Sheheen, Hancock & Godwin, LLP.
bd_7ed07e2f90e31e5b · schema v1 · pii pii-v1
Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lynx on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
At Sheheen Hancock & Godwin, LLP, we believe in the value of relationships. We view every client relationship like a partnership, and truly believe that our success is a result of your success. We are committed to providing quality services and attention to our clients at the level that each specifies, from tax preparation and bookkeeping, to business consulting and comprehensive planning. Regardless of the level of service you choose, we take pride in giving you the assurance that the assistance you receive comes from years of advanced training, technical experience and financial acumen. Our continual investment of time and resources in professional continuing education, state-of-the-art technology and extensive business relationships is indicative of our commitment to excellence. Located in Camden, South Carolina, our firm was established in 1959. We have grown from a solo practice into one that is among the largest in the Midlands area.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Apr 7, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Massachusetts State AGbd_065ca86029e465b22025-09-25 · +171dVerified by operator
- Indiana State AGbd_18fa589fd88ecea92025-09-25 · +171dVerified
- Maine State AGbd_2e563cef937ceaad2025-09-25 · +171dCandidate
- New Hampshire State AGbd_7585b35e7f47d53d2025-09-25 · +171dVerified
Show 4 more filings ↓Show fewer ↑up to 177d gap
- Vermont State AGbd_96ab18af330e59db2025-09-25 · +171dVerified
- Montana State AGbd_f5be8a10e36b1ee52025-09-25 · +171dVerified
- Texas State AGbd_b7dc5f072dbb64712025-09-26 · +172dVerified
- South Carolina State AGbd_f6201484cb0798032025-10-01 · +177dVerified
Filing propagation · 9 filings · 8 states
View merged incident ↗Pattern: first filing Apr 7, last Oct 1 (SC) — a 177-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
lynx
According to ransomware.live, Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.