Oasis Legal Group Data Breach

Alleged

Everest Ransomware Claim Involving Oasis Legal Group

Published: Aug 5, 2026 Everest
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Oasis Legal Group
Industry
Legal Services
Threat Actor
Everest
Date of Incident
Aug 5, 2026

Executive Summary

Oasis Legal Group, a professional services firm operating within the United States, has been identified as a victim on the dark web portal of the Everest ransomware group. This listing was published on August 5, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. As a firm in the legal services sector, any potential compromise poses a significant governance challenge due to strict client confidentiality requirements. Professional services represent the second most frequently targeted industry by Everest in their recent activity, indicating a strategic focus on this sector. Within the 60 days preceding this listing, Everest has claimed a total of 18 other victims. The group consistently targets the technology, professional services, and energy and utilities sectors, with a significant concentration of victims in the United States, India, and the United Arab Emirates. Several other organizations, including Aptara, Keysight, Mansfield Family Dentistry, and Conway Analytics, have also been recently listed by Everest, sharing either a sector (professional services) or geographic overlap (US organizations) with Oasis Legal Group. This aligns Oasis Legal Group with the ransomware group’s typical targeting patterns.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a notable credential exposure linked to the oasislg.com domain. The query returned three records indicating exfiltrated corporate employee credentials, captured during authentication to a cloud identity provider. These logs date back to late 2025. Although the volume of records is low, each identified credential belongs to a corporate employee, without apparent dilution from customer or third-party data. For a firm of Oasis Legal Group’s size, even a small number of compromised corporate credentials can represent a significant portion of their user base, making the observed exposure a matter of high severity. The observed pattern of credential exposure through infostealer logs is a well-documented initial access vector used by ransomware groups like Everest. Threat actors or initial access brokers commonly source these logs from underground marketplaces. After validating the credentials, they are used to gain unauthorized access to systems such as Microsoft 365, VPNs, or other remote access portals, ultimately serving as a precursor to ransomware deployment. While this telemetry data does not definitively confirm that Everest utilized these specific credentials for an intrusion into Oasis Legal Group, the observed activity is consistent with the typical intrusion kill chain associated with such attacks. Given the nature of the exposed corporate identities, CTI teams monitoring this threat should consider these credentials a standing risk. Prioritizing proactive measures such as credential rotation and session invalidation is recommended over relying solely on point-in-time assessments. Continued dark web monitoring for any further listings or related activity is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.