We thought Taylor Wessing made a manual mistake with a GDPR request. We were wrong. It’s an automated, firm-wide catastrophe.
🚨 Key Findings:
The Breach: Elite law firm Taylor Wessing is using an outdated script to “redact” sensitive PDFs, masking data visually but leaving the text fully readable underneath.
The Scale: Evidence suggests this vulnerability has affected their corporate clients (including giants like Pfizer, Just Eat, Chubb, and SAP) since 2019.
The Hypocrisy: While leaking massive amounts of data, their lawyers issue baseless criminal threats to citizens making lawful GDPR requests.

A few days ago, as a spin-off to our massive cybersecurity exposé on How Valve Profits From 70M+ Stolen Steam Accounts, we published an article documenting a catastrophic legal blunder.

We revealed how the elite, high-priced lawyers at Taylor Wessing (specifically Dr. Patrick Zurheide and Dr. Tobias Schelinski) accidentally leaked 830 pages of highly sensitive, de-anonymized Steam user data while trying to defend Valve against a routine GDPR request.

We joked that my dog, having precisely zero data breaches on her resume, was officially better at data protection than a Salary Partner with a PhD in IT Law.

My dog is now winning 2–0.

Meet our Chief Data Protection Officer. 0 data breaches. 100% better at using PDFs than Taylor Wessing.

After publishing the first piece, we had a long, hard think. We looked at those 830 pages of black rectangles. We realized something fundamental about corporate lawyers: they are generally too self-important to manually draw black boxes on 800+ pages. Doing that by hand would give you a severe case of digital hemorrhoids.

No, they didn’t do it manually. They used a script. And that’s when the joke stopped being funny, and became a systemic, global cybersecurity crisis.

The Cheap Software Behind the Elite Facade

Forensic metadata extraction of Taylor Wessing’s 830-page response. The “36 seconds” processing time is the smoking gun: they didn’t redact manually; they used an automated, vulnerable script.

Here is the technical reality of what these lawyers — who think they are richer, smarter, and more important than Valve’s own users — actually did.

To save money on proper, enterprise-grade data sanitization software, their systems rely on a generic, outdated library: Aspose.PDF for .NET 20.8.

The core issue is that their script uses this outdated software to draw black vector rectangles (using re/f operators in the PDF code) over text coordinates. What it should be doing is properly sanitizing and deleting the underlying text layer (using BT/ET operators).

It creates a visual mask on your screen. But the raw data? It remains 100% accessible beneath it.

Let’s do the math on the scale of this catastrophe. Dr. Patrick Zurheide alone likely processes roughly 100 to 300 GDPR requests a year. For the few users who don’t immediately surrender to his initial wave of legal threats and delays, he eventually sends them the “brilliance of his experience” — a legal response document that consists of 94% black rectangles.

But this is not Malevich’s “Black Square”.
It is just a cheap vector shape. Remove it.

The Blast Radius: Whose Data Did Taylor Wessing Process?

We didn’t just guess that this was a firm-wide issue. We tested it.

We immediately contacted individuals we knew who had previously received documents processed by Taylor Wessing. They sent us their files. We opened them and looked straight at the meta-tags. What did we find? Exactly what we expected. The exact same vulnerability. The exact same flawed redaction script.

Did we read the contents of their hidden documents? No. We absolutely refused to look at the underlying data. We simply checked the metadata, confirmed the vulnerability, and handed the owners the instructions on how to reveal the hidden text themselves.

But let’s scale this up. This vulnerability has likely been present in hidden documents processed by Taylor Wessing since 2019. Now, think about the corporate giants they defend.

Taylor Wessing proudly advertises its Data Protection and Cyber Security work for massive global corporations. Based on their own public client lists and our forensic findings, we have to ask a terrifying question regarding the data they have processed over the last five years:

If Taylor Wessing used this same cheap script to “redact” documents for these corporations, then they didn’t hide anything. They intentionally disclosed it.

The Difference Between Us: A Message to Taylor Wessing

Let’s address Taylor Wessing directly. What is the fundamental difference between your actions and ours?

You, Dr. Patrick and Dr. Tobias, are utterly arrogant. You threaten your clients and opponents with criminal code articles. You act like God. You arbitrarily hand out permanent account bans simply because a user’s burner email address doesn’t explicitly contain their real name. You act as the judge, the jury, and the executioner.

We do not blackmail. We do not suffer from a God complex. And we don’t just write articles. We do not decide which criminal articles apply — the courts and the regulators do. But apparently, at Taylor Wessing, you operate under the delusion that lawyers write the laws and pass the verdicts.

ATTENTION TO ALL CORPORATE CLIENTS: This avalanche cannot be stopped. The data is already out there. It was emailed from Taylor Wessing’s own servers. You should say a massive “thank you” to Dr. Patrick, Dr. Tobias, and their accomplices for single-handedly compromising your confidential documents.

📎 SECURITY ADVISORY: We Warned Them. Now It’s Up To You.

We have already contacted Taylor Wessing and informed them of this critical vulnerability. But let’s be realistic: we know they are liars.

We fully expect them to lie, hide the truth, and bury this under attorney-client privilege, because the scale of this data leak is undeniably critical. If you or your company have ever received a “redacted” PDF document from Taylor Wessing, audit these files immediately.

⚡️ No-Install Lifehacks (The Easiest Ways to Check)

- The “Select All” Hack: Open the PDF in your browser. Press Ctrl+A (Select All), then Ctrl+C (Copy), and paste it (Ctrl+V) into Notepad. If the redaction is fake, the “hidden” text will simply paste right along with the rest of the document.

The “Blind Search” Hack: Press Ctrl+F and search for common characters (like the vowel “a” or the number “1”). If the browser registers a hit and highlights the black redaction box — the text layer is still alive.

🛠 How to Check Visually (Safe Offline Software)

LibreOffice Draw — Open the PDF, click the black box, and press Delete.
Adobe Acrobat Pro — Use the “Edit PDF” tool to simply drag the black shapes out of the way.

⚠️ WARNING: Do NOT upload sensitive legal documents to random online PDF editors like ilovepdf. You might be committing a data breach. Only use local software.

Do Not Let Them Hide This

We are not willing to take on the burden of responsibility, nor will we act as free cybersecurity janitors to cover up the crimes of a massive law firm that exists to threaten and intimidate citizens in the interests of mega-corporations.

If you discover that your data (or your opponent’s data) was left exposed by Taylor Wessing’s fake PDF redactions, do not wait for them to contact you. They won’t.

We contacted Patrick, and apparently, he thought he was the smartest guy in the room. In response to our message about the data leak, he seemed to think we were going to chat with him, and he simply called it ‘amusing.’
There will be no further communication between PhishDestroy and Taylor Wessing. We have notified them about the leak via their official emails. However, judging by Patrick’s reaction, ‘amusing’ means that no one is going to take any action or notify anyone.
Because of this, we have created a tool so you can check and report it yourselves. It can be run locally without an internet connection, and there are no logs. It works not only for this specific case but for any similar ones. Let’s just hope there aren’t any more ‘amusing’ lawyers out there besides these guys.

GitHub - phishdestroy/taylor-wessing-data-breach-toolkit: Forensic auditing utility to expose and unmask failed visual-only PDF redactions by Taylor Wessing LLP. Designed to extract hidden text layers offline and verify GDPR compliance following the Valve Corporation data leak.

https://phishdestroy.github.io/taylor-wessing-data-breach-toolkit/

Remove the black square, read the truth, and immediately report the data leak to your national Data Protection Regulator.

And if you want to share your confirmed leaks with us (complains@phishdestroy.io), we will gladly forward them to the universities where these “experts” give lectures. We are certain they have nothing of value to teach students, except perhaps a masterclass in arrogance and issuing empty threats.

They will inevitably call us “black-hat hackers.” They will likely issue PR statements claiming they are “cooperating with law enforcement.” Funny, isn’t it?

Apparently, the law applies differently to them. They are the ones who leaked the data of minors. They are the ones who put children’s lives in digital and physical danger through their sheer incompetence. Yet, they operate under the delusion that they are the law.

Dr. Patrick Zurheide Taylor Wessing GDPR Threat Doctor, in response to a legitimate GDPR request, what are you doing? Making accusations? Did you have a fever? We guarantee that we won’t hide anything and will forward everything not just to the appropriate authorities, but to more than just the appropriate authorities — including your university. We want to challenge the fact that you’re a doctor — I think you might be a criminal? A fraudster? A blackmailer? But I’m not a court, and I’m not you — I can’t call you that.

They don’t hesitate to issue direct criminal threats, labeling anyone associated with a lawful GDPR request as “accomplices” (a direct formulation from Dr. Patrick Zurheide’s official response). To the corporate giants reading this: this is who you trust with your clients’ data. You are paying premium rates to absolute amateurs who treat a fundamental GDPR data request like an aggressive debt collector’s call or a hostile corporate attack.

People with this mentality have no business working in Tech and IT Law. They twist European legislation to suit their arrogance, and to make matters worse, they are allowed to teach at EU universities. With clowns like this gatekeeping data protection, EU citizens effectively have no rights. They use the very laws designed to protect you as a weapon to threaten you.

Let us remind Dr. Patrick and his “accomplices” of one simple fact: We do not blackmail, and we do not suffer from a God complex. We do not decide which criminal articles apply, and neither do you. The courts and the regulators do.

— PhishDestroy Research Team (and the Dog)

About PhishDestroy
PhishDestroy is an independent cybersecurity research initiative dedicated to dismantling criminal phishing infrastructure, exposing corporate data breaches, and holding tech giants accountable for user safety. We accept no donations. We rely entirely on forensic facts.