Grubman Shire Meiselas & Sacks, a law firm that specializes in dealing with A-listed starts, was hacked by REvil ransomware. The law firm confirmed the hack and BBC reported that there are notable names on the list.

A snapshot of stolen files from ransomware authors show names like Lady Gaga, Madonna, Drake, etc. The total information was mounted to 756GB, containing contracts and contact information of those celebrities.

REvil Ransomware Hacked a Law Firm That Serves Drake, Lady Gaga, Madonna, etc
REvil Ransomware Hacked a Law Firm That Serves Drake, Lady Gaga, Madonna, etc

The Same Infamous Group Again

REvil or Sodinokibi group has just recently evolved with a new version to steal even more data using Windows Restart Manager API and was responsible for many famous hacks like Travelex, GEDIA, Har Shalom, Artech information systems, etc. They are following the recent trend in ransomware groups, like stealing data before encrypting the files. And if the proposed ransom isn’t paid, threatens to leak the data.

This ransomware group has now caught a top law firm based in New York and posted an image of the stolen data as proof. Emsisoft, a cybersecurity firm that has seen the image says the contract for Madonna’s World Tour 2019-20 with signatures from concert company Live Nation and an employee was found. Further, there’s an image showing all the client folders too.

Source: Emsisoft
Source: Emsisoft

Victimized Celebrities

Popular names include Barry Manilow, Lil Nas X, Madonna, Sir Elton John, Barbra Streisand, Lady Gaga, Priyanka Chopra, The Weeknd, Rod Stewart, U2, Drake, Mike Tyson, LeBron James, Robert De Niro and even companies like Activision and Sony were in the list. It’s unclear how much ransom demanded by the hacker group, and what Grubman Shire Meiselas & Sacks is planning to do.

As of now, they’ve told in a press release that, says they’ve hired world-class experts to address this issue, and have informed all their customers and staff about this incident.


Please enter your comment!
Please enter your name here