Martin, Cukjati & Tom, LLP Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Martin, Cukjati & Tom, LLP appeared on a list published by the incransom ransomware group on March 02, 2026, indicating that internal files had been taken in a ransomware attack. Individuals connected to the firm should verify whether their information was involved and consider protective steps.
Breaking down the breach
The only confirmed element is that internal files were removed during a ransomware attack. The scale of the operation, including how many records or clients are implicated, remains unknown. No official statement from the firm has clarified whether the files were encrypted, whether ransom demands were met, or whether any data was later published.
The group behind it: incransom
Incransom is a ransomware operator that has appeared in multiple public listings of compromised organizations. The group typically claims responsibility by posting victim names on its leak site and sometimes releases samples of stolen material. In this case the group claims Martin, Cukjati & Tom, LLP as a victim; that claim has not been independently verified beyond the listing itself.
About Martin, Cukjati & Tom, LLP
Martin, Cukjati & Tom, LLP is a law firm that has operated for more than 75 years, handling high-stakes litigation for both individuals and businesses. Law firms routinely maintain records that include client identities, case details, financial arrangements, and communications protected by attorney-client privilege. Any compromise of such records can affect ongoing legal matters and the privacy of parties involved in them.
The information in question
The only data category reported is internal files exfiltrated during the ransomware attack. The specific contents of those files have not been disclosed. Organizations of this type commonly store client personal information, litigation documents, and financial records, but it is not confirmed whether any of those categories were among the material taken.
What's at stake
People whose information appears in the exfiltrated files could encounter follow-on risks such as identity misuse or targeted scams. The firm itself may face regulatory scrutiny, reputational damage, and costs associated with investigation and client notification. Because the number of affected individuals is unknown, the full scope of these consequences cannot yet be measured.
What to do if you're exposed
Anyone who has been a client or counterpart of the firm should monitor their accounts and financial statements for unusual activity. Steps that can reduce immediate risk include:
- Changing passwords for any accounts linked to the firm and enabling multi-factor authentication.
- Requesting a copy of any client file the firm holds to understand what information may have been present.
- Placing fraud alerts with credit bureaus if personal identifiers were likely involved.
- Running a free exposure scan of their email address against known breach data sets to check for prior appearances.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
belpointeasset.com \ belpointe.com Listed by incransom Ransomware Grouphttps://sibillacapital.com/ Listed by incransom Ransomware Groupnorthstaria.com Listed by incransom Ransomware Groupmcfirm.com Listed by incransom Ransomware GroupLatest breaches
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.