LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Schaad Balass Menzl & Partner Listed by Deadlock Ransomware

HIGH severityUnverified claimHow we verify

Schaad Balass Menzl & Partner Listed by Deadlock Ransomware: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 25, 2026
Schaad Balass Menzl & Partner Listed by Deadlock Ransomware

Reported July 25, 2026.

HIGH
Severity
1
Data types exposed
July 25, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Schaad, Balass, Menzl and Partner AG was listed by the Deadlock ransomware group on July 25, 2026, with an undisclosed number of individuals’ internal files appearing on the gang’s leak site. If you have any association with the firm, check whether your information is among the exposed files and follow the guidance the organisation is expected to issue.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Schaad Balass Menzl & Partner Listed by Deadlock Ransomware breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Ransomware groups continue to pressure professional-services firms by listing them on leak sites and asserting that internal material has been taken. In that landscape, a Swiss intellectual property practice has appeared on one such site, drawing attention to how law firms that handle sensitive commercial and inventive work can become targets even when public detail remains thin.

According to reporting dated 25 July 2026, the Deadlock ransomware group added Schaad, Balass, Menzl and Partner AG to its leak site and claimed to have exfiltrated internal files. The number of people affected is unknown, and beyond the description “internal files” the exact contents of any taken data have not been publicly detailed. For clients, counterparties, and staff, the listing itself is reason to treat the claim seriously and to understand what is and is not confirmed.

What happened

Public reporting states that on or about 25 July 2026 the Deadlock ransomware group listed Schaad, Balass, Menzl and Partner AG on its leak site. The group claimed that it had exfiltrated internal files from the firm. No independent confirmation of the volume of data, the method of intrusion, or the precise timeline of any compromise has been included in the available facts. The number of individuals affected is unknown. What is established in the record is the leak-site listing and the group’s claim of exfiltration of internal files; further operational detail remains undisclosed.

How a breach like this happens

Incidents of this type commonly begin with initial access obtained through phishing, compromised remote-access credentials, unpatched internet-facing systems, or stolen session tokens. Once inside a network, attackers often move laterally, elevate privileges, and identify file shares, document-management systems, and backups that hold business-critical material. In ransomware operations, data is frequently copied out before encryption is deployed, so that operators can threaten publication if demands are not met. Listing a victim on a leak site is a pressure tactic: it signals a claim of possession and creates a public clock for the organisation and anyone who may be named in the material. None of this describes a verified sequence for this specific case; it is general background on how such campaigns typically unfold when no detailed forensic account has been released.

About Schaad, Balass, Menzl and Partner AG

Schaad, Balass, Menzl and Partner AG is a Swiss intellectual property law firm. It specialises in patent, trademark, and design law. Firms in this sector advise inventors, companies, and rights holders on the creation, registration, defence, and commercialisation of intellectual property. Their work product and client files routinely include technical descriptions, filing strategies, correspondence with patent and trademark offices, licensing terms, and other commercially sensitive material. A breach affecting such a practice is consequential because the confidentiality of that material underpins client trust, competitive position, and, in some matters, the legal protection of inventions and brands. Even when only “internal files” are named in public claims, the nature of IP practice means those files can touch many external parties.

What data was at risk

The available facts name the exposed data types only as internal files. No further breakdown—such as client lists, email archives, patent drafts, or employee records—has been disclosed in the record. Organisations of this kind typically hold client matter files, correspondence, billing and contact data, and internal administrative documents. Whether any of those categories were among the material claimed by the listing group is unconfirmed. Readers should treat specific content as unknown unless and until the firm or a competent authority provides a clearer inventory.

The real-world impact

For people and organisations whose information may sit inside a law firm’s systems, the practical risks include unwanted disclosure of business strategy, technical know-how, or personal contact details; targeted follow-on phishing that impersonates the firm or its clients; and, in competitive markets, misuse of non-public IP-related information. For the firm, a leak-site listing can damage reputation, trigger regulatory and professional obligations, and require costly investigation, client notification, and remediation—regardless of whether every claim made by a ransomware group is later proven in full. Because the count of affected people is unknown and the file contents are not detailed publicly, the scale of individual harm cannot be stated as fact; the prudent stance is to assume that anyone with a recent or ongoing relationship to the firm could be touched if the claim of exfiltration is accurate.

What to do if you're exposed

If you are a client, former client, employee, or partner of Schaad, Balass, Menzl and Partner AG, watch for unusual emails or calls that reference IP matters, invoices, or confidential projects, and verify them through known channels rather than links or numbers in the message. Consider changing passwords used with the firm’s portals, enabling multi-factor authentication where available, and reviewing financial and identity accounts for unexpected activity. If you receive notice from the firm, follow its instructions and keep records of what you are told. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which can help you prioritise further monitoring and password changes.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanySchaad Balass Menzl & Partner AG security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Schaad Balass Menzl & Partner AG’s full breach history →

More recent breaches

American Hospice & Home Health Services (Ahhh Care) Listed by CRPxO Ransomware GroupJuly 27, 2026Louisiana Coalition Against | Domestic Violence Listed by Global Secret Group Ransomware GroupJuly 27, 2026Nourison | Home Listed by Global Secret Group Ransomware GroupJuly 26, 2026West Nova Fuels & Superline Fuels Listed by Global Secret Group Ransomware GroupJuly 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Schaad Balass Menzl & Partner Listed by Deadlock Ransomware →

Source: threat-actor leak-site listing

Publicly posted — pending verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram