Emery Celli Brinckerhoff Abady Ward & Maazel LLP appeared on the Abyss ransomware leak site on September 14, 2024. The New York-based civil-rights and commercial litigation boutique was listed after attackers claimed to have exfiltrated internal files during a ransomware incident. The leak-site posting does not specify how many individuals are affected or exactly which documents were taken, leaving current and former clients, employees, and business partners uncertain about their exposure.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch ecbawm.com
Get alerted the next time ecbawm.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about ecbawm.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Abyss ransomware group’s public leak page states that it obtained internal files from ecbawm.com in a ransomware attack. The disclosure indicates that data was exfiltrated but provides no count of records, no sample documents, and no deadline for payment. Public views of the listing state the firm’s full name and website but do not reveal the content of the stolen material. The notification does not state whether client case files, employee records, or financial documents were included.
Why This Matters for You and Your Family
When a law firm that handles civil-rights, criminal, and ethics cases loses control of internal files, the people whose sensitive matters appear in those files face immediate risk. If your name, address, Social Security number, medical details, financial records, or court-case notes were stored in the firm’s systems, that information may now sit on a criminal server. Even without exact numbers, the breach represents a high-severity incident because litigation firms routinely hold the kind of personal data that identity thieves and stalkers prize. Any client or employee of the firm since its founding should treat their information as potentially exposed.
Doxxing and Identity-Chain Implications
Stolen internal files often contain more than isolated records. They can include spreadsheets that link names to addresses, phone numbers, email accounts, and opposing-party details. Attackers and downstream data brokers can combine these fragments with login credentials or customer lists from other breaches to build complete identity chains. A single leaked email can lead to gaming accounts, family photos, or children’s online profiles. Credential leaks like this one frequently cascade into account takeovers that expose additional personal material, creating a widening circle of doxxing risk for you and everyone in your household.