On October 24, 2023, the Canadian law firm McCarter Grespan (mgbwlaw.com) was listed on the LockBit 3.0 ransomware leak site, with the group claiming to have exfiltrated internal files during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch mgbwlaw.com
Get alerted the next time mgbwlaw.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about mgbwlaw.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page states that McCarter Grespan, a Kitchener-based firm offering business and litigation services, suffered a ransomware intrusion in which attackers copied internal documents before encrypting systems. The disclosure does not quantify the number of records affected, list specific data types beyond “internal files,” or reveal the exact date of initial compromise. It does not detail ransom demands or whether any client personally identifiable information was taken. The listing follows the group’s standard format: a countdown timer, a sample of allegedly stolen files, and the threat to publish the full archive if payment is not received.
Why This Matters for You and Your Family
When a law firm’s internal files are stolen, the exposure often reaches far beyond the business. Clients entrust these firms with names, addresses, dates of birth, Social Insurance Numbers, financial records, court documents, and correspondence that can tie directly to your household. Even if the leak site does not publish every record immediately, the mere confirmation that data left the firm’s control creates lasting risk. If your family has ever used McCarter Grespan for estate planning, real estate closings, family law, or small-business incorporation, your information may now sit in an attacker’s archive. The disclosure indicates the breach is real; the volume and sensitivity of what was taken remain unknown to the public.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at encryption. Once internal files are exfiltrated they are sorted for high-value personal data that can be sold, leveraged for extortion, or used to launch follow-on attacks. A single leaked email or phone number from a law-firm directory can be chained with other breaches to map your full digital footprint—linking banking logins, children’s school records, and even gaming accounts. Credential leaks like this one cascade into account takeovers that expose family members who never interacted with the firm. Doxxers use these chains to harass, impersonate, or demand payment by threatening to release sensitive family or business documents. The longer the data sits in underground repositories, the more likely it is to surface in unexpected places months or years later.