On July 28, 2025, the kairos Ransomware Group listed mortensenlawoffices.com on its leak site, claiming to have exfiltrated 99GB of internal files from the California-based law firm Mortensen Law Offices.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Mortensen Law Offices
Get alerted the next time Mortensen Law Offices files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Mortensen Law Offices’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates the firm’s data appeared on the kairos leak site hosted on the dark web. The posting includes a sample of the allegedly stolen material and states that 99GB of internal documents were taken during a ransomware incident. The exact number of individuals whose information may have been exposed remains unknown. Available reporting describes the data as internal files, though specific categories such as client names, Social Security numbers, or financial records have not been independently verified in open sources.
Why This Matters for You and Your Family
When a law firm’s internal files are stolen, the people whose documents were stored there face direct risk. If your estate plan, divorce records, personal injury claim, or any other legal matter was handled by Mortensen Law Offices, your private information may now sit on a ransomware site. Client files from law offices frequently contain full names, addresses, dates of birth, Social Security numbers, bank details, and family information. Once that data leaves the firm’s control, it can be sold, traded, or used to open accounts in your name. Your family members listed in those files—including children—are also exposed.
The Doxxing and Identity-Chain Risk
Ransomware groups rarely stop at one leak. Stolen legal files often contain email addresses, phone numbers, and account handles that link together. Attackers can follow these connections to gaming accounts, social media profiles, and school records. A credential found in the 99GB dump can lead to takeover of your child’s Roblox or Fortnite account, which in turn reveals your home address through linked payment methods or chat logs. This is exactly how small breaches become long-term doxxing campaigns. Credential leaks cascade into account takeovers that expose far more than the original files suggested.