ICE lawyer's address posted online: what the 2026 case actually exposed
If you are a customer of ICE lawyer's address posted online, here’s what is being claimed, and what it would mean for you.
In February 2025 a Santa Monica man posted an ICE attorney’s home address and told people to send a SWAT team to her house. He pleaded guilty and was sentenced in August 2026 to 27 months in federal prison. This was a crime against one person, not a stolen list of addresses.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
ICE lawyer's address posted online customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
In February 2025, Gregory John Curcio of Santa Monica posted on Facebook identifying an ICE attorney, published her home address, and told other people to “swat” her — meaning make a fake emergency call so armed police would go to that house. He put the same address and the same instruction on a second social-media account he controlled. He was arrested in September 2025 and pleaded guilty in June 2026 to one federal count of violating the law that protects people doing certain official duties.
On 21 August 2026 he was sentenced to 27 months in federal prison. The maximum for that charge was five years. He was 68 when arrested and 69 at sentencing. The Department of Justice and ICE have not named the attorney. They describe a harassment campaign going back to at least January 2024. No official source says a SWAT team was actually sent.
This is not a data leak, and there is no list to check
Coverage of this case leads with the crime, the guilty plea, and the prison term. That is all true. What it leaves sitting in the background is the question a regular person actually has after seeing the words “doxxed” and “home address” next to a federal agency: is there a dump, and am I in it?
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
There is not. Nobody broke into a government system. Nobody stole a spreadsheet of ICE staff, neighbors, or anyone else. One man who already knew this attorney typed her address into Facebook and invited strangers to send police to her door. Prosecutors could use a federal statute because of her official work. That is a targeted crime against one person. It is not a breach that might quietly include you.
The sentence can also read like the story is over. For the attorney, the address is still out. Posts get saved and copied. Official accounts have kept her name unpublished; this article will not fill that in. If you came here to find out whether your address was part of this, the honest answer is that this case never produced a list anyone could match you against — including us.
What to actually expect
- You will not receive a notice that you were “affected.” There is no company sending emails, no stolen file, and no roster beyond one unnamed attorney.
- A search of breach databases cannot tell you whether you were in this case, because there is no such file to search. A clean result would not mean you were checked and cleared.
- Authorities have described the posts and the swatting instruction. They have not said that police were actually tricked into going to her home.
- Curcio is serving 27 months in federal prison. There is no credit-monitoring offer and no second wave of records coming out of this case.
What you can and cannot fix
The home address he posted cannot be undone. It cannot be recalled from people who saw it, saved it, or shared it. Prison does not delete a post. If you are not the attorney in this case, none of that information is yours, and there is nothing from this incident to take down.
- Do not search for her name or address to double-check. Official sources left her anonymous on purpose. Looking, screenshotting, and forwarding is how one post becomes permanent.
- If your own address has been posted in some other situation, treat that original post as unrecoverable. You cannot get it back from everyone who already has it.
- What you can still reduce is the extra detail that people-search and data-broker sites attach to a name — relatives, phone numbers, employers, and previous addresses. A single posted address becomes much more dangerous when those sites stitch it to a full household file, and unlike the original post, those listings can often be removed.
- If someone has posted your address with a threat or a swatting instruction, contact law enforcement. That is the same kind of conduct that was charged as a federal crime in this case.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Autistici/Inventati Named a Terror Group: Does the ICE Doxing Affect You?
On August 26, 2026, the U.S. government designated Autistici/Inventati a terrorist organization, say…
Brightspeed Fiber Broadband Incident — January 2026
Crimson Collective ransomware group allegedly stole personal data of over 1 million Brightspeed cust…
Anywhere Real Estate 17K Records — February 2026
Real-estate brokerage Anywhere Real Estate disclosed a breach exposing PII for approximately 17,000 …