B2B Compliance Intelligence (Part 2) PHISHDESTROY RESEARCH
Cybersecurity Gdpr Data Breach Privacy Legal Tech

Taylor Wessing GDPR Data Breach: My Dog vs. Elite Lawyers (Part 2) — The 5-Year PDF Vulnerability Exposing Global Corporations

We thought Taylor Wessing made a manual mistake with a GDPR request. We were wrong. It’s an automated, firm-wide catastrophe.

🚨 Key Findings:

The Breach: Elite law firm Taylor Wessing is using an outdated script to “redact” sensitive PDFs, masking data visually but leaving the text fully readable underneath.

The Scale: Evidence suggests this vulnerability has affected their corporate clients (including giants like Pfizer, Just Eat, Chubb, and SAP) since 2019.

The Hypocrisy: While leaking massive amounts of data, their lawyers issue baseless criminal threats to citizens making lawful GDPR requests.

A few days ago, as a spin-off to our massive cybersecurity exposé on How Valve Profits From 70M+ Stolen Steam Accounts, we published an article documenting a catastrophic legal blunder.

We revealed how the elite, high-priced lawyers at Taylor Wessing (specifically Dr. Patrick Zurheide and Dr. Tobias Schelinski) accidentally leaked 830 pages of highly sensitive, de-anonymized Steam user data while trying to defend Valve Corporation against a routine GDPR request.

We joked that my dog, having precisely zero data breaches on her resume, was officially better at data protection than a Salary Partner with a PhD in IT Law.

My dog is now winning 2–0.

EXHIBIT 1.0: CHIEF DATA PROTECTION OFFICER AUDIT (PART 2) SCORE: DOG 2 — 0 LAWYERS
Dr. Patrick Zurheide Taylor Wessing GDPR PDF Leak Dog Officer

Meet our Chief Data Protection Officer. 0 data breaches. 100% better at using PDFs than Taylor Wessing.

After publishing the first piece, we had a long, hard think. We looked at those 830 pages of black rectangles. We realized something fundamental about corporate lawyers: they are generally too self-important to manually draw black boxes on 800+ pages. Doing that by hand would give you a severe case of digital hemorrhoids.

No, they didn’t do it manually. They used a script. And that’s when the joke stopped being funny, and became a systemic, global cybersecurity crisis.

The Cheap Software Behind the Elite Facade

Here is the technical reality of what these lawyers — who think they are richer, smarter, and more important than Valve’s own users — actually did.

To save money on proper, enterprise-grade data sanitization software, their systems rely on a generic, outdated library: Aspose.PDF for .NET 20.8.

The core issue is that their script uses this outdated software to draw black vector rectangles (using re/f operators in the PDF code) over text coordinates. What it should be doing is properly sanitizing and deleting the underlying text layer (using BT/ET operators).

It creates a visual mask on your screen. But the raw data? It remains 100% accessible beneath it.

// The Math on the Scale of this Catastrophe:

Dr. Patrick Zurheide alone likely processes roughly 100 to 300 GDPR requests a year. For the few users who don’t immediately surrender to his initial wave of legal threats and delays, he eventually sends them the “brilliance of his experience” — a legal response document that consists of 94% black rectangles.

But this is not Malevich’s “Black Square”. It is just a cheap vector shape. Remove it.

EXHIBIT 2.0: ASPOSE.PDF METADATA SMOKING GUN 36 SECONDS PROCESSING TIME
Dr. Tobias Schelinski Taylor Wessing Valve Data Breach Forensic Metadata

Forensic metadata extraction of Taylor Wessing’s 830-page response. The “36 seconds” processing time is the smoking gun: they didn’t redact manually; they used an automated, vulnerable script.

The Blast Radius: Whose Data Did Dr. Patrick Zurheide and Dr. Tobias Schelinski Process?

We didn’t just guess that this was a firm-wide issue. We tested it.

We immediately contacted individuals we knew who had previously received documents processed by Taylor Wessing. They sent us their files. We opened them and looked straight at the meta-tags. What did we find? Exactly what we expected. The exact same vulnerability. The exact same flawed redaction script.

Did we read the contents of their hidden documents? No. We absolutely refused to look at the underlying data. We simply checked the metadata, confirmed the vulnerability, and handed the owners the instructions on how to reveal the hidden text themselves.

But let’s scale this up. This vulnerability has likely been present in hidden documents processed by Taylor Wessing since 2019. Now, think about the corporate giants they defend.

Taylor Wessing proudly advertises its Data Protection and Cyber Security work for massive global corporations. Based on their own public client lists and our forensic findings, we have to ask a terrifying question regarding the data they have processed over the last five years:

  • What about the millions of gamers in the Valve Corporation (Steam) ecosystem?
  • What about the global Taylor Wessing GDPR compliance documents of Just Eat?
  • What about the European data transfers for tech giants like Vinted and SAP?
  • What about the sensitive incident reports for Chubb Insurance (where Taylor Wessing ironically boasts about sitting on their “Cyber Incident Response Team”)?
  • And what about the highly confidential clinical data handled by Pfizer and their other Life Sciences clients?

If Taylor Wessing used this same cheap script to “redact” documents for these corporations, then they didn’t hide anything. They intentionally disclosed it.

The Difference Between Us: A Message to Taylor Wessing

Let’s address Taylor Wessing directly. What is the fundamental difference between your actions and ours?

You, Dr. Patrick Zurheide and Dr. Tobias Schelinski, are utterly arrogant. You threaten your clients and opponents with criminal code articles. You act like God. You arbitrarily hand out permanent account bans simply because a user’s burner email address doesn’t explicitly contain their real name. You act as the judge, the jury, and the executioner.

We do not blackmail. We do not suffer from a God complex. And we don’t just write articles. We do not decide which criminal articles apply — the courts and the regulators do. But apparently, at Taylor Wessing, you operate under the delusion that lawyers write the laws and pass the verdicts.

ATTENTION TO ALL CORPORATE CLIENTS: This avalanche cannot be stopped. The data is already out there. It was emailed from Taylor Wessing’s own servers. You should say a massive “thank you” to Dr. Patrick, Dr. Tobias, and their accomplices for single-handedly compromising your confidential documents.

📎 SECURITY ADVISORY: We Warned Them. Now It’s Up To You.

We have already contacted Taylor Wessing and informed them of this critical vulnerability. But let’s be realistic: we know they are liars.

We fully expect them to lie, hide the truth, and bury this under attorney-client privilege, because the scale of this data leak is undeniably critical. If you or your company have ever received a “redacted” PDF document from Taylor Wessing, audit these files immediately.

⚡️ No-Install Lifehacks (The Easiest Ways to Check):
The “Select All” Hack: Open the PDF in your browser. Press Ctrl+A (Select All), then Ctrl+C (Copy), and paste it (Ctrl+V) into Notepad. If the redaction is fake, the “hidden” text will simply paste right along with the rest of the document.
The “Blind Search” Hack: Press Ctrl+F and search for common characters (like the vowel “a” or the number “1”). If the browser registers a hit and highlights the black redaction box — the text layer is still alive.
🛠 How to Check Visually (Safe Offline Software):

LibreOffice Draw — Open the PDF, click the black box, and press Delete.

Adobe Acrobat Pro — Use the “Edit PDF” tool to simply drag the black shapes out of the way.

⚠️ WARNING: Do NOT upload sensitive legal documents to random online PDF editors like ilovepdf. You might be committing a data breach. Only use local software.

Do Not Let Them Hide This: Open-Source Forensic Toolkit

We contacted Patrick, and apparently, he thought he was the smartest guy in the room. In response to our message about the data leak, he seemed to think we were going to chat with him, and he simply called it ‘amusing.’

There will be no further communication between PhishDestroy and Taylor Wessing. We have notified them about the leak via their official emails. However, judging by Patrick’s reaction, ‘amusing’ means that no one is going to take any action or notify anyone.

Because of this, we have created a tool so you can check and report it yourselves. It can be run locally without an internet connection, and there are no logs.

GitHub Forensic Utility: taylor-wessing-data-breach-toolkit

Forensic auditing utility to expose and unmask failed visual-only PDF redactions by Taylor Wessing LLP.

Access Open-Source Toolkit on GitHub

Remove the black square, read the truth, and immediately report the data leak to your national Data Protection Regulator.

And if you want to share your confirmed leaks with us ([email protected]), we will gladly forward them to the universities where these “experts” give lectures.

Dr. Patrick Zurheide Taylor Wessing GDPR Threat Audit

Doctor, in response to a legitimate GDPR request, what are you doing? Making accusations? Did you have a fever? We guarantee that we won’t hide anything and will forward everything not just to the appropriate authorities, but to more than just the appropriate authorities — including your university. We want to challenge the fact that you’re a doctor — I think you might be a criminal? A fraudster? A blackmailer? But I’m not a court, and I’m not you — I can’t call you that.

They don’t hesitate to issue direct criminal threats, labeling anyone associated with a lawful GDPR request as “accomplices” (a direct formulation from Dr. Patrick Zurheide’s official response). To the corporate giants reading this: this is who you trust with your clients’ data. You are paying premium rates to absolute amateurs who treat a fundamental GDPR data request like an aggressive debt collector’s call or a hostile corporate attack.

People with this mentality have no business working in Tech and IT Law. They twist European legislation to suit their arrogance, and to make matters worse, they are allowed to teach at EU universities. With clowns like this gatekeeping data protection, EU citizens effectively have no rights. They use the very laws designed to protect you as a weapon to threaten you.

Let us remind Dr. Patrick and his “accomplices” of one simple fact: We do not blackmail, and we do not suffer from a God complex. We do not decide which criminal articles apply, and neither do you. The courts and the regulators do.

— PhishDestroy Research Team (and the Dog)

Full Investigation & Evidence Database

Access the complete technical breakdown, source logs, and timeline directly on the primary research platform.

👉 Read the full technical analysis and evidence of the Taylor Wessing leak at PhishDestroy
Direct Link Target: https://phishdestroy.io/valve-profits-from-stolen-accounts