Naulty, Scaricamazza and McDevitt, LLC Listed by royal Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Naulty, Scaricamazza and McDevitt, LLC Listed by royal Ransomware Group (reported December 16, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Naulty, Scaricamazza and McDevitt, LLC, a Philadelphia-based law firm, was listed by the royal ransomware group on or around December 16, 2022. Public reporting indicates that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.
For clients, employees, and others whose information may have been held by the firm, the listing raises concrete questions about what was taken and what practical steps follow. This article sets out only what is known from the available record, places the claim in context, and outlines measured next steps.
What happened
According to the public record, Naulty, Scaricamazza and McDevitt, LLC appeared on a listing associated with the royal ransomware group, with the matter reported on December 16, 2022. The available summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of individuals affected has been released. Timing of the intrusion itself, the precise method of initial access, the full scope of systems involved, and any ransom demand or negotiation details are undisclosed in the material at hand.
The listing constitutes a claim by the group that it obtained and removed data from the firm. Independent confirmation of the full extent of the compromise is not contained in the reported facts. Organizations facing such claims typically investigate internally and may notify regulators or affected parties once the scope is better understood; whether and when those steps occurred here is not detailed in the public summary provided.
Who is royal?
Royal is a ransomware operation that emerged in the public threat landscape in 2022. Like other groups in this category, it has been observed deploying encryption against victim networks while also exfiltrating data beforehand, a double-extortion approach intended to increase pressure by threatening to publish or sell stolen material if demands are not met. The group has typically advertised victims on dedicated leak sites, listing organization names and sometimes sample files or descriptions of purported data volumes.
Public reporting on royal has described the use of common initial-access techniques seen across the ransomware ecosystem, including exploitation of exposed services, stolen credentials, and phishing, though the specific vector used against any single victim is rarely confirmed by the group itself. Royal’s listings are claims; they do not by themselves constitute verified proof of every asserted detail. In this case, the facts state only that the firm was listed and that internal files were described as exfiltrated. No further statements attributed to royal about this particular victim appear in the given record.
About Naulty, Scaricamazza and McDevitt, LLC
Naulty, Scaricamazza and McDevitt, LLC is a law firm headquartered at 1617 JFK Boulevard, Suite 750, Philadelphia, Pennsylvania. Public business information places its size at approximately 56 employees and its revenue on the order of $14 million. The firm traces its origins to 1952, when it was founded by John F. Naulty after his work as house counsel for national insurance companies; he was later joined by Angelo L. Scaricamazza and Francis T. McDevitt. Angelo Scaricamazza led the firm until his death in December 2020; Francis McDevitt has continued as a prominent attorney and leader. The firm’s website is listed as www.naulty.com and its phone number as (215) 568-5116.
Law firms of this type routinely handle sensitive client matters, correspondence, contracts, litigation files, and related personal and financial information. A breach affecting such an organization is consequential because the data held is often confidential by nature, may include material covered by attorney-client privilege or work-product protections, and can expose both the firm and its clients to secondary risks if it is misused or further disseminated.
What data was at risk
The reported facts name the exposed material as internal files exfiltrated in a ransomware attack. No itemized inventory of file types, no count of records, and no confirmation of specific categories such as client names, Social Security numbers, financial account details, or medical information appear in the given record. Exact contents therefore remain unconfirmed.
Organizations in the legal sector typically maintain case files, client intake and contact data, billing and payment records, internal administrative documents, employee information, and correspondence. Whether any or all of those categories were among the files taken in this incident is not established by the public summary. Readers should treat claims about precise data elements as unverified until corroborated by the firm or by official notifications.
What's at stake
For individuals whose information may have been held by the firm, the primary risks are misuse of personal or case-related data, targeted phishing or social-engineering attempts that reference genuine details, and, in some circumstances, identity theft or financial fraud if highly sensitive identifiers were included. Because the exact data types and the number of people affected are unknown, the severity for any single person cannot be assessed from the public record alone.
For the firm, consequences can include operational disruption from the ransomware event itself, costs of investigation and remediation, potential regulatory or professional obligations to notify clients and authorities, reputational harm, and possible civil exposure if privileged or confidential client material was compromised. None of these outcomes is asserted as fact for this incident; they are the ordinary categories of risk that accompany ransomware claims against professional-services organizations.
If your data was in this claimed breach
If you have a past or present relationship with Naulty, Scaricamazza and McDevitt, LLC and are concerned that your information may have been involved, consider the following practical steps:
- Monitor account statements, credit reports, and any notices from the firm for unusual activity or official breach communications.
- Treat unsolicited emails, calls, or messages that reference the firm or your legal matters with caution; verify through known official channels before responding or clicking links.
- Change passwords on related accounts if you reused credentials, and enable multi-factor authentication where available.
- If you receive a formal notification letter, follow the specific guidance it provides, including any offer of credit monitoring.
- You can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets.
Public detail on this incident remains limited. Further clarity, if it becomes available, would most reliably come from the firm itself or from regulatory disclosures rather than from unverified third-party claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Law Firm of Friedman + Bartoumian Listed by royal Ransomware GroupVolt Listed by coinbasecartel Ransomware GroupTA Supply Listed by royal Ransomware GroupGrupo Ibiapina Ltda Listed by royal Ransomware GroupLatest breaches
Publicly posted by royal — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.