Thilges & Bernhardt, Attorneys at Law Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Thilges & Bernhardt, Attorneys at Law was listed by the qilin ransomware group on January 12, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of people. Anyone who may have shared personal information with the firm should check for official updates and monitor their accounts for suspicious activity.
People who have worked with a family-law firm may find their personal histories, financial details, or court-related documents suddenly at risk when that firm appears on a ransomware group's leak site. For clients of Thilges & Bernhardt, Attorneys at Law, the listing by the group known as qilin raises immediate questions about what internal material may have been taken and whether it will become public. The practical stakes are concrete: sensitive records that describe divorces, custody arrangements, or financial settlements could be exposed, creating lasting privacy and security concerns for ordinary individuals who never expected their legal matters to surface online.
Public reporting on 12 January 2025 indicated that the firm had been listed by qilin, with the group claiming that all of the company's data would be made available for download on 19 January 2025. The number of people potentially affected remains unknown, and independent confirmation of the full scope is limited. What is known is that the listing itself signals a ransomware incident in which internal files were allegedly exfiltrated.
Breaking down the breach
According to the available public record, Thilges & Bernhardt, Attorneys at Law was listed by the qilin ransomware group on or around 12 January 2025. The group claimed that internal files had been exfiltrated during a ransomware attack and stated that all data of the company would be available for download beginning 19 January 2025. No verified figure for the volume of data, the precise method of intrusion, or the number of individuals whose information may be involved has been released in the public facts. Timing details beyond the listing date and the claimed publication deadline are also undisclosed. The incident is therefore known primarily through the group's leak-site claim rather than through a detailed independent disclosure from the firm or regulators.
In ransomware cases of this type, attackers typically encrypt systems and remove copies of data to increase pressure for payment. Here the public facts confirm only that internal files were described as exfiltrated and that a download deadline was announced. Whether any ransom demand was made, whether systems were restored, or whether the claimed data was ultimately published remains outside the confirmed record.
Inside qilin
qilin is a ransomware operation that has been active for several years and is known for a double-extortion model: encrypting a victim's systems while also stealing data and threatening to publish it if payment is not received. The group typically operates through affiliates who gain initial access, often via compromised credentials, phishing, or exploitation of remote-access tools, then deploy the ransomware payload. Once inside, operators commonly spend time mapping networks, identifying valuable file shares, and exfiltrating large volumes of data before encryption begins. Public reporting on prior qilin activity has documented attacks against professional services, manufacturing, and other mid-sized organizations, with leak sites used both to pressure victims and to advertise the group's capabilities.
In this instance the group claims to have listed Thilges & Bernhardt and to have scheduled the release of the firm's data. That claim should be treated as an assertion by the threat actor rather than independently verified fact. qilin's public communications frequently include brief descriptions of the victim and countdown timers for data release; the language used here—that all data of the company will be available—is consistent with that pattern. No additional statements attributed specifically to this victim beyond the listing and the 19 January 2025 download date appear in the available facts.
Thilges & Bernhardt, Attorneys at Law and its sector
Thilges & Bernhardt, Attorneys at Law is a small firm dedicated exclusively to family law. Public information associated with the listing notes that the firm was founded in 1991 by J. Bradley Short and Ray L. Borth, both now retired, and that it currently operates with four attorneys. Family-law practices handle matters such as divorce, child custody, support, adoption, and related financial settlements. These cases routinely require clients to share highly personal information: income and asset statements, medical or psychological records, correspondence, and court filings that detail private family circumstances.
Law firms of this size and specialty sit at the intersection of professional confidentiality and sensitive personal data. Ethical rules and professional standards require attorneys to safeguard client information, yet the digital systems used to store case files, emails, and billing records remain attractive targets for ransomware operators. A breach at such a firm is consequential precisely because the data is both intimate and long-lived; custody arrangements or financial disclosures may remain relevant for years, and exposure can affect not only the clients but also children and other family members named in the records.
The information in question
The public facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of specific data types—such as client names, Social Security numbers, financial statements, or medical records—has been disclosed. Exact contents therefore remain unconfirmed. Organizations of this kind typically hold case-management databases, scanned court documents, email archives, billing and trust-account records, and correspondence that may contain personally identifiable information and sensitive family details. Because the facts do not name those categories as confirmed exposures, it is accurate only to say that internal files were claimed to have been taken and that the precise nature of any released material is not yet publicly verified.
What's at stake
For individuals whose information may be among the internal files, the risks include identity theft, financial fraud, and the public exposure of private family matters. Court documents or financial affidavits that surface online can be used for targeted scams, harassment, or simply permanent loss of privacy. Children named in custody files may face long-term consequences if sensitive details become searchable. Even if the data is never published, the mere possibility of exposure creates anxiety and may require clients to monitor credit reports, change passwords, and remain alert for phishing that references their legal matters.
For the firm itself, the stakes involve professional reputation, potential regulatory or ethical inquiries, and the cost of investigation, notification, and remediation. Small practices often lack the resources of larger corporate legal departments, so recovery can be slower and more disruptive. Clients may lose confidence and seek representation elsewhere. None of these outcomes is inevitable, but each is a realistic consequence when a ransomware group claims to hold a law firm's internal files.
Were you affected?
If you have been a client of Thilges & Bernhardt or have otherwise shared personal information with the firm, treat the listing as a reason to take basic protective steps. Monitor bank and credit-card statements for unusual activity, place a fraud alert or credit freeze if you believe sensitive identifiers may be involved, and be cautious of unsolicited emails or calls that reference your legal matters. Change passwords on any accounts that may have reused credentials associated with the firm. Because the number of people affected and the exact data types remain unknown, these measures are prudent rather than panic-driven.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan does not confirm or rule out involvement in this specific incident, but it provides a practical starting point for understanding whether personal information has previously circulated. Stay alert for any official notification from the firm itself; until further verified details emerge, caution and routine monitoring remain the most useful responses.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Elslaw.com ( EARLY , LUCARELLI , SWEENEY & MEISENKOTHEN LAW ) Listed by qilin Ransomware GroupJohn G Yphantides A Professional Law Listed by qilin Ransomware GroupLaw Office of Steven R Smith Listed by qilin Ransomware GroupGeorgia Dermatology & Skin Cancer Center Listed by qilin Ransomware GroupLatest breaches
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.