A ransomware group calling itself Spacebears claims to have targeted Schwartz, Giannini, Lantsberger & Adamson (SGLA), according to a listing posted on the group’s own leak site on September 4, 2026. This claim is entirely unverified — SGLA has not confirmed any breach, and no regulator has issued any statement on the matter. The listing was identified and is being tracked by ransomware.live, a security research platform that monitors public leak sites operated by ransomware groups.
What we know — and don’t
- A group calling itself Spacebears posted a claim referencing SGLA on its leak site, dated September 4, 2026.
- SGLA appears to operate in the legal sector, based on its name and available public information; the firm itself has not commented publicly.
- The specific types of data the group claims to have obtained — such as client files, financial records, or personal information — have not been disclosed in the listing and have not been independently confirmed.
- No official confirmation of an incident has been issued by SGLA, and there is no indication yet that the claim has been reported to any regulatory body.
- Claims made on ransomware leak sites are statements by the criminal group itself and are not independent proof that a breach occurred or that any particular data was accessed.
What should you do if you have an account with this company?
- Change your password for any account associated with SGLA, and avoid reusing that password elsewhere.
- Enable two-factor authentication (2FA) wherever it is offered, especially for email and any client portals.
- Be alert to phishing attempts — messages claiming to be from SGLA or referencing this incident that ask for personal details, login credentials, or payment should be treated with suspicion.
- Monitor your financial statements and any correspondence for unusual activity, particularly if you have shared sensitive documents with the firm.
- Consider using a service like a service like Aura or LifeLock for ongoing identity monitoring, which can help flag suspicious use of your personal information even before a breach is officially confirmed.
- Keep records of any suspicious communications in case they are needed later for reporting or verification purposes.
BreachLetter will update this page if Schwartz, Giannini, Lantsberger & Adamson confirms this incident, issues a statement, or if the matter is officially reported to data protection regulators.