On January 25, 2026, the website of McMath Woods P.A., a personal injury and family law firm in Little Rock, Arkansas, appeared on the leak site operated by the Clop ransomware group. Internal files were allegedly exfiltrated during a ransomware attack, and the firm’s clients — individuals and families who sought legal help after car accidents, workplace injuries, wrongful death, or environmental harm — now face the possibility that sensitive personal information is in the hands of criminals.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Mcmathlaw.Com
Get alerted the next time Mcmathlaw.Com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Mcmathlaw.Com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that McMath Woods P.A. was listed on the Clop leak site hosted at an onion address. The data consists of internal files exfiltrated during a ransomware incident. The exact number of people affected remains unknown, and the specific documents have not been publicly detailed beyond the firm’s own description of its casework involving personal injury, employment disputes, and family-related legal matters. No confirmation has emerged about the precise date the intrusion occurred or the initial access method used.
Why This Matters for You and Your Family
When a law firm that handles car accidents, workplace injuries, and wrongful death claims loses control of its files, the people most exposed are ordinary clients — not corporations. Medical records, insurance details, home addresses, phone numbers, employment histories, and family circumstances can all sit inside those documents. Once that information leaves the firm’s protected systems, it can be sold, posted, or used to pressure victims into paying to keep their cases private. For many families, the breach turns an already difficult legal situation into a permanent privacy problem.
Credential leaks like this one frequently cascade into account takeovers on email, banking, and government portals that were referenced during the legal process. Children’s information tied to a parent’s case file can also surface, creating long-term risks that extend beyond the original client.