Skip to content
Ransomware News

Ransomware Group Deadlock Hits: SHAHEEN LAW GROUP PLC – Richmond, Virginia, USA

Admin
HookPhish team
Target organization SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA slgjustice.com Professional Services

Summary

In the latest cybersecurity news, SHAHEEN LAW GROUP PLC – Richmond, Virginia, USA — an organization based in US — has fallen victim to a ransomware attack conducted by the group Deadlock. This data breach, discovered on 2026-08-24T21:21:27.834915+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization SHAHEEN LAW GROUP PLC – Richmond, Virginia, USA
Threat Group Deadlock
Summary Family law firm, established 1995 by Victor A. Shaheen (†2025 – the General Assembly of Virginia honored him with a resolution; google it, it is touching). Now run by his three sons. 48 employees across four offices: Richmond, Midlothian, Virginia Beach, Newport News. What do they do? They close 150+ real estate transactions EVERY MONTH for some of the largest corporate relocation programs in America. When a Fortune-500 moves an employee to Virginia, this firm holds that employee’s Social Security Number, bank wiring details, home address, family identities, and sometimes their medical clearance. They hold everyone’s future in a shared folder. We now hold the folder. WHAT WE TOOK 36,788 files · 27GB · 21,789 fully read 67,000+ SSN patterns (their own dedup says 6,017 real people — we will let their customers decide which number to believe) EVIDENCE — SERIES PREVIEW (from their actual files) – S1 DEEDS WITH SOCIAL SECURITY NUMBERS File: “5053815 – Unsigned Deed.docx” (verbatim from their server): “***-**-XXXX B•••• H••• Social Security Number ***-**-XXXX J••••• H••• Social Security Number 10356 Ashburn Road, North Chesterfield, VA 23235” File: “Kelley 5042085 – DEED.docx”: “PURCHASER(S): N••••• S••• SELLER’S NAME: S••• E. K•••• SS#: ***-**-XXXX …including the withholding of twenty percent (20%) of the sales proceeds.” ← FIRPTA: foreign sellers. IRS will want this list. We have it. Thousands of these. Every deed folder = a name, a number, an address, a transaction. Their client roster IS the leak. – S3 INSIDE THEIR BANKING & THEIR NETWORK File: “shared_Accounting/Banking/Other Banking/Shaheen DDA Statements SunTrust DDA” (email from SunTrustOnlineCourier to their own staff — headers verbatim): Received: from barracuda.shaheenlaw.com ([10.0.0.6]) by ricdcex1.shaheenlaw.com … X-ASG-Debug-ID: 1291233029-… for ; Wed, 1 Dec 2010 Why we publish an email HEADER: their internal map is in it. Barracuda at 10.0.0.6. Exchange “ricdcex1”. Domain SHAHEENWORLD. We did not forget how to enter. Neither will the next group, when we sell the map. 150 banking statement attachments ride along in this folder. – S5 THE CLIENT LIST, WRITTEN IN FOLDERNAMES They named folders after their customers. Verbatim paths: shared_PENDING_SALE/HENNY/Closed Files/ Wisniewski-Markel, Suzanne_5027384_12263 Eagle … Merza, Jamal & Adrienne_5027826_811 Woodberry … Name, file number, STREET ADDRESS — in the path itself. Marketing lists sell for money. This one is annotated with purchase history. Relocation buyers are premium leads. – S2 MEDICAL – S4 LITIGATION Held. 120 medical files exist (their own audit counted them). Litigation: we confirm their December escrow dispute is public (Porchlight Homes v. Almeida & Shaheen, Henrico — google it, BizSense covered it). Virginia residents: §18.2-186.6. Illinois relocations: BIPA. Opposing counsel and journalists: samples on request. Media & researchers: samples on request, we answer fast We keep our word to everyone who pays. We keep it also to everyone who does not.
Date of Breach 2026-08-24T21:21:26.480350+00:00
Discovery Date 2026-08-24T21:21:27.834915+00:00
Region US
Target Domain slgjustice.com
Business Sector Professional Services

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions