty for those whose matters were handled there.
The information in question
The only data description supplied in the public summary is “internal files exfiltrated in ransomware attack.” No inventory of file types, client names, employee records or financial documents has been released. Organisations in the legal sector typically maintain matter files, emails, contracts, identity documents collected for know-your-client checks, billing records and internal administrative data. Whether any of those categories were among the material alphv claims to hold is unconfirmed. Readers should therefore treat every specific data element as unverified until the firm or competent authorities provide a clearer accounting.
What's at stake
For individuals, the practical risks centre on misuse of personal or financial details that may have been present in internal files—identity fraud, targeted phishing that references real legal matters, or reputational harm if sensitive personal circumstances become public. For corporate clients the exposure could include competitive intelligence, negotiation positions or unfinished transactions. For the firm itself the stakes include regulatory notification duties, potential civil claims, erosion of client trust, and the operational cost of investigation and remediation. Because the scale remains unknown, the prudent assumption is that anyone who has been a client, employee or close counterparty in recent years should monitor for unusual activity rather than assume they were unaffected. None of these consequences has been established as having materialised; they are the ordinary downstream possibilities that follow an unverified exfiltration claim of this kind.
What to do if you're exposed
If you have reason to believe your information may have been held by Lawsonlundell, begin by enabling multi-factor authentication on email and financial accounts, and watch for unexpected password-reset messages or invoices that reference real legal matters. Consider placing a fraud alert with credit bureaus if you are in a jurisdiction that offers that service, and retain any suspicious correspondence for later reference. Free exposure-scan tools can check whether your email address already appears in indexed breach data sets; running such a scan provides a quick, low-effort baseline. Finally, follow any official guidance the firm itself issues once its investigation advances, and report confirmed identity theft to local authorities promptly.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Wesgar Inc Listed by alphv Ransomware Grouproyaleinternational.com Listed by alphv Ransomware GroupLisa Mayer CA, Professional Corporation Listed by alphv Ransomware GroupVertex Resource Group Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Lawsonlundell Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.