Schaad Balass Menzl & Partner Listed by Deadlock Ransomware: What Was Exposed & What To Do
Schaad, Balass, Menzl and Partner AG was listed by the Deadlock ransomware group on July 25, 2026, with an undisclosed number of individuals’ internal files appearing on the gang’s leak site. If you have any association with the firm, check whether your information is among the exposed files and follow the guidance the organisation is expected to issue.
Ransomware groups continue to pressure professional-services firms by listing them on leak sites and asserting that internal material has been taken. In that landscape, a Swiss intellectual property practice has appeared on one such site, drawing attention to how law firms that handle sensitive commercial and inventive work can become targets even when public detail remains thin.
According to reporting dated 25 July 2026, the Deadlock ransomware group added Schaad, Balass, Menzl and Partner AG to its leak site and claimed to have exfiltrated internal files. The number of people affected is unknown, and beyond the description “internal files” the exact contents of any taken data have not been publicly detailed. For clients, counterparties, and staff, the listing itself is reason to treat the claim seriously and to understand what is and is not confirmed.
What happened
Public reporting states that on or about 25 July 2026 the Deadlock ransomware group listed Schaad, Balass, Menzl and Partner AG on its leak site. The group claimed that it had exfiltrated internal files from the firm. No independent confirmation of the volume of data, the method of intrusion, or the precise timeline of any compromise has been included in the available facts. The number of individuals affected is unknown. What is established in the record is the leak-site listing and the group’s claim of exfiltration of internal files; further operational detail remains undisclosed.
How a breach like this happens
Incidents of this type commonly begin with initial access obtained through phishing, compromised remote-access credentials, unpatched internet-facing systems, or stolen session tokens. Once inside a network, attackers often move laterally, elevate privileges, and identify file shares, document-management systems, and backups that hold business-critical material. In ransomware operations, data is frequently copied out before encryption is deployed, so that operators can threaten publication if demands are not met. Listing a victim on a leak site is a pressure tactic: it signals a claim of possession and creates a public clock for the organisation and anyone who may be named in the material. None of this describes a verified sequence for this specific case; it is general background on how such campaigns typically unfold when no detailed forensic account has been released.
About Schaad, Balass, Menzl and Partner AG
Schaad, Balass, Menzl and Partner AG is a Swiss intellectual property law firm. It specialises in patent, trademark, and design law. Firms in this sector advise inventors, companies, and rights holders on the creation, registration, defence, and commercialisation of intellectual property. Their work product and client files routinely include technical descriptions, filing strategies, correspondence with patent and trademark offices, licensing terms, and other commercially sensitive material. A breach affecting such a practice is consequential because the confidentiality of that material underpins client trust, competitive position, and, in some matters, the legal protection of inventions and brands. Even when only “internal files” are named in public claims, the nature of IP practice means those files can touch many external parties.
What data was at risk
The available facts name the exposed data types only as internal files. No further breakdown—such as client lists, email archives, patent drafts, or employee records—has been disclosed in the record. Organisations of this kind typically hold client matter files, correspondence, billing and contact data, and internal administrative documents. Whether any of those categories were among the material claimed by the listing group is unconfirmed. Readers should treat specific content as unknown unless and until the firm or a competent authority provides a clearer inventory.
The real-world impact
For people and organisations whose information may sit inside a law firm’s systems, the practical risks include unwanted disclosure of business strategy, technical know-how, or personal contact details; targeted follow-on phishing that impersonates the firm or its clients; and, in competitive markets, misuse of non-public IP-related information. For the firm, a leak-site listing can damage reputation, trigger regulatory and professional obligations, and require costly investigation, client notification, and remediation—regardless of whether every claim made by a ransomware group is later proven in full. Because the count of affected people is unknown and the file contents are not detailed publicly, the scale of individual harm cannot be stated as fact; the prudent stance is to assume that anyone with a recent or ongoing relationship to the firm could be touched if the claim of exfiltration is accurate.
What to do if you're exposed
If you are a client, former client, employee, or partner of Schaad, Balass, Menzl and Partner AG, watch for unusual emails or calls that reference IP matters, invoices, or confidential projects, and verify them through known channels rather than links or numbers in the message. Consider changing passwords used with the firm’s portals, enabling multi-factor authentication where available, and reviewing financial and identity accounts for unexpected activity. If you receive notice from the firm, follow its instructions and keep records of what you are told. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which can help you prioritise further monitoring and password changes.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
American Hospice & Home Health Services (Ahhh Care) Listed by CRPxO Ransomware GroupLouisiana Coalition Against | Domestic Violence Listed by Global Secret Group Ransomware GroupNourison | Home Listed by Global Secret Group Ransomware GroupWest Nova Fuels & Superline Fuels Listed by Global Secret Group Ransomware GroupLatest breaches
Publicly posted — pending verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.