Cullotta Bravo Law Group, an Aurora, Illinois personal injury firm, experienced a ransomware attack claimed by the INC Ransom group. The breach may have exposed client Social Security numbers, medical records, and case files. The exact number of affected individuals has not been publicly disclosed. Affected individuals should monitor credit reports and consider a credit freeze immediately.
| Company | Cullotta Bravo Law Group |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Full Names and Contact Information, Social Security Numbers, Medical Records and Treatment History, Insurance Information, Case Files, Financial Account Details |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Cullotta Bravo Law Group Data Breach?
Cullotta Bravo Law Group, a personal injury firm based in Aurora, Illinois, has confirmed a ransomware attack on its network. A group known as INC Ransom has claimed responsibility for the intrusion. This group is known for stealing files before locking systems, then threatening to leak the data unless paid.
The firm has handled personal injury, nursing home abuse, and workers’ compensation cases for more than 35 years. Because of this, its systems likely held years of sensitive client files. As a result, the potential scope of exposed records could be significant, even though exact details remain limited.
The exact date the intrusion began has not been publicly disclosed. However, the firm issued notification about the incident in September 2026. Following discovery, the firm reportedly began an internal review to determine what happened and which systems were affected.
At this stage, forensic investigators are still working to confirm the full extent of the breach. In addition, the firm has not released a complete technical timeline of the attack. This kind of investigation typically takes weeks or months to fully resolve, especially when threat actors claim to have exfiltrated files.
Who was affected?
The individuals affected likely include current and former clients of Cullotta Bravo Law Group. Because the firm handles personal injury and workers’ compensation cases, this may include people who suffered serious injuries or medical harm. Nursing home abuse victims, a particularly vulnerable population, may also be among those affected.
The exact number of affected individuals has not been publicly disclosed. Given the firm’s decades of practice, however, the pool of past and current clients could be substantial. In addition, employees of the firm may also have had personal data stored on the compromised systems.
Because personal injury cases often involve medical treatment and long legal proceedings, affected individuals may span a wide range of ages. This could include elderly nursing home residents and their families. Meanwhile, the geographic scope appears centered on Illinois, given the firm’s Aurora location, though clients from other areas cannot be ruled out.
What Information Was Potentially Exposed?
Details about the specific categories of data stolen in this incident remain limited. However, based on the nature of a personal injury law practice, certain types of sensitive information are commonly stored in client case files. This makes the following categories reasonably likely to have been affected.
- Full names and contact information
- Social Security numbers
- Medical records and treatment history
- Insurance information
- Case files related to legal claims
- Financial account details tied to settlements
If Social Security numbers were indeed exposed, affected individuals face a heightened risk of identity theft. Criminals could use this information to open new credit accounts or file fraudulent tax returns. In addition, stolen medical records could be used for medical identity theft, where someone else obtains treatment under a victim’s name.
Because personal injury cases often include financial settlement details, exposed banking or account information could lead to direct financial fraud. Furthermore, combining medical history with personal identifiers creates a more complete profile for scammers. This makes phishing attempts more convincing and harder to detect, since fraudsters can reference real case details to appear legitimate.
What is the company doing?
Cullotta Bravo Law Group has acknowledged the ransomware incident and began investigating the intrusion after it was discovered. The firm is reportedly working to determine which systems and files were accessed. As is standard practice, the firm is likely coordinating with cybersecurity specialists to contain the threat and assess the damage.
Notification to affected individuals occurred in September 2026, according to confirmed reporting. Going forward, the firm may offer credit monitoring or identity protection services to those impacted, though specific offerings have not been publicly detailed. In addition, firms responding to ransomware incidents typically strengthen network security and access controls following an attack like this one.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should request free copies of their credit reports from all three major bureaus. Regularly checking these reports can help catch new accounts or inquiries opened without permission. Because identity thieves often act quickly after a breach, early detection matters.
You can access free credit reports through AnnualCreditReport.com. Reviewing these reports every few months for the next year is a reasonable precaution. If anything looks unfamiliar, dispute it with the bureau immediately.
Consider a Credit Freeze or Fraud Alert
Given the possible exposure of Social Security numbers, placing a credit freeze is a strong protective step. A freeze blocks new creditors from accessing your credit file, which makes it much harder for thieves to open accounts in your name. This is one of the most effective tools available to consumers.
Alternatively, a fraud alert requires lenders to verify your identity before extending credit. This option is less restrictive than a freeze but still adds a layer of protection. Either option can be requested directly through Equifax, Experian, or TransUnion.
Watch for Medical Identity Theft
Because medical records may have been exposed, affected individuals should review any insurance statements and medical bills carefully. Unfamiliar charges or services could indicate someone else used your identity to receive care. This type of fraud can also corrupt your own medical records with inaccurate information.
If you notice suspicious medical activity, contact your health insurance provider right away. In addition, request an accounting of disclosures from healthcare providers if something seems off. Catching this early can prevent complications with future medical treatment or insurance coverage.
Stay Alert for Phishing Attempts
Following a breach like this, scammers often send emails or texts pretending to be from the affected company. These messages may ask you to click links or verify personal information. Because attackers may already have real case details, these messages can look highly convincing.
Never click links or share personal information in response to unsolicited messages. Instead, contact the law firm directly using verified contact information if you have concerns. Reporting suspicious messages to the Federal Trade Commission can also help track broader phishing campaigns tied to this incident.
Consult a Data Breach Attorney
Given the sensitive nature of the exposed data, affected individuals may want to speak with an attorney who focuses on data breach cases. Many offer free consultations to review your specific situation. This can help you understand whether you qualify for compensation.
Because personal injury clients often have unique privacy concerns, legal guidance can be especially valuable here. An attorney can help you evaluate potential claims and monitor developments in any related legal action. Acting sooner rather than later can help preserve your options.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
