A ransomware group known as SilentRansomGroup has claimed it breached law firm Cozen O’Connor and accessed internal files. Cozen O’Connor has not publicly confirmed the incident or specified what data was involved. Potentially affected clients or employees should monitor credit reports, watch for phishing attempts, and consider a credit freeze as a precaution.
| Company | Cozen O’Connor |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Client Names and Contact Details, Case Files and Legal Correspondence, Financial Information, Social Security Numbers, Employee Personnel Records, Confidential Business Documents |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Cozen O’Connor Data Breach?
A ransomware group calling itself SilentRansomGroup has claimed it breached the network of Cozen O’Connor, a Philadelphia-based law firm. The group posted its claim on a dark web leak site, stating it accessed internal files. As of now, Cozen O’Connor has not publicly confirmed this incident or verified the claims made by the attackers.
Because this is an unconfirmed claim, the exact timeline of the alleged intrusion remains unclear. Ransomware groups often claim access to a network long after the actual intrusion occurred. Therefore, the breach discovery date has not been publicly disclosed. The notification of this claim became public in September 2026.
At this stage, there is no publicly available forensic report describing how SilentRansomGroup allegedly gained access. In addition, the firm has not released a statement detailing an internal investigation. As a result, readers should treat details about attack vectors or timelines as unverified until Cozen O’Connor issues an official response.
Law firms are frequent targets for ransomware groups because they store highly sensitive client information. This makes any claim involving a firm like Cozen O’Connor worth taking seriously, even while confirmation is pending. Affected individuals should watch for official updates as this situation develops.
Who was affected?
Because Cozen O’Connor has not confirmed this incident, the full scope of who may be affected remains unknown. Law firms typically hold data belonging to clients, employees, and sometimes opposing parties in litigation. This means any of these groups could potentially be included if the claim proves accurate.
The number of individuals affected has not been publicly disclosed. Cozen O’Connor operates across the United States and internationally, serving clients in litigation, insurance, real estate, labor, and corporate matters. Consequently, the potential population impacted could span a wide range of industries and geographic locations.
It is also unclear whether employee records were included in what the attackers claim to have accessed. Because law firms often retain sensitive records for years, even former clients or former employees could theoretically be involved. However, none of this has been verified by the firm itself.
What Information Was Potentially Exposed?
Since Cozen O’Connor has not issued a formal breach notification, the specific data categories involved have not been officially confirmed. However, based on the nature of a full-service law firm’s typical case files, certain categories of information are commonly at risk in incidents like this one.
- Client names and contact details
- Case files and legal correspondence
- Financial information tied to legal matters
- Potentially Social Security numbers within litigation or employment files
- Employee personnel records
- Confidential business or insurance-related documents
If the SilentRansomGroup claim is accurate, the exposure of legal case files could be especially damaging. This is because litigation records often contain sensitive personal details disclosed during discovery. For example, medical histories, financial disputes, or employment conflicts may appear in these files.
In addition, if Social Security numbers or financial account details were part of any stolen files, affected individuals could face a heightened risk of identity theft. Fraudsters often use stolen identity data to open new credit lines or file fraudulent tax returns. As a result, vigilance becomes essential even before official confirmation arrives.
What is the company doing?
Because Cozen O’Connor has not publicly confirmed this incident, there is no confirmed statement describing an internal investigation or remediation steps. The firm has not announced any notification process, credit monitoring offer, or other protective measures tied to this specific claim.
Readers should be cautious about assuming any official response has occurred. Until Cozen O’Connor issues a formal statement, the appropriate next step for concerned individuals is to monitor official communications directly from the firm. This includes any breach notification letters that may be mailed in the future.
If the firm eventually confirms the incident, additional details about remediation efforts and support services would likely follow. In the meantime, affected individuals should not wait for confirmation before taking basic protective steps outlined below.
What Should Affected Individuals Do?
Monitor Your Credit Reports Regularly
Because the scope of this incident remains unconfirmed, it is wise to check your credit reports for any unfamiliar activity. You can request free credit reports from all three major bureaus. Reviewing these reports regularly helps you catch fraudulent accounts early.
If you notice unfamiliar inquiries or accounts, report them immediately. Early detection often limits the damage from identity theft. This is especially important if you have ever been a client, employee, or opposing party connected to Cozen O’Connor’s legal work.
Consider a Fraud Alert or Credit Freeze
If you believe your Social Security number or financial details may have been part of any stolen files, consider placing a fraud alert on your credit file. This makes it harder for identity thieves to open new accounts in your name. A fraud alert is free and lasts for one year.
For stronger protection, you can also request a credit freeze. This restricts access to your credit file entirely until you lift it. Because a freeze offers more robust protection than an alert, many security experts recommend it when sensitive identifiers may be at risk.
Stay Alert to Phishing Attempts
After a ransomware claim like this becomes public, scammers sometimes send phishing emails pretending to be from the affected company. Therefore, be cautious of any unexpected emails referencing this incident. Never click links or provide personal information without verifying the sender.
Instead, if you receive a suspicious message, contact Cozen O’Connor directly using verified contact information from their official website. This helps you avoid falling victim to a secondary scam that piggybacks on breach news. Always verify before you trust.
Keep Records of Any Suspicious Activity
If you notice signs of fraud, keep detailed records of dates, amounts, and communications. This documentation can help you dispute fraudulent charges. It may also become useful if you choose to pursue legal action later.
In addition, consider consulting a data breach attorney for a free case evaluation. An attorney can help you understand your rights and whether you may be eligible for compensation. This step becomes especially valuable once official confirmation of the breach occurs.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
