On July 28, 2025, law firm Hankin & Mazel, PLLC appeared on the leak site of the pear ransomware group. The firm, which has represented cooperative and condominium boards in New York for more than 30 years, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates that samples of the stolen data have been posted, though the total number of people whose information is now exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Hankin & Mazel, PLLC
Get alerted the next time Hankin & Mazel, PLLC files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Hankin & Mazel, PLLC’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Available reporting describes the incident as a classic ransomware operation in which the attackers first gained access, encrypted systems, and then exfiltrated files before demanding payment. The data exposed consists of internal documents that a law firm handling real-estate and board matters would typically hold: contracts, financial records, correspondence, and client identifying details. No precise victim count has been released, and the firm has not yet issued a public statement detailing the volume or exact sensitivity of the files. The leak site listing itself serves as the primary public evidence, hosted on an onion address and mirrored by ransomware-tracking services such as ransomware.live.
Why This Matters for You and Your Family
When a law firm that manages housing-board records suffers a breach, the ripple effects reach everyday people. If you or your family live in a New York co-op or condominium represented by Hankin & Mazel, your names, addresses, financial information, or personal correspondence may now sit in an attacker-controlled archive. Internal files from such firms frequently contain Social Security numbers, bank routing details, tax records, and scanned identification documents. Once that information leaves the firm’s control, it can be sold, traded, or used to open accounts in your name. Children listed on family filings or guardianship papers are not exempt; their details often travel in the same datasets.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at posting generic “samples.” They publish enough material to prove they hold the full archive, then wait for payment. When payment is not made, the data frequently migrates to dark-web markets or private Telegram channels where doxxing crews buy it in bulk. A single leaked email or phone number becomes the starting node of an identity chain that links your online handles, gaming accounts, family addresses, and financial profiles. Credential leaks of this kind routinely cascade into account takeovers on Steam, Roblox, Discord, and other platforms where children maintain profiles tied to the same family email. The speed at which these chains form leaves most families unaware until fraudulent charges or harassing messages appear.