Henshaw Law Data Breach

Alleged

Ransomware claim involving Henshaw Law

Published: Aug 5, 2026 Triple X
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Henshaw Law
Industry
Business Services
Threat Actor
Triple X
Date of Incident
Aug 5, 2026

Executive Summary

Henshaw Law, a professional services firm based in the United Kingdom, has been identified as a victim on the Triple X ransomware group’s dark web portal, with the listing published on August 5, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. Operating within the legal services sector, Henshaw Law likely handles a significant volume of sensitive client data, making it a potential target for ransomware attacks. The Triple X group’s portal has shown very low activity, with this listing being one of only a few entries. In the 60 days preceding this listing, Triple X claimed only two other victims: a legal services provider in the United States and an entry related to banking in Indonesia. This limited activity places Triple X among the smaller operations tracked. The claimed victims span the professional services, business services, and financial services industries, with geographical distribution across the United Kingdom, the United States, and Indonesia. Given the small sample size of victims, it is difficult to establish a definitive targeting pattern. However, two out of the three listed victims are in the legal or financial sectors, which aligns with Henshaw Law’s industry. While this overlap might suggest a pattern, analysts should exercise caution when interpreting the threat actor’s intent due to the extremely limited number of known victims.

Technical Analysis

SOCRadar’s analysis of initial access vectors against its stealer-log telemetry returned no records associated with Henshaw Law’s domain within the queried dataset. It is crucial to understand that a null result does not confirm the absence of a compromise. The telemetry query covered a paginated sample, not the entire dataset, and could potentially exclude credentials associated with alternative or subsidiary corporate domains. Furthermore, credentials harvested using personal email aliases, which are not uncommon in smaller legal practices that may use personal accounts alongside firm infrastructure, would not surface against the corporate domain in this type of query. For threat groups like Triple X, credentials obtained through infostealers are a recognized method for initial access. Threat actors or initial access brokers often source these credentials from underground marketplaces, validate them, and then use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While specific tradecraft for Triple X is not extensively documented, this general pattern is commonly observed within the ransomware landscape. The absence of evidence in this specific query does not preclude the possibility of such an intrusion path. It is possible that compromised credentials appeared in data feeds outside the scope of this query, were used and subsequently rotated before indexing, or were harvested under personal email addresses. Consequently, threat intelligence teams should prioritize ongoing monitoring of dark web and stealer-log feeds, alongside proactive credential hygiene checks, rather than interpreting a null query result as a definitive indication of security.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.