LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Moses & Singer Listed by SilentRansomGroup Ransomware Group

HIGH severityUnverified claimHow we verify

Moses & Singer Listed by SilentRansomGroup Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 2, 2026
Moses & Singer Listed by SilentRansomGroup Ransomware Group

Reported August 2, 2026.

HIGH
Severity
1
Data types exposed
August 2, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Moses & Singer was listed by the SilentRansomGroup ransomware group on August 02, 2026, after internal files were exfiltrated in a ransomware attack; the date of the actual intrusion has not been established. Anyone who has shared data with the firm should check whether their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Moses & Singer Listed by SilentRansomGroup Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

Law firms remain a persistent target in today’s ransomware landscape, where attackers seek not only to encrypt systems but to exfiltrate internal material that can be leveraged for pressure and secondary harm. Professional-services organisations hold concentrated stores of client, transactional, and proprietary information, making them attractive to groups that operate leak sites and double-extortion models.

On August 02, 2026, Moses & Singer was reported as listed by the ransomware group SilentRansomGroup. Public detail is limited: the number of people affected is unknown, and the material described is internal files said to have been exfiltrated in a ransomware attack. The listing itself is a claim by the group and has not been independently confirmed in the available record. For clients, counterparties, and staff, even an unverified claim warrants calm attention to what is known and what practical steps remain useful.

Inside the incident

According to the reported record, Moses & Singer LLP appeared on a listing associated with SilentRansomGroup on August 02, 2026. The organisation is described as a full-service law firm specialising in corporate transactions and intellectual property–related work, among other practice areas. The facts state that internal files were exfiltrated in a ransomware attack. No confirmed figure for individuals affected has been published. Timing of the underlying intrusion, the precise method of initial access, the volume of data, and any ransom demand or negotiation outcome are not disclosed in the available information.

What is on the public record, therefore, is a group claim of compromise and exfiltration rather than a fully documented forensic account. Until the firm or independent investigators provide further verified detail, the scale and exact contents of any exposure remain unconfirmed. Readers should treat the leak-site listing as an assertion by the threat actor, not as established proof of every claimed element.

Who is SilentRansomGroup?

SilentRansomGroup is a ransomware actor known in public reporting for double-extortion tactics: encrypting victim environments while also copying data and threatening to publish or auction it if demands are not met. Groups of this type commonly maintain leak or negotiation sites where they name organisations and, in some cases, sample or dump material to increase pressure. Their operations typically rely on initial access through phishing, compromised credentials, exposed remote services, or other common enterprise entry points, followed by lateral movement, data staging, and deployment of ransomware.

Public documentation of SilentRansomGroup’s broader activity describes a pattern of targeting organisations that hold sensitive commercial or professional data. That general profile does not, by itself, prove every detail of any single listing. In this case, the facts support only that Moses & Singer was listed and that internal files were described as exfiltrated; they do not include verified quotes, file counts, or specific claims the group may have posted beyond that framing. Any assertion on a leak site should be read as the actor’s claim until corroborated.

Moses & Singer and its sector

Moses & Singer LLP is a full-service law firm whose reported focus includes corporate transactions and intellectual property work. Law firms in this segment routinely handle deal documents, contracts, correspondence, billing records, and privileged communications. They may also hold identity and contact details for clients, opposing parties, experts, and employees, as well as matter-related financial and strategic information.

A breach or claimed breach at a law firm is consequential because the data involved is often confidential by design, sometimes subject to privilege or regulatory expectations, and frequently valuable to competitors, litigants, or criminals who specialise in fraud and extortion. Even when the full scope is unknown, the sector’s role as a trusted intermediary means that disruption or data exposure can affect not only the firm but also the clients and counterparties whose matters sit in its systems.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as specific categories of personal data, client lists, or document types—is provided in the available record. The number of people affected is unknown.

Organisations of this kind typically hold matter files, emails, contracts, identity and contact information, billing and trust-accounting related records, and other internal work product. That is a general description of the sector, not a confirmed inventory of what was taken here. Exact contents remain unconfirmed. No assumption should be made that any particular client’s file or any named individual’s data was included unless and until verified notice is issued.

Why it matters

For people who may be connected to the firm—clients, employees, vendors, or others—the practical risks of internal-file exposure in a legal context include targeted phishing that references real matters, social-engineering attempts that misuse names and case details, and longer-term misuse of personal or financial identifiers if such data were present. Privilege and confidentiality concerns can also create professional and reputational consequences for the organisation and for the parties whose information was entrusted to it.

For the firm, a ransomware incident that includes exfiltration claims can mean operational disruption, investigative and recovery costs, notification and regulatory obligations where applicable, and sustained attention from clients who need assurance about how their matters were handled. Because the people-affected count and precise data types beyond “internal files” are undisclosed, the individual residual risk cannot be quantified from public facts alone. The prudent response is still to assume that heightened vigilance is warranted until clearer information emerges.

What to do if you're exposed

If you have a relationship with Moses & Singer or reason to believe your information may have been involved, start with basics: treat unexpected emails, calls, or messages that reference legal matters or the firm with scepticism; verify any request for money, credentials, or documents through a known separate channel; and monitor financial and credit activity for unusual behaviour. If you receive direct notice from the firm, follow the instructions in that notice, including any offer of credit monitoring or identity-protection services. Preserve copies of suspicious communications. Consider updating passwords on important accounts, especially if you reused credentials, and enable multi-factor authentication where available.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets. That check does not confirm or deny involvement in this specific incident, but it can help you prioritise further monitoring and password hygiene while official detail remains limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMoses & Singer security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Moses & Singer’s full breach history →

More recent breaches

Fox Rothschild LLP Listed by SilentRansomGroup Ransomware GroupMay 28, 2026Barclay Damon Listed by SilentRansomGroup Ransomware GroupMay 19, 2026Marshall Dennehey Listed by SilentRansomGroup Ransomware GroupMay 12, 2026Porter Wright Listed by SilentRansomGroup Ransomware GroupMay 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Moses & Singer Listed by SilentRansomGroup Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by silentransomgroup — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram