On February 17, 2026, Michigan-based law firm Plunkett Cooney appeared on the leak site of the ransomware group SilentRansomGroup. The firm, founded in 1913 and headquartered in Bloomfield Hills, confirmed that internal files had been exfiltrated during a ransomware incident. While the exact number of people whose information may have been exposed remains unknown, anyone whose legal matters, financial records, or personal documents passed through the firm in recent years could be affected.
Watch Plunkett Cooney
Get alerted the next time Plunkett Cooney files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Plunkett Cooney’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that SilentRansomGroup added Plunkett Cooney to its data-leak site and began publishing samples of stolen material. The firm has not released a detailed breach notification, but available information confirms internal files were allegedly exfiltrated. No precise count of affected records or individuals has been disclosed. The incident follows the group’s typical pattern of stealing data before encrypting systems and then threatening to publish it unless a ransom is paid.
Why This Matters for You and Your Family
When a law firm’s internal files are stolen, the information often includes names, addresses, dates of birth, Social Security numbers, financial details, court filings, and correspondence that can reveal sensitive family matters. If your estate planning, divorce, personal injury claim, or business transaction was handled by Plunkett Cooney, pieces of your life may now sit in an attacker’s archive. Once data leaves a secure environment, it can be sold, traded, or used to target you months or years later. Ordinary families rarely learn about these incidents until fraudulent accounts or unexpected collection calls appear.
The Doxxing and Identity-Chain Implications
Legal documents frequently link multiple pieces of identifying information: email addresses, phone numbers, home addresses, family member names, and sometimes children’s dates of birth. Attackers chain these fragments together with data from earlier breaches to build complete profiles. A single leaked email can lead to gaming accounts, school portals, or social-media profiles. Credential leaks like this one regularly cascade into account takeovers because people reuse passwords across work, personal, and family services. The result is not just identity theft but sustained harassment through doxxing.