Back to Blog
high severity August 14, 2026 · 4 min read Unverified claim — what this is

Tapper Cuddy LLP Listed by Storm Ransomware Group

If you have an account with Tapper Cuddy LLP, here’s what is being claimed, and what it would mean for you.

Tapper Cuddy LLP is a full-service law firm based in Manitoba, specializing in civil litigation, family law, and commercial law. With over 40 years of experience, the firm is dedicated to providing personalized legal representation in a clear and understandable manner. They prioritize client relationships, viewing clients as people rather than cases, and aim to serve a diverse range of legal needs across more than 20 specialized practice areas. Tapper Cuddy LLP is committed to reconciliation and collaboration with Indigenous communities, reflecting their respect for the traditional territories

— from Storm’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Tapper Cuddy LLP Listed by Storm Ransomware Group

Your account credentials at Tapper Cuddy LLP may now be in the hands of the Storm Ransomware Group. The group has listed the Canadian law firm on its leak site and claims to have obtained internal files, including what it describes as a password database.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

That single fact changes your immediate risk profile. If the claim is accurate, attackers now hold at least one set of login details tied to you. Because the storage scheme for those passwords has not been disclosed, you must treat the credential as potentially usable right now. The company has not publicly confirmed the incident as of this writing.

What the Storm Ransomware Listing Actually Shows

A ransomware-extortion crew posting a company name on a leak site is an accusation, not proof. These groups routinely publish victim lists to pressure payment. Sometimes the data is fresh. Sometimes it is recycled from an earlier breach. Sometimes the listing contains no real data at all and exists only to create panic or negotiation leverage.

Until the company itself, a regulator, or an independent forensic report confirms that client or employee data left their environment, the incident remains unverified. No independent breach index has validated the claim. Have I Been Pwned surfaces the listing because the group published it, not because the breach has been proven.

This distinction matters for your decisions. Believing every leak-site claim produces unnecessary anxiety and wasted effort. Dismissing every claim because “nothing is confirmed yet” can leave you exposed if the data is real. The rational middle ground is conditional caution: act as though the password is compromised until you have changed it, while recognising that the full scope of the incident may never be known.

The Password Situation Is Not Yet Clear

The listing mentions a password field but does not reveal how those passwords were stored. That absence of detail is important. Without knowing whether they were stored using strong, salted hashing or in a weaker format, the safest assumption is that at least some of them could be cracked or used directly.

Because no permanent personal identifiers such as Social Insurance Numbers were included in the exposed fields, the long-term identity theft risk is lower than in many other incidents. The primary near-term risk is account takeover if you reused the same password anywhere else.

Why Law Firms Keep Appearing on These Lists

Law firms remain frequent targets for ransomware groups because they hold highly sensitive client information: contracts, financial records, litigation strategy, and personal details of high-net-worth individuals. That data can be worth far more than the ransom itself when sold on underground markets or used for extortion.

Many firms still lag behind the defensive investment levels seen in banks or large technology companies, even though their risk profile is comparable. The pattern is clear across multiple ransomware leak sites over the past three years: law practices continue to surface, often with the same initial access vectors — phishing, compromised remote desktop credentials, or third-party software vulnerabilities.

For you as a client or former client, this pattern means one practical takeaway. Assume that any law firm holding your sensitive documents will eventually face at least one serious incident. Reduce your exposure by limiting the number of firms that hold copies of your most critical files and by never reusing passwords across different legal service providers.

What You Should Do Right Now

  1. Change your Tapper Cuddy LLP password immediately — and do not reuse it anywhere else. Use a unique, randomly generated password at least 16 characters long.
  2. Enable multi-factor authentication on the account if you have not already done so. This blocks most credential-stuffing attacks even if the password is already known to the attackers.
  3. Review every other account where you used the same password. Change those too, starting with email, banking, and any accounts that contain financial or health information.
  4. Check your credit reports and account statements for unexpected activity. While no government identifiers may have been exposed, stolen legal correspondence can still give attackers enough context to attempt impersonation or targeted fraud.
  5. Be wary of any unsolicited contact claiming to be from Tapper Cuddy LLP. Phishing attempts often increase after a leak-site listing as attackers try to capitalise on the news.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, along with identity-chain mapping and remediation support by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Tapper Cuddy LLP is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 14, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email