INC Ransom Targeted 24 Law Firms, but Only 10 are Listed
INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. Cross-referencing those 24 firms against INC’s known leak site months later, roughly 58% (14 of 24) do not appear there, while 42% (10 of 24) are listed.

Anonymized example of an extortion page: countdown timer, breach notice addressed to the firm’s clients, and the “Staff of Shame” photo row. Company name, contact details, and faces redacted.
Absence from a leak site is not proof a victim paid. An organization also may not be listed because a negotiation is still open, a partial settlement was reached, or for reasons unrelated to payment entirely. Even so, 58% is a striking number for a matched set of victims we can check one at a time, and it fits the logic of the tactic itself: extortion aimed at a firm’s own clients raises the reputational and legal stakes well past what a single leak-site listing does, giving firms a much stronger incentive to resolve the incident quickly and quietly.
A Campaign Built to Include Pressure from the Client Base
Unlike INC’s data leak site (DLS), these pages sit on plain clearnet domains, patterned as [firm-name]-leak.com, hosted across a small number of dedicated IPs. That’s a deliberate choice; a clearnet link opens in any browser and drops straight into an email or text to a firm’s clients, no Tor required.
Every page SOCRadar reviewed used the same template. A live countdown to a data-publication deadline, a notice warning the reader that “the law firm you trusted” suffered a breach and failed to protect their Social Security number, ID, passport, home address, and case files, a direct instruction to contact their lawyer and demand action, and a photo gallery of the firm’s own staff, labeled “Staff of Shame” on at least one page. Based on these sites’ content, SOCRadar assesses that the threat actors emailed the firms’ clients and attached these pages to pressure the victim organization into paying the ransom.

Another firm’s page: identical template, different countdown deadline.
A third example: same boilerplate copy, only branding and contact details change.
The Payment Signal, in More Detail
All 24 identified firms are US-based; the dedicated pages themselves went offline around the time the campaign became public and are no longer reachable. Checking each associated firm against INC Ransom’s leak site showed:
- 10 of 24 (41.67%) are listed on INC’s leak site,
- 14 of 24 (58.33%) are not listed.
That’s consistent with more than half of this specific cluster having resolved the incident in a way that kept their data off the public leak site, whether through payment, a negotiated partial arrangement, or another outcome we can’t see from the outside.
It’s still just an absence, not a confirmation. Either way, it’s a more direct payment-adjacent signal than most ransomware reporting gets to work with, because this cluster gives us a clean, matched set of victims to check one by one.

INC Ransom’s “disclosures” leak site.
Why It Matters
Most ransomware pressure plays out strictly between the group and the victim organization. Here, it’s aimed at the victim’s own client base, the people a law firm depends on most to trust them with sensitive matters, and it’s working: 58% of this cluster is not listed on INC’s leak site, a notably higher rate than we typically see across ransomware incidents. That’s a strong incentive for other affiliates to copy the tactic against any client-facing profession: accounting, healthcare, financial advisory.
How to Reduce Your Risk
By using SOCRadar’s Digital Risk Protection, you can catch newly registered, brand-adjacent domains as soon as they’re registered, in time to request a takedown before they’re weaponized against your clients. SOCRadar’s Supply Chain Intelligence extends that visibility to the vendors, platforms, and managed service providers you depend on, surfacing exposed credentials and breach indicators tied to third parties before they become your own incident.
Conclusion
This tactic didn’t emerge in isolation. Other groups working the legal sector, like Silent Ransom Group, get similar results through phone-based social engineering instead of a dedicated website, just one of several playbooks running under “ransomware group targeting law firms.” The specialization runs deeper too; SOCRadar’s Threat Research Unit has separately profiled FortiBleed, a credential-harvesting operation feeding FortiGate access to INC and Lynx affiliates, unconnected to this cluster as far as we can tell. Kit names and delivery methods will keep changing, but a client-facing pressure tactic that converts this well is one other affiliates will keep reaching for, worth watching across every client-facing industry, not just law firms.

