Federis Abogados Data Breach

Alleged

Ransomware claim involving Federis Abogados

Published: Aug 24, 2026 Booba Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Federis Abogados
Industry
Business Services
Threat Actor
Booba Project
Date of Incident
Aug 24, 2026

Executive Summary

Federis Abogados, a law firm based in Mexico and operating under federisabogados[.]com, was listed on the Booba Project ransomware group’s leak site on August 24, 2026. The targeting of a Mexican legal firm aligns with Booba Project’s demonstrated interest in professional services organizations within Latin American markets, with Mexico being one of their most frequently targeted countries. In the 60 days preceding this listing, Booba Project claimed 10 victims across the Business Services, Professional Services, and Technology sectors. Their primary geographic targets have been the United States, Russia, and Mexico. The group frequently targets law firms and professional advisory companies across various jurisdictions, with previous victims in similar professional services sectors including Chernyy & Associates, Country-Wide Insurance, Davroc, and Betz Industries, indicating a consistent pattern of targeting for this segment.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry did not yield any records for the domain federisabogados[.]com within the queried dataset. It is important to note that this dataset represents a paginated sample and may not encompass all active log feeds, alternate corporate domains, or credentials harvested using personal email aliases. Mexican professional services firms, like Federis Abogados, may utilize multiple brand or practice-area domains that would not be captured by this specific query. The operational methodology of Booba Project involves sourcing infostealer logs from underground markets, validating corporate credentials, and subsequently authenticating against platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Mexican law firms, particularly those involved in cross-border transactions, often maintain international-facing systems alongside Spanish-language client portals. Consequently, any external-facing endpoint that utilizes credentials becomes a potential part of the attack surface. Credential screening should therefore extend beyond the primary corporate domain to include any affiliated practice-area or client portal domains.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.