milbermakris.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The milbermakris.com Listed by lockbit3 Ransomware Group (reported September 8, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 8 September 2023, the law firm associated with milbermakris.com appeared on a listing by the ransomware group known as lockbit3. Public detail is limited: the number of people affected is unknown, and the only description of what was taken refers to internal files said to have been exfiltrated in a ransomware attack. For clients, opposing parties, insurers, and employees whose information may sit inside a civil-litigation practice, that claim alone is enough to raise practical questions about confidentiality and secondary misuse of records.
Because the listing is an unverified claim by the group rather than a confirmed disclosure from the firm, the precise scope and confirmation of any intrusion remain unclear. What is known is still consequential for anyone who has shared sensitive material with a full-service civil litigation defense firm that works closely with the insurance industry.
Inside the incident
According to the available record, milbermakris.com was listed by lockbit3 on or about 8 September 2023. The reported summary identifies the organisation as Milber Makris Plousadis & Seiden, LLP. The only data description provided is that internal files were allegedly exfiltrated in a ransomware attack. No figure for the number of people affected has been published, no technical method of initial access has been disclosed, and no independent confirmation of the volume or exact contents of any stolen material has been released in the facts at hand. Timing beyond the reported listing date, ransom demands, and any negotiation outcome are likewise undisclosed.
In short, the public picture rests on the group’s leak-site claim that the firm was a victim and that internal files left its environment. Beyond that assertion, detail is limited.
Who is lockbit3?
LockBit 3 (sometimes styled LockBit 3.0 or LockBit Black) is a well-documented ransomware operation that has operated as a Ransomware-as-a-Service model. Affiliates gain access to target networks, exfiltrate data, deploy encryption, and then pressure victims by threatening to publish stolen material on a dedicated leak site if payment is not made. The group has been linked to numerous high-profile incidents across legal, manufacturing, healthcare, and professional-services sectors in multiple countries. Its typical playbook combines double extortion—encryption plus data theft—with public naming of victims to increase leverage.
With respect to this specific listing, the only established point is that lockbit3 claimed milbermakris.com as a victim and asserted that internal files had been taken. No further statements attributed to the group about this particular firm appear in the given facts, and the listing itself should be treated as an unverified claim unless and until corroborated by the organisation or independent investigators.
milbermakris.com and its sector
Milber Makris Plousadis & Seiden, LLP is described as a full-service civil litigation defense firm and a business partner to the insurance industry. Firms of this type routinely handle case files, pleadings, discovery materials, insurance claim documentation, correspondence with carriers and insureds, and internal work product. They often hold personally identifiable information belonging to clients, witnesses, employees, and sometimes opposing parties, as well as commercially sensitive details about coverage disputes, settlements, and litigation strategy.
A breach affecting such a practice is consequential because legal and insurance-related records are both confidential by nature and useful to fraudsters, competitors, or litigants seeking leverage. Even when the exact contents of any exfiltration remain unconfirmed, the sector’s ordinary data holdings make the potential exposure material to the people and organisations whose matters the firm handles.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data types—such as names, addresses, Social Security numbers, medical records, financial account details, or privileged communications—has been published. The number of individuals potentially affected is unknown.
Organisations of this kind typically maintain client and matter files, insurance-related documents, employee records, and internal administrative data. Whether any of those categories were among the files claimed by lockbit3 is unconfirmed. Readers should therefore treat the precise contents as undisclosed rather than assume any particular category was or was not taken.
Why it matters
For individuals whose information may have been inside the firm’s systems, the practical risks include targeted phishing that references real case or insurance details, identity theft if personal identifiers were present, and unwanted exposure of sensitive personal or financial circumstances. For corporate clients and insurers, there is the additional possibility that litigation strategy, settlement figures, or proprietary claim information could be misused. For the firm itself, an incident of this type can disrupt operations, trigger notification and regulatory obligations, and damage the trust that underpins attorney-client and insurer relationships.
None of these outcomes is established as having occurred solely from the listing; they are the ordinary downstream concerns that arise when internal files from a litigation and insurance-defense practice are alleged to have left the organisation’s control. Because the scale remains unknown, the prudent stance is to assume that anyone who has had a matter, employment relationship, or substantial correspondence with the firm could be within the circle of potential exposure until clearer information emerges.
What to do if you're exposed
If you believe your data may have been held by Milber Makris Plousadis & Seiden, LLP or related to matters handled under milbermakris.com, consider the following practical steps:
- Monitor account statements, credit reports, and insurance correspondence for unfamiliar activity and consider a fraud alert or credit freeze if personal identifiers were ever shared with the firm.
- Treat unsolicited emails, calls, or messages that reference specific legal or insurance matters with heightened caution; verify directly through known firm or carrier channels before responding or opening attachments.
- Change passwords on any accounts that reused credentials potentially stored in professional correspondence, and enable multi-factor authentication where available.
- Retain copies of any breach notices you receive and follow the specific guidance they contain regarding credit monitoring or identity-protection services.
- Run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets.
Public detail on this incident remains limited. Staying alert to unusual contact and verifying the status of your own records are the most immediate, concrete actions available while fuller confirmation is unavailable.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
mcs360.com Listed by lockbit3 Ransomware Grouptradewindscorp-insbrok.com Listed by lockbit3 Ransomware Groupcitizenswv.com Listed by lockbit3 Ransomware Grouptcw.com Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the milbermakris.com Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.