On February 27, 2024, Toronto-based law firm Whaley Estate Litigation Partners appeared on the leak site of the incransom ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the boutique trusts-and-estates litigation practice. The disclosure does not quantify how many individuals are affected, nor does it list the specific documents posted.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch WEL Partners
Get alerted the next time WEL Partners files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about WEL Partners’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Leak-Site Posting
The incransom leak site entry states that WEL Partners, which focuses exclusively on estate litigation across Ontario, suffered a ransomware incident resulting in data exfiltration. The posting includes a sample of the allegedly stolen material but does not enumerate record counts or name the precise data types beyond “internal files.” No ransom demand figure is shown on the public page, and the notification does not specify when the intrusion occurred or which systems were initially compromised. Public reporting on incransom indicates the group follows a double-extortion model: encrypt where possible, then threaten to publish sensitive exfiltrated data unless payment is made.
Why This Matters for You and Your Family
If you or a family member worked with WEL Partners on estate planning, wills, trusts, or probate matters, your personal information may now sit in an attacker-controlled archive. Estate litigation files routinely contain full names, dates of birth, Social Insurance Numbers, financial account details, family relationships, health information, and copies of wills or trust instruments. Exposure of this data raises the risk of identity theft, fraudulent loan applications, tax-refund fraud, and targeted scams that reference intimate family details. Because the breach involves a specialized legal practice, the stolen material can also reveal inheritance plans, beneficiary disputes, or asset distributions that criminals could exploit to impersonate relatives or pressure family members.
The Doxxing and Identity-Chain Risk
Legal-client files often link multiple pieces of personally identifiable information with email addresses, phone numbers, and physical addresses. Once published on a ransomware leak site, that information can be scraped and fed into automated correlation tools that map your online handles back to your real-world identity. The result is an identity chain: a single leaked email can unlock linked gaming accounts, social-media profiles, or family-shared credentials. Credential leaks of this nature frequently cascade into account takeovers, especially for gaming platforms used by children or teens who reuse passwords. DoxxScan by GalaxyWarden continuously monitors across 13.1B+ breach records and 100+ platforms with AI-powered identity-chain mapping, helping surface these connections before criminals act.