On January 24, 2024, Canadian law firm MBC Law Professional Corporation appeared on the leak site operated by the alphv ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the Ottawa-based legal services provider. The disclosure does not quantify how many individuals or records are affected, nor does it list the specific types of documents taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch MBC Law Professional Corporation
Get alerted the next time MBC Law Professional Corporation files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about MBC Law Professional Corporation’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The alphv leak site entry, still accessible via the .onion link as of the initial publication date, claims that MBC Law Professional Corporation suffered a ransomware intrusion and that attackers successfully removed internal files. No sample data is shown publicly, and the posting does not specify the volume or exact nature of the stolen material. The firm, which operates in the legal sector and employs between 11 and 20 people, has not released its own public notification detailing the incident. Public reporting on alphv indicates the group frequently uses its leak site to pressure victims after encryption and data theft.
Why This Matters for You and Your Family
When a law firm’s internal files are taken, the exposure often includes documents containing names, addresses, dates of birth, financial details, and sensitive case notes for clients. Even though the exact contents remain undisclosed, anyone who has worked with MBC Law or whose records passed through the firm now faces heightened risk. Legal client data is especially valuable because it can tie personal identifiers to financial histories, family matters, or immigration status. If your information was among the exfiltrated files, it could surface on dark-web markets or be used in follow-on fraud attempts months or years later.
The Doxxing and Identity-Chain Risk
Ransomware leaks rarely stop at one company. Stolen internal files frequently contain spreadsheets that link client names to email addresses, phone numbers, and sometimes spouse or child details. These fragments allow attackers or opportunistic criminals to build identity chains that connect your professional life to your home address, online accounts, and family members. A single exposed email can lead to credential-stuffing attempts against banks, government portals, or children’s gaming logins. Once an attacker maps one handle to a real person, the chain grows quickly, increasing the chance of doxxing, targeted phishing, or account takeover. Credential leaks like this one cascade into account takeovers and doxxing chains that can affect every member of a household.