LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Paul-Alexandre Doïcesco, Notaires Associés Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

Paul-Alexandre Doïcesco, Notaires Associés Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 25, 2023
Paul-Alexandre Doïcesco, Notaires Associés Listed by qilin Ransomware Group

Reported October 25, 2023.

HIGH
Severity
October 25, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Paul-Alexandre Doïcesco, Notaires Associés Listed by qilin Ransomware Group (reported October 25, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 25 October 2023, the French notarial practice Paul-Alexandre Doïcesco, Notaires Associés was listed on a leak site operated by the ransomware group known as qilin. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational detail has not been disclosed. The group’s own notice claimed the firm had chosen to ignore its demands and that the data would therefore be made available for download. That claim has not been independently confirmed in the available record.

For clients and counterparties of a notarial office, any confirmed or claimed exposure of internal files raises practical questions about confidentiality, identity risk and the integrity of sensitive legal paperwork. What is known so far is limited to the listing itself, the reported date and the description of exfiltrated internal files.

Inside the incident

According to the public record tied to this listing, Paul-Alexandre Doïcesco, Notaires Associés appeared on qilin’s leak site on or around 25 October 2023. The available summary attributes the incident to a ransomware attack in which internal files were taken. No confirmed figure for the volume of data, no inventory of specific document categories, and no technical description of the initial access method have been published in the facts at hand. The number of individuals whose information may be involved is listed as unknown.

qilin’s posted notice stated that the company had chosen to ignore the group and that the data would therefore be opened for download. That statement is a claim by the threat actor; it does not by itself establish what was ultimately released, to whom, or whether negotiations or containment steps occurred outside public view. Timing beyond the reported listing date, the scale of any encryption on internal systems, and any ransom demand amount are undisclosed.

Inside qilin

qilin is a ransomware operation that has been documented in open reporting as a group that conducts double-extortion attacks: encrypting systems where possible while also exfiltrating data and threatening to publish it if payment is not made. Like other actors in this category, it has used dedicated leak sites to name victims and, in some cases, to stage sample files or larger archives. Public analyses of the group’s activity over time have described affiliate-style operations, pressure tactics that include countdown notices, and targeting across multiple sectors and countries rather than a single industry focus.

None of that general pattern should be read as confirmed detail about the specific intrusion path, tools, or negotiations in the Paul-Alexandre Doïcesco, Notaires Associés case. For this incident, the only actor-side assertion in the provided facts is the leak-site listing and the accompanying claim that ignored demands would lead to data being made downloadable. Independent verification of what was posted, if anything, beyond that claim is not part of the record supplied here.

Paul-Alexandre Doïcesco, Notaires Associés and its sector

Paul-Alexandre Doïcesco, Notaires Associés is identified as a notarial practice. In France and comparable civil-law systems, notaires are public officers who authenticate deeds, oversee property transfers, handle succession and family-law instruments, and maintain formal records that carry legal weight. Firms of this type routinely hold identity documents, property and mortgage information, financial particulars tied to transactions, wills and succession files, and correspondence with clients, banks and other professionals.

Because notarial work sits at the intersection of private life and legally binding acts, confidentiality is central to the role. A breach or claimed exfiltration involving a notarial office is consequential not only for the firm’s operations but for anyone whose authenticated deeds, personal identifiers or transaction details may have been stored in internal systems. The facts do not describe the firm’s size, locations or client volume; they establish only the organisation name and the sector context implied by that name.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether client deeds, identity scans, email archives, accounting records or staff data were included—is provided. The number of people affected is unknown.

Organisations in the notarial sector typically hold highly sensitive personal and financial information as a normal part of their mandate. That general pattern explains why an exfiltration claim is taken seriously, but it does not state the exact contents of any archive associated with this listing. Exact data types beyond the phrase “internal files” remain unconfirmed in the public detail available for this incident.

Why it matters

If internal files from a notarial practice are copied by unauthorised parties, affected individuals can face lasting risks: misuse of identity details, targeted fraud that references real property or succession matters, phishing that appears credible because it draws on genuine transaction context, and exposure of private family or financial arrangements. Even when the full scope is unknown, the mere possibility that authenticated legal paperwork or supporting identity data left the firm’s control creates uncertainty that clients cannot easily resolve on their own.

For the organisation, a ransomware incident and a public leak-site listing can disrupt daily operations, trigger regulatory and professional obligations around personal data, and damage the trust on which notarial work depends. None of these outcomes requires assuming negligence; they follow from the nature of the data such offices hold and from the pressure model ransomware groups commonly use. Because headcount of affected people and a precise data inventory are undisclosed, the practical impact must be treated as potentially significant but not yet quantified in the public record.

Were you affected?

If you have been a client of Paul-Alexandre Doïcesco, Notaires Associés or have completed property, succession or other notarial formalities through the firm, treat the listing as a reason to heighten caution rather than as proof that your specific file was published. Monitor bank and credit activity, be sceptical of unexpected messages that reference real estate, inheritance or identity documents, and consider placing fraud alerts where appropriate. Prefer official channels if you need to verify the status of your file with the practice.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out involvement in this specific incident, but it can help you see whether your credentials or personal details appear in broader collections of leaked material and decide on password changes or further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPaul-Alexandre Doïcesco, Notaires Associés security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Paul-Alexandre Doïcesco, Notaires Associés’s full breach history →

More recent breaches

Bekman Marder Hopper Malarkey & Perlin Listed by qilin Ransomware GroupJune 10, 2026INTERSPA Betriebsverwaltungsgesellschaft Listed by qilin Ransomware GroupJune 5, 2026John G Yphantides A Professional Law Listed by qilin Ransomware GroupMay 13, 2026Law Office of Steven R Smith Listed by qilin Ransomware GroupMay 4, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Paul-Alexandre Doïcesco, Notaires Associés Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram