Dissinger and Dissinger Law Firm Data Breach

Alleged

Ransomware claim involving Dissinger and Dissinger Law Firm.

Published: Jul 16, 2026 Gunra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Dissinger and Dissinger Law Firm
Industry
Business Services
Threat Actor
Gunra
Date of Incident
Jul 16, 2026

Executive Summary

Dissinger and Dissinger Law Firm, a business services company based in the United States, has been listed as a victim on the Gunra threat group’s dark web portal. The listing was published on July 16, 2026, and identified through SOCRadar’s Dark Web Monitoring service. The organization operates within the Business Services sector and its appearance on the leak site places it within Gunra’s recent activity targeting multiple regions and sectors. In the 60 days preceding this listing, Gunra claimed eight other victims. The group predominantly targets the Business Services, Financial Services, and Transportation/Logistics sectors. Geographically, its victims are frequently found in Uruguay, France, and the United States. Dissinger and Dissinger Law Firm’s profile aligns with this pattern, being a Business Services organization located in the United States. Other recent Gunra victims with similar profiles include Suárez&Clavera, Cambridge Law Chambers, Cablematic Dos Mil SLU, and Yuditec S.A..

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for dissingerlaw.com in the queried slice. It is important to note that a null result does not confirm the absence of a compromise. The underlying query retrieves a partial, paginated sample, and exposure can go undetected if it occurs under alternate corporate domains, personal email aliases, or if logs were harvested and rotated before indexing. The queried domain did not surface any credentials in this specific data pull, and therefore, no further conclusions can be drawn from this particular result. For ransomware operators like Gunra, credentials harvested by infostealers are a well-documented avenue for initial access. Threat actors or initial access brokers typically source fresh logs from underground marketplaces, validate the corporate credentials within them, and then use these to access systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The absence of specific evidence in this query does not preclude this scenario. Credentials may have appeared in data feeds not covered by this dataset, been used and subsequently rotated before being indexed, or been harvested using personal email aliases. Given these factors, cybersecurity teams should prioritize continued monitoring and proactive credential-hygiene checks. A null query result should not be interpreted as exoneration, and ongoing vigilance is recommended to effectively manage potential risks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.