On December 11, 2025, the Indiana-based law firm Woodard, Emhardt, Henry, Reeves & Wagner, LLP appeared on the public leak site of the Rhysida ransomware group. The listing indicates that internal files were exfiltrated during a ransomware attack on the firm’s systems. While the exact number of people whose information may have been exposed remains unknown, anyone whose legal, financial, or personal records passed through the firm in recent years could be affected.
Watch Woodard
Get alerted the next time Woodard files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Woodard’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the firm’s data first surfaced on the Rhysida leak portal on December 11, 2025. The posted notice states that internal files were taken during a ransomware incident. No sample documents have been publicly examined, and the precise volume or sensitivity of the material has not been independently verified. Available reporting describes the firm as a longstanding intellectual-property and litigation practice whose clients include individuals, families, and businesses whose case files often contain Social Security numbers, financial details, medical information, and family records.
Why This Matters for You and Your Family
When a law firm’s internal systems are breached, the information exposed is rarely limited to corporate contracts. Client files frequently hold copies of driver’s licenses, tax returns, bank statements, medical histories, and correspondence that can be used to open accounts, file fraudulent taxes, or impersonate family members. If your family has worked with this firm—or with any client of this firm—your data may now sit in an attacker’s archive. Once exfiltrated, stolen records do not expire; they can be sold, traded, or held for years until they become useful for identity theft or targeted fraud.
The Doxxing and Identity-Chain Implications
Legal documents often link names, addresses, phone numbers, email accounts, and sometimes children’s information in a single file. Attackers can chain these details with username leaks from gaming platforms, social-media handles, or older breaches to build a complete profile. A single exposed email or phone number can lead to account takeover attempts on personal email, banking apps, or your child’s Roblox, Fortnite, or Minecraft account. Credential leaks like this one routinely cascade into doxxing chains that connect your real identity to every online handle tied to the same household.