Quick Summary
AllegedExecutive Summary
On September 29, 2026, m3rx ransomware listed Otero Geeza Law, P.A., a US-based law firm, on its dark web portal. SOCRadar’s Dark Web Monitoring service detected this listing. Law firms are frequently targeted by ransomware groups due to the sensitive nature of their data, including client case files, privileged communications, and financial records, making them attractive targets regardless of the firm’s size. In the 60 days preceding this listing, m3rx claimed 7 other victims, primarily in the Professional Services, Technology, and Retail & E-Commerce sectors. These victims were located in the United States, Brazil, and Canada. Notable recent victims include Interconnect Computer Cabling Services Inc., CPACB, Soma Soluções em T.I., and Cipher Systems. The targeting pattern suggests a consistent focus on professional services and related industries across North and South America.
Technical Analysis
SOCRadar’s stealer-log query, which targeted the domain oterolaw[.]com, returned no results. However, this absence of data does not confirm that the organization is unaffected by a compromise. The query represents a paginated snapshot of telemetry, and it is possible that credentials may exist in other data feeds not included in the sample, or they might be associated with personal email accounts of attorneys and staff rather than the corporate domain. Smaller professional services firms frequently utilize personal email addresses for some work-related functions, creating potential gaps that domain-specific queries cannot always identify. The m3rx ransomware group typically follows a strategy of acquiring credentials through stealer logs, which are then used to gain access to Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The finding of no positive credential matches does not negate the exposure risk indicated by the listing on the ransomware group’s portal. Organizations are advised to conduct a thorough credential hygiene review across all staff accounts, including personal email addresses used for professional purposes, and to maintain continuous monitoring for any new credential exposures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.