CSIDB logo
Incident

Fabrega Molino Abogados

Incident posture

Attack window
Mar 2023
Location
Panama
Status
Historical
CIA posture
Available to members
Updated
2026-08-28 14:53

Linked entities

Victim
Fabrega Molino Abogados
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Panamanian law firm was compromised by the BlackCat ransomware group, resulting in the exfiltration and leak of 113GB of sensitive data containing personal information such as passports and wills. The firm acknowledged an isolated cybersecurity incident, stating it was promptly contained and that additional security measures were implemented following expert recommendations, but did not confirm whether customer data was stolen or provide details about affected individuals. No evidence of victim notifications or offered mitigation services was disclosed, and the attackers did not clarify whether the operation involved encryption or solely data theft.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The Fabrega Molino incident involved a cyberattack on the Panamanian law firm culminating in the public leak of its data by the BlackCat ransomware group on or around March 18, 2023. BlackCat claimed to have exfiltrated 113 gigabytes of the firm’s data and published it on their leak site. While the group did not specify whether they deployed ransomware to encrypt systems or solely extracted data, the leak included sensitive personal documents such as passports and a will, indicating potential privacy impacts for affected individuals. Fabrega Molino acknowledged a security incident in a website statement but provided limited technical or operational details, characterizing it as an "isolated" event detected on an unspecified network segment. The firm asserted their cybersecurity experts "contained and resolved" the incident immediately but did not disclose the initial attack vector, duration of unauthorized access, or specific data types compromised beyond general references to computer equipment security enhancements.

Fabrega Molino’s public response lacked confirmation of data theft or acknowledgment of BlackCat’s claims, despite the threat actor publishing identifiable personal documents as proof of compromise. The firm did not address whether it notified individuals whose personal information appeared in the leak, nor did it reference plans to offer identity monitoring or other mitigation services to impacted parties. Independent verification attempts by DataBreaches.net yielded no additional information from either Fabrega Molino or BlackCat regarding the scope of exfiltrated client data. The confirmed presence of passports and a will within the leaked data introduced risks of identity theft, fraud, and exposure of confidential client legal matters. Limited transparency from the firm left critical questions about attack chronology, data integrity, and remediation effectiveness unresolved as of the last reported outreach on March 24, 2023.

Sources

Sources available to members: 1 source.

CSIDB