West Sixth Law Listed by Global Secret Group Ransomware Group: What Was Exposed & What To Do
West Sixth Law was listed by the Global Secret Group ransomware group on July 26, 2026, after internal files were exfiltrated in an attack whose timing has not been established. Individuals who may have shared data with the firm should verify their exposure and take any recommended protective steps.
People who have dealt with West Sixth Law — clients, opposing parties, employees, or others whose records sit in a small firm’s systems — now face a familiar and unsettling question: whether material tied to them was copied in a ransomware incident and what that could mean in daily life. Public reporting places the firm on a leak site associated with the group known as Global Secret Group, with the listing dated July 26, 2026. The number of people affected is unknown, and the precise contents of any taken data have not been independently confirmed.
What is stated in available summaries is that internal files were exfiltrated in a ransomware attack, with the group’s materials describing a large volume of material. For anyone who has shared sensitive legal, financial, or personal information with a law practice, that claim alone is reason to pay attention, verify risk, and take basic protective steps while fuller detail remains limited.
Inside the incident
According to the public listing, West Sixth Law, a law firm based in Columbus, Indiana, United States, was named by the ransomware group Global Secret Group. The report is dated July 26, 2026. Available facts describe the event as a ransomware attack in which internal files were exfiltrated. The group’s listing associates the incident with a claimed data set of 328 GB, described as 708,816 files across 47,925 folders. How the attackers gained access, when the intrusion began or ended, whether systems were encrypted, and whether any ransom demand was made or paid are not disclosed in the material provided.
The count of individuals whose information may be involved is unknown. No independent confirmation of the group’s claims about volume or contents is included in the reported facts. The firm’s public web presence is associated with agslawyers.com; revenue is reported in summaries at about $5 million, with a staff size in the 11–50 employee range. Beyond the leak-site listing and those organizational details, public technical specifics of this incident remain limited.
The group behind it: Global Secret Group
Global Secret Group is presented in the reporting as a ransomware group. Like other actors in this category, such groups typically break into organizational networks, attempt to steal data before or during encryption, and pressure victims by threatening to publish or sell stolen material on dedicated leak sites if demands are not met. Public tracking of ransomware ecosystems shows that these operations often use double-extortion tactics: disruption of systems plus the threat of exposure. They commonly advertise victims with file counts, folder structures, or sample screenshots to increase pressure.
For this incident, the only attribution in the facts is the group’s own listing of West Sixth Law. That listing should be treated as a claim by the group, not as a fully verified forensic finding, unless and until the firm or independent investigators confirm the details. No statements from Global Secret Group beyond the fact of the listing and the claimed scale of material are provided in the source summary, and no additional quotes or victim-specific boasts are recorded here.
Who is West Sixth Law?
West Sixth Law is identified as a law firm and legal-services organization in Columbus, Indiana. Summaries place it in the law firms and legal services industry, with roughly 11–50 employees and reported revenue on the order of $5 million. Firms of this size typically handle client intake, case files, correspondence, billing, and related administrative records. They may work across civil, criminal, family, business, or other practice areas depending on their focus; the exact practice mix for this firm is not detailed in the breach facts.
Law practices are consequential targets because they concentrate information that clients and others expect to remain confidential: identities, contact details, case strategies, financial arrangements, medical or family matters in some practice types, and communications protected by professional privilege. A breach at even a mid-sized local firm can affect people far beyond the employee roster, including clients, opposing parties, witnesses, and vendors whose data appears in matter files or accounting systems.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. They do not publish a verified inventory of data types such as names, Social Security numbers, bank details, or medical records. The group’s listing claims a volume of 328 GB comprising 708,816 files and 47,925 folders; that figure is part of the group’s claim and has not been independently itemized in the provided reporting.
Organizations in legal services commonly hold client contact information, case documents, contracts, invoices, internal email, employee records, and credentials or system logs used to run the practice. Whether any of those categories were among the files taken in this incident is unconfirmed. Exact contents remain undisclosed in public detail. Readers should not assume a specific document about them was or was not included without further notice from the firm or a reliable breach notification.
Why it matters
For individuals, exposure of legal-matter data can mean more than generic identity theft risk. Case-related documents may reveal personal disputes, financial positions, health or family circumstances, or strategic information that could be misused for fraud, extortion, or reputational harm. Even partial files — a scanned ID, a retainer agreement, or an email thread — can be enough for social engineering aimed at the person or at the firm’s other clients. Because the number of people affected is unknown, the practical scope of that risk is still unclear.
For the organization, a ransomware event with claimed exfiltration raises operational, professional, and regulatory concerns: continuity of client work, duties to protect confidential information, possible notification obligations, and the cost of investigation and remediation. None of those outcomes are established as facts in the source material; they are the ordinary consequences such incidents can bring. The listing itself can also affect trust among clients who must decide how to respond while waiting for clearer information.
If your data was in this breach
If you are a current or former client, employee, or other party who has shared information with West Sixth Law, treat the situation as a prompt for caution rather than panic. Watch for unexpected contact that references legal matters, invoices, or personal details; verify any such contact through known firm channels rather than links or numbers supplied in unsolicited messages. Consider placing fraud alerts or credit freezes if you have reason to believe highly sensitive identifiers were on file, and review financial and email accounts for unusual activity. Preserve any official notice you receive from the firm.
Exact confirmation of whose data was taken is not available in public reporting. As a practical check, you can run a free exposure scan of your email address to see whether your information has already appeared in known breach data sets elsewhere. That step does not prove involvement in this specific incident, but it helps you understand your broader exposure and prioritize next actions while official details, if any, are still emerging.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Baker Business & Tax Solutions Listed by Global Secret Group Ransomware GroupPark Manufacturing Corp. Listed by Global Secret Group Ransomware GroupLouisiana Coalition Against | Domestic Violence Listed by Global Secret Group Ransomware GroupNourison | Home Listed by Global Secret Group Ransomware GroupLatest breaches
Publicly posted by global-secret-group — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.