Ransomware Group rhysida Hits: Law Offices of R. David Williams, P.A.
Summary
In the latest cybersecurity news, Law Offices of R. David Williams, P.A. — an organization based in US — has fallen victim to a ransomware attack conducted by the group rhysida. This data breach, discovered on 2026-09-30T10:10:55.394139+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | Law Offices of R. David Williams, P.A. |
| Threat Group | rhysida |
| Summary | Law Offices of R. David Williams, P.A. Contents. A complete dossier of the firm’s criminal defense practice covering ~175+ clients: felonies (an undercover sex sting involving a minor – Ramirez; domestic violence robbery – Valderrama, involving a 4-year-old child; felony DUI – Segula; fraud – B. Williams), a core caseload of ~10 DUI matters (including an arrest at breath readings of 0.011 and SCRAM alcohol monitoring), violations of probation (VOP), FDLE expungement packets with FD-258 fingerprint cards, a ‘red flag’ Risk Protection Order (RPO), 2 clients in ICE custody, and a material witness under GPS monitoring for 3+ years. Attorney fees range from $750 to $25,000. The case files include complete police discovery: ~206 GB of bodycam video, 911 recordings, and jail calls, incident reports, photo line-ups, FCIC/NCIC forms, and victim and witness data (Marsy’s Law). More |
| Date of Breach | 2026-09-30T10:10:40.492936+00:00 |
| Discovery Date | 2026-09-30T10:10:55.394139+00:00 |
| Region | US |
| Business Sector | Professional Services |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- security awareness training — close the gap attackers exploit.
- dark web monitoring — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
