Pincu Barkan, Law Office and Notary Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Pincu Barkan, Law Office and Notary was listed by the everest ransomware group on November 14, 2024, after internal files were exfiltrated in a ransomware attack. The number of individuals affected has not been disclosed; anyone who may have shared personal or legal documents with the firm should verify their status and review their security measures.
Ransomware groups continue to target professional-service firms that hold concentrated stores of personal and legal records, turning routine office systems into high-value pressure points. In this environment, even smaller practices can appear on leak sites within days of an intrusion claim.
On 14 November 2024 the ransomware group everest listed Pincu Barkan, Law Office and Notary as a victim, asserting that internal files had been exfiltrated. The number of people affected remains unknown, yet the claim alone raises immediate questions for anyone whose documents may have been held by the firm.
Breaking down the breach
Public reporting states that Pincu Barkan, Law Office and Notary was listed by the everest ransomware group on 14 November 2024. The group claims that more than 230,000 internal files were taken in a ransomware attack. Those files are described as including copies of personal identification documents, FBI crime records, birth certificates and similar materials. No independent confirmation of the intrusion method, the exact date of compromise, or the full volume of data has been released. The number of individuals whose information may be involved is listed as unknown. The firm’s websites are noted in the reporting, but no further technical details about the attack vector or ransom demand have been disclosed.
Inside everest
Everest is a ransomware operation that follows the now-common double-extortion model: encrypt systems and simultaneously steal data, then threaten public release if payment is not made. The group maintains a leak site where it posts victim names and, in some cases, sample files to increase pressure. It has previously claimed attacks against organisations in legal, professional and industrial sectors, typically advertising large file counts and sensitive document types. Listings on the site are claims made by the group itself; they are not independently verified at the moment of publication. In this instance everest asserts that it holds the Pincu Barkan material, but no third-party forensic confirmation has been made public.
About Pincu Barkan, Law Office and Notary
Pincu Barkan operates as a law office and notary practice. Firms of this type routinely handle identity documents, court records, property papers, powers of attorney and other highly personal materials required for legal and notarial services. Because clients must supply original or certified copies of sensitive records, such offices become natural repositories of concentrated personal data. A breach claim against a practice of this kind therefore carries weight beyond ordinary commercial data loss: the documents themselves are often the very proofs of identity and legal status that individuals rely on in daily life.
The information in question
Reporting names the exposed material as internal files exfiltrated in a ransomware attack. The everest listing further claims that the haul exceeds 230,000 files and includes personal ID copies, FBI crime records, birth certificates and comparable documents. Exact contents, file formats and whether any encryption or redaction was present remain unconfirmed by independent sources. Organisations in the legal and notarial sector typically retain precisely these categories of records—identity papers, criminal-history extracts, vital-event certificates and case-related correspondence—so the claimed inventory is consistent with the firm’s professional function, yet the precise inventory has not been verified outside the group’s own statements.
Why it matters
If the claimed files are authentic, individuals whose documents were stored with the firm face concrete risks: identity documents can be reused for fraud, birth certificates can support synthetic identities, and crime-record extracts can be weaponised for blackmail or reputational harm. Even partial exposure can force people to monitor credit, re-issue official papers and remain alert for social-engineering attempts that reference real case details. For the firm itself, the listing creates regulatory, professional-liability and client-trust consequences that will require careful investigation and communication. Because the number of affected people is still unknown, the full scale of personal impact cannot yet be measured.
Were you affected?
Anyone who has used Pincu Barkan for legal or notarial services should treat the claim seriously until more information emerges. Practical first steps include:
- Contacting the firm directly to ask whether your file was among those claimed.
- Reviewing recent account statements and credit reports for unfamiliar activity.
- Requesting replacement identity or vital-record documents if originals were lodged with the office.
- Remaining cautious of unsolicited calls or emails that reference specific case details.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Early awareness remains the most reliable defence while official details continue to develop.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
The Law Office of Omar O. Vargas, P.C. Listed by everest Ransomware GroupAccounting Professionals LLC. Price, Breazeale & Chastang Listed by everest Ransomware GroupStudio Marchi - Studio Professionale Associato Listed by everest Ransomware GroupMorgan Records Management Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.