Lepant Law Office Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Lepant Law Office was listed by the qilin ransomware group on March 17, 2025 after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may have been affected; anyone connected to the firm should review their records and take appropriate protective steps.
On March 17, 2025, Lepant Law Office was listed by the ransomware group known as qilin, according to public reporting on the incident. The listing indicates that the Nebraska law firm was the target of a ransomware attack in which internal files were claimed to have been exfiltrated. The number of people affected remains unknown, and public detail on the full scope of the event is limited.
Law firms hold sensitive client and operational records by nature of their work. A claimed ransomware listing of this kind therefore raises practical questions for anyone who has dealt with the firm, even while many specifics stay unconfirmed.
Breaking down the breach
Public reporting states that Lepant Law Office, also referenced as PC or LLO, appeared on a qilin leak site. The available summary describes the firm as a successor to the law offices of Merrell Andersen and the partnerships in which he practiced over a thirty-five-year career as a Nebraska attorney, with David Lepant continuing that practice. The only data description provided is that internal files were allegedly exfiltrated in a ransomware attack. No confirmed figure for the volume of data, no list of specific file categories beyond the general label “internal files,” no exact date of intrusion or encryption, and no statement of whether systems were restored or ransoms demanded have been disclosed in the material available. The number of individuals potentially affected is listed as unknown. All that can be stated with certainty from the record is the reported listing date of March 17, 2025, the firm’s identity, and the claim of internal-file exfiltration.
The group behind it: qilin
Qilin is a ransomware operation that has operated for several years under a ransomware-as-a-service model. Public reporting on the group consistently describes a double-extortion approach: data is stolen before systems are encrypted, after which the group threatens to publish the material if payment is not made. Affiliates typically gain initial access through common vectors such as compromised credentials, phishing, or exploitation of exposed remote services, then move laterally and exfiltrate files before deploying the encryptor. Qilin has previously listed victims across multiple sectors and geographies on its leak site; those listings function as pressure tactics and are claims by the group rather than independently verified confirmations. In the present case, the appearance of Lepant Law Office on the site is therefore treated as an unverified claim by qilin that it holds data belonging to the firm. No additional statements attributed specifically to qilin about this victim—such as sample file names, ransom amounts, or deadlines—appear in the available facts.
Lepant Law Office and its sector
Lepant Law Office is a Nebraska law practice that succeeded the offices of Merrell Andersen. Legal practices of this type routinely handle client intake records, correspondence, contracts, court filings, financial documents related to retainers and billing, and other materials that may contain personal identifiers, financial details, and confidential legal strategy. Even a small or mid-sized firm can accumulate years of such records. A ransomware incident affecting a law office is consequential because the data at stake is often subject to attorney-client privilege and professional confidentiality rules, and because clients may have no ready alternative source for the same documents. The firm’s regional focus does not reduce the sensitivity of the material it holds; it simply means the potential impact is concentrated among Nebraska clients and counterparties who have relied on the practice.
The information in question
The only description given in the reporting is that internal files were allegedly exfiltrated. No further breakdown—such as whether client files, employee records, financial ledgers, or email archives were involved—has been publicly confirmed. Organizations of this kind typically retain client contact information, case-related documents, billing records, and internal administrative files. Because the precise contents remain unconfirmed, it is not possible to state which of those categories, if any, were taken. Readers should treat any assertion of specific data types beyond the general label “internal files” as unverified until the firm or independent investigators provide additional detail.
Why it matters
For individuals whose information may have been among the internal files, the practical risks include identity theft, targeted phishing that references genuine case details, and unauthorized use of financial or personal data. Even if the firm later recovers systems, the exfiltrated copies remain outside its control once stolen. For the firm itself, the incident can disrupt ongoing client work, trigger notification and regulatory obligations, and require costly forensic and recovery efforts. Because the number of affected people is unknown and the exact data set is undisclosed, the full extent of these risks cannot yet be measured; the absence of numbers does not eliminate the possibility of harm to clients or staff whose records were stored on the compromised systems.
If your data was in this claimed breach
If you have been a client, opposing party, or employee of Lepant Law Office, treat the listing as a reason to take basic protective steps. Monitor bank and credit accounts for unexpected activity, place fraud alerts if you believe sensitive identifiers were involved, and be alert to phishing messages that appear to reference legitimate legal matters. Change passwords on any accounts that may have shared credentials with firm systems, and enable multi-factor authentication where available. Because public confirmation of exact data contents is still lacking, these measures are precautionary rather than responses to a fully documented exposure list. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan does not prove or disprove involvement in this specific incident, but it can surface other exposures that warrant attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Marta Montserrat Areny Guerrero ABOGADO Listed by qilin Ransomware Groupcamaradealmeria.com Listed by qilin Ransomware Groupenvac.es Listed by qilin Ransomware Groupjoseantoniorodriguez.com Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Lepant Law Office Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.