On June 12, 2026, the website of Mogren, Glessner & Ahrens, a King County law firm handling family law, divorce, probate, wills, criminal defense, personal injury, and adoption cases, appeared on the leak site of the threeam ransomware group. Internal files were allegedly exfiltrated during a ransomware attack, placing sensitive client and employee information at risk of public release.
Watch mgrlaw.com
Get alerted the next time mgrlaw.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about mgrlaw.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the firm, established in 1942, had internal documents stolen. The exact number of people affected remains unknown. Available details confirm the data includes records tied to the firm’s core practice areas, which routinely contain names, addresses, financial details, Social Security numbers, medical information, and court filings for thousands of families across Washington state. The threeam leak site listed mgrlaw.com on June 12, 2026, following the exfiltration phase of their ransomware operation.
Why This Matters for You and Your Family
Family law and divorce records often hold the most private details about your household—custody arrangements, financial disclosures, addresses of children, and previous names. When a firm like Mogren, Glessner & Ahrens is breached, that information can spread far beyond the original case. Criminal defense files may expose past charges or ongoing matters. Probate and will documents can reveal inheritance details and family financial structures. Personal injury records frequently include medical histories and insurance data. Any of these can be used for identity theft, targeted scams, or harassment. If you or your family ever worked with this firm or similar local practices, your information could already be in the hands of criminals.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one dataset. Criminals combine the newly exposed files with information from previous breaches to build detailed profiles. A single email or phone number found in these internal files can link to your social media, children’s school records, or gaming accounts. Once connected, attackers can impersonate family members, file fraudulent tax returns, or launch doxxing campaigns that publish home addresses and personal histories. Credential leaks of this type frequently cascade into account takeovers, especially for gaming platforms where children often reuse passwords or email addresses tied to family domains.