LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Schaad Listed by Deadlock Ransomware Group

HIGH severityUnverified claimHow we verify

Schaad Listed by Deadlock Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 25, 2026
Schaad Listed by Deadlock Ransomware Group

Reported July 25, 2026.

HIGH
Severity
1
Data types exposed
July 25, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Schaad was listed by the Deadlock ransomware group on July 25, 2026, with internal files reported as exfiltrated in the attack. An undisclosed number of people may be affected; anyone connected to Schaad should review the group’s claims and take protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Schaad Listed by Deadlock Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

On July 25, 2026, the Swiss intellectual-property firm Schaad, formally known as SBMP (Schaad Balass Menzl & Partner AG), was listed by the ransomware group Deadlock. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.

For clients, counterparties, and staff connected to a specialist IP practice, any confirmed or claimed exposure of internal material carries concrete implications. What is known so far is limited to the listing itself and the description of exfiltrated internal files; the rest of the picture is still incomplete.

Inside the incident

According to available reporting, Schaad was named on Deadlock’s leak site in connection with a ransomware attack in which internal files were taken. The incident was reported on July 25, 2026. No public figure has been given for the volume of data, the number of systems involved, or the precise timeline of intrusion, encryption, or exfiltration. Methods of initial access, dwell time, and whether any ransom demand was issued or paid are undisclosed.

The listing by Deadlock constitutes a claim by the group that it holds data belonging to the firm. Independent confirmation of the full scope of the intrusion has not been detailed in the material provided. People affected are recorded as unknown. Beyond the statement that internal files were exfiltrated, no further breakdown of the incident’s technical course has been made public.

Inside Deadlock

Deadlock is a ransomware operation that, like other groups in this category, has been observed using double-extortion tactics: encrypting systems while also copying data and threatening to publish it if demands are not met. Such groups typically advertise victims on dedicated leak sites to increase pressure. Public reporting on Deadlock has associated the name with ransomware campaigns against organisations across various sectors, though specific tooling, affiliate structures, and targeting patterns can evolve and are not always fully documented in open sources.

In this case, the group’s appearance on a leak site naming Schaad should be read as the actors’ own claim. No additional statements attributed to Deadlock about this particular victim—beyond the fact of the listing and the reported exfiltration of internal files—are included in the available facts. Readers should treat unverified actor claims with appropriate caution until corroborated by the organisation or independent investigation.

About Schaad

Schaad Balass Menzl & Partner AG (SBMP) is a specialised Swiss intellectual-property boutique with offices in Zurich and Winterthur. The firm provides services in patent law, trademark law, and design protection. With more than fifty years of experience, it employs lawyers and technical experts who assist companies across industries with matters ranging from filing through enforcement.

IP practices routinely handle sensitive commercial and technical information: invention disclosures, patent drafts, trademark portfolios, correspondence with clients and authorities, and strategy documents. A breach affecting such a firm is consequential because the material it holds is often central to clients’ competitive position, product pipelines, and legal rights. Even when the exact contents of an incident remain unconfirmed, the nature of the work makes any unauthorised access or exfiltration a serious concern for the firm and those it represents.

The information in question

The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as specific categories of personal data, client lists, financial records, or technical documents—has been named in the available reporting. The number of individuals whose information may be involved is unknown.

Organisations of this type typically maintain client matter files, correspondence, billing and contact data, draft and filed IP applications, and internal administrative records. Whether any of those categories were among the files taken in this incident is unconfirmed. Until Schaad or competent authorities provide a clearer accounting, the precise contents of the exfiltrated material should be treated as undisclosed.

What's at stake

For people whose data may have been included, risks include unwanted contact, social engineering that leverages knowledge of real legal or commercial relationships, and, in some cases, longer-term misuse of personal or professional details. For corporate clients, exposure of IP-related material could affect pending applications, licensing discussions, or competitive confidentiality, depending on what was actually taken—something that remains unverified in public detail.

For the firm itself, consequences can include regulatory notification duties under applicable Swiss and European data-protection rules, contractual obligations to clients, reputational harm, and the operational cost of investigation and remediation. None of these outcomes are automatic; they depend on the still-undisclosed scope of the data and on how the incident is handled. The absence of a published count of affected individuals means the human scale of the event cannot yet be stated with precision.

What to do if you're exposed

If you have a past or present relationship with Schaad—as a client, employee, or counterpart—monitor communications for unusual requests that reference real matters or contacts. Prefer official channels when verifying any message that asks for credentials, payments, or sensitive documents. Consider placing fraud alerts or credit monitoring where appropriate to your jurisdiction, and review account passwords and multi-factor authentication on services you share with professional contacts.

Keep records of any suspicious contact and report it to the firm and, if needed, to local authorities. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which may help you decide what to secure next. Official updates from Schaad, when issued, should take precedence over third-party claims.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySchaad security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Schaad’s full breach history →

More recent breaches

Vinilon Listed by Deadlock Ransomware GroupJuly 25, 2026Kemek Listed by Deadlock Ransomware GroupJuly 25, 2026BioResearch Listed by Deadlock Ransomware GroupJuly 25, 2026Enedo Power Listed by Deadlock Ransomware GroupJuly 25, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Schaad Listed by Deadlock Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by deadlock — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram