riggsabney Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The riggsabney Listed by alphv Ransomware Group (reported August 3, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On August 3, 2023, the Oklahoma-based law firm Riggs Abney appeared on a listing associated with the alphv ransomware group. Public detail indicates that internal files were claimed to have been exfiltrated in a ransomware attack, though the number of people affected remains unknown and the precise scope of any exposure has not been independently confirmed. For clients, employees, and others whose information may sit inside a law firm’s systems, such an incident raises immediate practical questions about confidentiality, identity risk, and what steps to take next.
Law firms routinely hold sensitive personal, financial, and legal records. When a ransomware group claims to have taken internal files, the stakes are concrete even when full technical details stay limited: the possibility that private correspondence, case materials, or identifying data could surface or be misused. This article sets out only what has been reported, places the claim in context, and outlines measured steps for anyone who may be concerned.
Inside the incident
According to the available record, Riggs Abney was listed by the alphv ransomware group on or around August 3, 2023. The reported summary states that internal files were exfiltrated in a ransomware attack. No public figure has been given for the number of people affected. Timing of the underlying intrusion, the method of initial access, the volume of data involved, and any ransom demand or negotiation details are not disclosed in the facts provided.
What is known is limited to the group’s listing and the description of internal files taken during a ransomware incident. There is no confirmed public accounting here of whether systems were encrypted, whether backups were affected, or how the firm responded operationally. Readers should treat the listing as a claim by the group rather than as independently verified proof of every asserted detail.
The group behind it: alphv
Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has been active in recent years using a ransomware-as-a-service model. The group has typically relied on affiliates to gain access to networks, exfiltrate data, and deploy encryption, then pressure victims by threatening to publish stolen material on leak sites. Public documentation of the group describes double-extortion tactics: encryption paired with data theft, followed by timed leak-site postings if payment is not made.
Alphv has been linked in open sources to attacks across multiple sectors, including professional services. The group has used customizable ransomware written in modern languages and has maintained a Tor-based leak site to name victims and, in some cases, release samples or larger archives. None of that general background states the specific contents or completeness of any claim about Riggs Abney beyond the listing itself. For this incident, the facts support only that alphv listed the firm and that internal files were described as exfiltrated; further assertions by the group should be read as claims pending independent verification.
riggsabney and its sector
Riggs Abney is described in the reported summary as one of Oklahoma’s larger law firms, founded in 1972 by four graduates of the University of Tulsa College of Law. Through a 1994 merger it became known as Riggs, Abney, Neal, Turpen, Orbison & Lewis and today operates simply as Riggs Abney, with offices in Tulsa, Oklahoma City, and Colorado. The firm provides broad-based legal counsel and representation across many areas of law.
Law firms occupy a position of trust. They hold client confidences, litigation strategy, contracts, personal identifiers, financial details tied to matters, and internal administrative records. A breach affecting such an organization is consequential because the data is often highly specific to individuals’ legal and personal circumstances, and because professional rules and client expectations place a premium on confidentiality. The sector as a whole has been a recurring target for ransomware groups precisely because of the sensitivity and potential leverage of the information held.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as specific categories of client data, employee records, or document types—is provided. The number of individuals affected is unknown.
Organizations of this kind typically maintain case files, correspondence, billing and trust-account related information, personnel records, and various forms of personally identifiable information belonging to clients and staff. That is general knowledge about legal practice, not a confirmed inventory of what was taken here. Exact contents remain unconfirmed. No public detail in the given record establishes which internal files, if any, were published or how widely they circulated.
Why it matters
For people who have dealt with the firm, the primary risks are practical rather than abstract. If personal identifiers, contact details, financial information, or sensitive case-related material were among the internal files, those individuals could face phishing, social-engineering attempts that reference real matters, or longer-term identity-related fraud. Even without confirmation of specific data types, the mere claim of exfiltration can create uncertainty and require heightened vigilance.
For the organization, a ransomware incident involving claimed data theft can disrupt operations, strain client relationships, and trigger legal, regulatory, and professional-ethics obligations around notification and safeguarding. Reputation and the duty of confidentiality are central to legal practice; any confirmed exposure of client information carries lasting consequences. Because the scale and exact data types are undisclosed, the full picture of harm cannot be stated as fact—only the realistic categories of risk that follow from this type of claim.
What to do if you're exposed
If you are a current or former client, employee, or other party who may have data with Riggs Abney, begin with basic precautions. Monitor financial and credit accounts for unfamiliar activity. Treat unexpected emails, calls, or messages that reference legal matters or personal details with caution, and verify any request for information through known official channels. Consider placing fraud alerts or credit freezes if you believe sensitive identifiers may have been involved. Retain any notice you receive from the firm and follow its guidance on next steps.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets. That check does not confirm or rule out involvement in this specific incident, but it can help you see whether your credentials or personal data appear in broader collections of leaked material and decide whether further monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Advantage Group International Listed by alphv Ransomware GroupLisa Mayer CA, Professional Corporation Listed by alphv Ransomware GroupAQIPA Listed by alphv Ransomware GroupHTC Global Services Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the riggsabney Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.