LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Levicoff Law Firm, P.C Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Levicoff Law Firm, P.C Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 5, 2024
Levicoff Law Firm, P.C Listed by medusa Ransomware Group

Reported December 5, 2024.

HIGH
Severity
December 5, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Levicoff Law Firm, P.C. was listed by the Medusa ransomware group on December 05, 2024, after internal files were taken in an attack whose timing has not been established. Anyone who may have shared personal information with the firm should review their accounts for unusual activity and follow official guidance from Levicoff Law Firm, P.C.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 5 December 2024 the Levicoff Law Firm, P.C. appeared on a listing published by the medusa ransomware group. For anyone who has dealt with the firm—clients in accident, employment or commercial disputes, opposing parties, or even staff—the practical stakes are immediate: internal files said to total 246.6 GB may now sit outside the firm’s control. How many people are affected remains unknown, and the precise contents of those files have not been independently confirmed.

Public detail is limited to the group’s own claims and a short organisational description. That scarcity itself matters; without verified counts or a clear inventory of records, individuals cannot yet know whether their own information is among the material the attackers say they took.

Breaking down the breach

According to the reported summary, the medusa group listed Levicoff Law Firm, P.C. on 5 December 2024 and stated that it had exfiltrated 246.6 GB of internal files in a ransomware attack. The number of people whose data may be involved is listed as unknown. No independent confirmation of the intrusion method, the exact date of compromise, or the full scope of systems affected has been made public. The group further claimed that “the poor leadership team begged us for 1000$ to solve their problem and keep their sensitive data safe,” though the statement trails off and has not been corroborated by the firm or by law-enforcement sources. All figures and assertions about volume and negotiations therefore remain claims advanced by the attackers rather than Reported Facts.

Inside medusa

Medusa is a well-documented ransomware operation that has operated for several years under a double-extortion model. The group typically encrypts a victim’s systems, exfiltrates large volumes of data beforehand, and then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. Public reporting on prior campaigns shows that medusa has targeted organisations across healthcare, education, manufacturing and professional services, often posting sample files and total data volumes to pressure victims. Its listings are claims of successful intrusion; they do not by themselves prove that every file named was in fact taken or that every organisation listed was fully compromised. In this instance the group’s post simply names Levicoff Law Firm, P.C., asserts the 246.6 GB figure, and includes the incomplete remark about a $1 000 request; nothing further has been independently verified.

Levicoff Law Firm, P.C and its sector

Levicoff Law Firm, P.C. is a Pittsburgh-based civil-litigation practice with eleven employees and an office at 4 PPG Place, Suite 200. Its work covers accident and injury cases, construction matters, insurance disputes, employment issues, contract claims, commercial torts and other business litigation. Law firms of this size routinely hold client intake forms, medical records, financial statements, correspondence, discovery materials and internal case strategies—documents that are both commercially sensitive and often protected by attorney-client privilege. A breach at such an organisation therefore carries consequences that extend beyond ordinary corporate data loss: confidentiality obligations, ethical rules and potential regulatory exposure all come into play once client files leave the firm’s custody.

What data was at risk

The only data type named in the available record is “internal files exfiltrated in ransomware attack,” with a claimed volume of 246.6 GB. Exact categories—whether client names, Social Security numbers, medical records, bank details or privileged work product—are not disclosed. Organisations of this kind typically retain precisely those categories of information, yet it remains unconfirmed which, if any, of them were among the material the attackers say they removed. Public statements have not supplied a file inventory or a sample set that would allow independent verification.

The real-world impact

For individuals whose records may be involved, the concrete risks include identity theft, targeted phishing that leverages case-specific details, and the possible public exposure of private medical or financial information. For the firm itself, the consequences include potential ethical complaints, loss of client trust, and the operational burden of notifying parties and cooperating with any investigation. Because the number of affected people is unknown and the precise contents of the 246.6 GB remain unverified, the full scale of harm cannot yet be measured; the risk, however, is real for anyone who has shared sensitive material with the practice.

What to do if you're exposed

If you have been a client, opposing party or employee of Levicoff Law Firm, P.C., consider the following practical steps:

These measures do not reverse the listing, but they reduce the chance that any exposed material can be used against you in the weeks and months ahead. Official notifications, if they are issued, should be read carefully and followed promptly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLevicoff Law Firm, P.C security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Levicoff Law Firm, P.C’s full breach history →

More recent breaches

Down East Granite Listed by medusa Ransomware GroupDecember 2, 2024Brodsky Renehan Pearlstein & Bouquet, Chartered Listed by medusa Ransomware GroupNovember 29, 2024Perfection Plus Services Inc Listed by medusa Ransomware GroupNovember 25, 2024RDS Electric Listed by medusa Ransomware GroupNovember 20, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Levicoff Law Firm, P.C Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram