SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA
bd_2c3f180fd91449d7 · schema v1 · pii pii-v2
Full breach record for SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Deadlock on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Family law firm, established 1995 by Victor A. Shaheen (†2025 - the General Assembly of Virginia honored him with a resolution; google it, it is touching). Now run by his three sons. 48 employees across four offices: Richmond, Midlothian, Virginia Beach, Newport News. What do they do? They close 150+ real estate transactions EVERY MONTH for some of the largest corporate relocation programs in America. When a Fortune-500 moves an employee to Virginia, this firm holds that employee's Social Security Number, bank wiring details, home address, family identities, and sometimes their medical clearance. They hold everyone's future in a shared folder. We now hold the folder. WHAT WE TOOK 36,788 files · 27GB · 21,789 fully read 67,000+ SSN patterns (their own dedup says 6,017 real people — we will let their customers decide which number to believe) EVIDENCE — SERIES PREVIEW (from their actual files) - S1 DEEDS WITH SOCIAL SECURITY NUMBERS File: "5053815 - Unsigned Deed.docx" (verbatim from their server): "***-**-XXXX B•••• H••• Social Security Number ***-**-XXXX J••••• H••• Social Security Number 10356 Ashburn Road, North Chesterfield, VA 23235" File: "Kelley 5042085 - DEED.docx": "PURCHASER(S): N••••• S••• SELLER'S NAME: S••• E. K•••• SS#: ***-**-XXXX ...including the withholding of twenty percent (20%) of the sales proceeds." ← FIRPTA: foreign sellers. IRS will want this list. We have it. Thousands of these. Every deed folder = a name, a number, an address, a transaction. Their client roster IS the leak. - S3 INSIDE THEIR BANKING & THEIR NETWORK File: "shared_Accounting/Banking/Other Banking/Shaheen DDA Statements SunTrust DDA" (email from SunTrustOnlineCourier to their own staff — headers verbatim): Received: from barracuda.shaheenlaw.com ([10.0.0.6]) by ricdcex1.shaheenlaw.com ... X-ASG-Debug-ID: 1291233029-... for ; Wed, 1 Dec 2010 Why we publish an email HEADER: their in
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Aug 24, 2026
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.