Studio Legale Grande Stevens
| Primary URL | Location | Industry | www[.]grandiestevens[.]it |
Country
Italy
|
Commercial
|
|---|
Profile
Grande Stevens Law Firm, also referred to as Studio Legale Grande Stevens, is an Italian legal practice with its headquarters located in Italy. The firm concentrates its practice on commercial and corporate law, offering advisory services to companies engaged in a variety of business activities. It is identified in open sources as the law firm associated with the Agnelli family, one of Italy’s most prominent industrial dynasties. The firm’s lawyers provide guidance on corporate governance, regulatory compliance, and the drafting and negotiation of complex contracts. By concentrating on a specialised niche, the firm aims to deliver tailored legal solutions that address the specific needs of corporate clients. Its reputation is built on a combination of legal expertise and experience advising Italian businesses. The firm serves domestic clients that require assistance navigating Italian corporate law.
On 29 August 2022, Grande Stevens Law Firm became the target of a ransomware operation conducted by the BlackByte cyber criminal group. BlackByte is known for employing a double‑extortion model, in which it encrypts victims’ data while also exfiltrating sensitive information for leverage. In this incident, the attackers succeeded in encrypting the firm’s internal systems and extracting a range of confidential files, including legal case records, technical consultancy documents, and employee directory listings. To demonstrate the breach, BlackByte published samples of the stolen material on its public leak site, showcasing the nature and volume of the data obtained. The ransom note issued by the gang demanded a payment of $160,000 for the promise to delete the exfiltrated data and an alternative demand of $210,000 for an exclusive purchase of the information. The attackers warned that failure to meet either demand would result in the public release or underground distribution of the compromised data. The attack disrupted the firm’s day‑to‑day operations, impeded access to critical case files, and raised concerns about the confidentiality of client information. The episode highlighted deficiencies in the firm’s cybersecurity posture and served as a reminder of the growing threat posed by ransomware groups to professional services organisations.
