On May 9, 2024, the law firm Corr & Corr appeared on the leak site of the Everest ransomware group, with the attackers giving the firm its final 24 hours to negotiate before publishing what they claim is 100 GB of internal files stolen during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Corr & Corr
Get alerted the next time Corr & Corr files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Corr & Corr’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The Everest leak page states that Corr & Corr suffered a ransomware intrusion in which attackers exfiltrated internal files. The listing does not specify the exact data types taken, nor does it name the number of individuals whose information may be inside the archive. It simply warns that all data will be published if the firm remains silent. The page includes a link to the company’s website, corrca.com, and notes the total volume of stolen material as 100 GB. No sample files have been released publicly at the time of this writing, and the disclosure itself contains no further technical details about the initial access vector or the precise systems compromised.
Why This Matters for You and Your Family
When a law firm’s internal documents are stolen, the exposure often reaches far beyond the business. Client records, correspondence, financial details, Social Security numbers, medical information, and family legal matters can sit inside the same shared drives that ransomware groups target. If your name, address, date of birth, or financial history appears in any of those files, the breach creates a permanent risk that the information will surface on dark-web markets or extortion forums. Even if the listing does not quantify affected records, the 100 GB volume suggests a substantial trove that could contain sensitive details about hundreds or thousands of individuals and their families.
The Doxxing and Identity-Chain Risk
Ransomware operators rarely stop at posting a single archive. Once data appears on a leak site, other criminals scrape it, cross-reference it with earlier breaches, and build detailed identity chains. An email address found in the Corr & Corr files can be linked to gaming accounts, social-media handles, or reused passwords, quickly turning a legal-matter leak into full doxxing. Children’s records are especially vulnerable because family legal files often list dependents’ names, dates of birth, and school information alongside parental contact details. These linkages can cascade into account takeovers on gaming platforms or social networks where kids use the same email or password patterns as their parents.