Sherr Puttmann Akins Lamb PC Listed by bianlian Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Sherr Puttmann Akins Lamb PC was listed by the Bianlian ransomware group on September 17, 2024, after internal files were exfiltrated in an attack. Individuals who may have had data with the firm should review their records and follow any guidance issued by the organization.
Ransomware groups continue to target professional-services firms that hold large volumes of personal and confidential records, using data theft as leverage even when encryption is secondary. Against that backdrop, the family-law practice Sherr Puttmann Akins Lamb PC was listed by the BianLian ransomware group on or around 17 September 2024. Public detail remains limited, yet the listing itself signals that internal material may have left the firm’s control, raising concrete privacy and security questions for anyone whose information the practice holds.
Because family-law files routinely contain highly personal details, any confirmed or claimed exfiltration carries lasting consequences for the individuals involved and for the firm’s ability to protect client confidentiality.
What happened
On 17 September 2024 it was reported that Sherr Puttmann Akins Lamb PC had been listed on a leak site operated by the BianLian ransomware group. According to the listing, the group claims to have exfiltrated internal files during a ransomware attack. The number of people affected is unknown, and no further technical details—such as the initial access vector, the precise date of intrusion, or the volume of data taken—have been publicly disclosed. The firm has not, in the available record, confirmed or denied the claim. At present the only concrete public statement is the group’s assertion that internal files were removed.
Inside bianlian
BianLian is a ransomware operation that has been active since at least 2022 and is known for a double-extortion model: after gaining access to a network, operators typically steal data before deploying encryption, then threaten to publish the stolen material if a ransom is not paid. The group has historically focused on mid-sized organisations across professional services, manufacturing and healthcare, often advertising victims on its dedicated leak site. Public reporting describes BianLian as favouring living-off-the-land techniques and remote-access tools rather than custom malware alone. The listing of Sherr Puttmann Akins Lamb PC is therefore consistent with the group’s established pattern of claiming data theft and using the threat of publication as pressure; it remains, however, an unverified claim by the actors themselves.
Who is Sherr Puttmann Akins Lamb PC?
Sherr Puttmann Akins Lamb PC is a full-service family-law firm that handles divorce, legal separation, child custody, juvenile-law matters and related domestic issues. Firms of this type routinely collect and store sensitive personal information—financial statements, medical and psychological records, correspondence about children, and detailed accounts of private family circumstances—because such material is essential to the legal work. A breach or claimed data theft at a practice of this kind is consequential precisely because the information is both intimate and long-lived; once outside the firm’s control it can be used for identity fraud, blackmail, or further social-engineering attacks against the same individuals.
What was likely exposed
The only data type named in the public record is “internal files” said to have been exfiltrated. Exact contents, file counts and any specific categories of personal data remain undisclosed. Organisations that practise family law typically hold client names and contact details, Social Security numbers or other government identifiers, bank and tax records, custody evaluations, medical information, and correspondence that may include children’s data. Whether any of those categories were among the files BianLian claims to possess has not been confirmed. Readers should therefore treat the exposure as unconfirmed beyond the general assertion of internal-file theft.
Why it matters
For individuals whose records may have been involved, the primary risks are identity theft, financial fraud, and the unwanted public disclosure of private family matters. Even partial files can supply enough personal detail to enable account takeovers or targeted phishing. For the firm itself, the incident raises questions of client trust, potential regulatory notification obligations, and the operational cost of investigating and containing the intrusion. Because the number of affected people is unknown and the precise data set is unconfirmed, the scale of residual risk cannot yet be quantified; the prudent assumption is that any client or employee whose information resided on the firm’s systems should treat the possibility of exposure seriously until more definitive information emerges.
If your data was in this claimed breach
Begin by monitoring financial accounts and credit reports for unexpected activity, and consider placing a fraud alert or credit freeze with the major credit bureaus. Change passwords on any accounts that may have shared credentials with the firm, and enable multi-factor authentication wherever it is offered. If you receive unexpected communications that reference personal or family details, treat them with caution and verify the sender through a known channel. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets; such a scan will not confirm or rule out involvement in this specific incident, but it can surface additional places where your information has previously circulated.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Giordano, DelCollo, Werb & Gagne, LLC. Listed by bianlian Ransomware GroupCottrell Fletcher & Cottrell P.C. Listed by bianlian Ransomware GroupKellerhals Ferguson Kroblin PLLC Listed by bianlian Ransomware GroupPalmisano & Goodman, P.A. Listed by bianlian Ransomware GroupLatest breaches
Publicly posted by bianlian — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.