On November 10, 2025, the personal injury law firm Gruel Mills Nims Pylman PLLC appeared on the leak site of the insomnia ransomware group. The Grand Rapids-based firm, which handles vehicle accidents, construction injuries, sexual abuse cases, and medical malpractice nationwide, is claimed to have had internal files exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Gruel Mills Nims Pylman
Get alerted the next time Gruel Mills Nims Pylman files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Gruel Mills Nims Pylman’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that insomnia posted data belonging to Gruel Mills Nims Pylman on its dark-web leak portal. The firm has not yet stated the breach publicly, but the listing includes references to internal files taken during the incident. No exact victim count inside the firm or among its clients has been disclosed. The posting aligns with insomnia’s typical pattern of publishing samples after encryption and failed ransom negotiations.
Why This Matters for You and Your Family
If you or anyone in your family has ever been represented by Gruel Mills Nims Pylman, your personal information may now sit in a ransomware data set. Internal files from a law firm often contain names, addresses, dates of birth, Social Security numbers, medical records, insurance details, and financial information tied to settlements. Once that material leaves the firm’s control, it can be sold, traded, or used to open accounts in your name. Children listed on family cases are not exempt; their information travels with the parent’s file and can be exploited years later.
The Doxxing and Identity-Chain Risk
Ransomware leaks rarely stop at one company. A single exposed email or phone number from the firm’s files can be cross-referenced with gaming accounts, social-media handles, and school records. This creates an identity chain that links your real name to every online alias your family uses. Credential leaks of this kind frequently cascade into account takeovers on Steam, Roblox, Discord, and other platforms where children maintain profiles. Public reporting shows that attackers and data brokers routinely combine these fragments to build full dossiers for identity theft, harassment, or further extortion.