On January 12, 2025, the qilin ransomware group listed Thilges & Bernhardt, Attorneys at Law on its leak site and announced that all of the firm’s internal files would be made available for public download on 19 January 2025.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Thilges & Bernhardt, Attorneys at Law
Get alerted the next time Thilges & Bernhardt, Attorneys at Law files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Thilges & Bernhardt, Attorneys at Law’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates the Missouri-based family law firm was hit by a ransomware attack in which attackers exfiltrated internal documents before encrypting systems. The qilin leak page states that the entire cache of stolen data will become freely downloadable after the deadline. The firm, originally founded in 1991, now operates with four attorneys focused exclusively on family law matters including divorce, child custody, and related personal legal issues. No exact victim count has been published, and the precise volume or sensitivity of the files remains unknown to the public at this time.
Why This Matters for You and Your Family
When a family law firm suffers a breach, the people most likely to be exposed are the firm’s own clients — ordinary individuals and families who shared highly personal information during divorce, custody battles, or support cases. Names, addresses, financial records, children’s school and medical details, and private correspondence may now sit on a ransomware leak site. Once that material reaches public forums or data brokers, it can be used for identity theft, harassment, or targeted scams. Even if you are not a current client, the precedent is clear: any professional who holds sensitive data about your household can become a gateway to your private life.
The Doxxing and Identity-Chain Risks
Family law files frequently contain multiple overlapping identifiers — email addresses, phone numbers, children’s names, social-media handles, and employer details. Attackers and opportunistic criminals can chain these fragments together to build a complete profile. A single leaked custody document can link a parent’s work email to a child’s gaming username, exposing both to account takeovers or physical doxxing. Credential leaks of this nature routinely cascade into gaming account compromises, especially for children who reuse passwords or security questions derived from family information.