On October 25, 2024, Egyptian law firm Matouk Bassiouny appeared on the leak site operated by the ransomware group known as raworld. The listing states that internal files were exfiltrated during a ransomware attack on the firm’s systems. The disclosure does not specify the number of records affected, the exact data types beyond “internal files,” or any ransom demand.
Watch Matouk Bassiouny
Get alerted the next time Matouk Bassiouny files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Matouk Bassiouny’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The raworld leak site entry, accessible via the .onion link indexed by ransomware.live, states that Matouk Bassiouny suffered a ransomware incident resulting in data exfiltration. It lists the Cairo-based firm as a victim and indicates that samples or proof of the stolen material have been uploaded. No client list, financial records, or specific document categories are detailed in the public portion of the posting. The notification does not provide a deadline for payment or further information about the initial access vector used by the attackers.
Why This Matters for You and Your Family
When a law firm’s internal files are stolen, the exposure often reaches far beyond the business itself. Clients entrust these firms with names, addresses, identification numbers, financial details, court filings, and sensitive correspondence. If any of that material belongs to you or someone in your household, the breach puts your personal information directly in the hands of criminals. Even if you are not a current client, shared vendors, opposing parties in litigation, or employees of corporate clients can create unexpected overlap. The result is heightened risk of identity theft, targeted phishing, and fraudulent loan applications using data that was supposed to remain protected under attorney-client privilege.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at one dataset. A single leaked email address or phone number from the firm’s files can be combined with information from previous breaches to build a complete profile. Attackers chain these fragments together: an old password from one site, a home address from another, and now privileged legal documents that reveal family structures, assets, or ongoing disputes. This creates persistent doxxing chains that can surface on dark-web forums or extortion marketplaces months or years later. Gaming accounts belonging to children are particularly vulnerable because the same email or password reused for a parent’s legal correspondence often protects those accounts, turning one professional breach into a household compromise.