Files that appear to have been stolen from the California Supreme Court in Sonoma County are for sale on the ransomware gang "Meow."

The group claims to have stolen approximately 5GB of sensitive files, including legal documents that offer valuable insights into the functioning of the court.
See related: US agency warns about Trinity Ransomware
“Dear customers! We are offering you exclusive access to over 5GB of confidential data from the Superior Court of California, Sonoma County, dealing with civil, criminal, family and juvenile cases,” the group wrote on its dark leak site. “These files may be of interest to legal, regulatory and other interested parties.”
The Sonoma County Superior Court is one of 58 superior courts in California, serving nearly half a million residents. According to the Russian gang, the full data package includes employee information, client information, personal data (such as dates of birth and social security numbers), agreements and certificates, addresses, and banking information.
The group is offering the 5GB package for $20,000, but is willing to sell the stolen memory to multiple buyers for $10,000 each. The samples Cybernews saw included various court and criminal documents, such as marriage certificates, court filings, bail collection reports, and signed warrants.
Read more: Casio reports IT systems failure after cyberattack
Some documents date back to November 2013, while others date back to September 20, 2024. Other documents include invoices from third-party suppliers and employee payroll data.
Who is the “Meow” gang?
Meow ransomware was first observed by security researchers in August 2022, but the group appears to have disappeared in February 2023 and resurfaced in September. Also known as MeowCorp or MeowCorp2022, its threats are often characterized as anti-Russian extortion.
As of December 2023, the group had only about 10 victims in its dark web, including Memorial Sloan Kettering Cancer Center in New York. According to Cybernews’ Ransomlooker tool, by September of this year, the group had increased its victims to at least 90, up from 38 in August alone, demanding between $20,000 and $40,000 per victim.
See more: American Water shuts down online services after cyberattack
It is believed to have created the NB65 ransomware, a modified version of the Russia-linked Conti v2 variant, according to WatchGuard. This variant was apparently leaked by a Ukrainian hacker in retaliation for the group's public support for Russia following its invasion of Ukraine in 2022.

The ransomware uses the “.MEOW” file extension, with notes containing four email addresses and two Telegram for communicating with victims, titled “readme.txt”.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“MEOW! MEOW! MEOW! Your files have been encrypted! Do you need decryption? Write to the e-mail:…”, the note reads, followed by the gang’s contact details.
Read more: MoneyGram: Cyberattack led to data breach
Meow ransomware also shares similar characteristics with Conti v2, using a combination of ChaCha20 and RSA-4096 to encrypt files. Other strains derived from the Conti variant include the Putin Group, ScareCrow, and BlueSky.
Source: cybernews
