There's an emerging cyber threat targeting law firms and their sensitive data. In an era where data is currency, cybercriminals are increasingly focused on one thing: valuable information.
For law firms, that information includes privileged communications, litigation strategy, merger and acquisition (M&A) activity, intellectual property and sensitive client financial data. What makes firms trusted advisors also makes them a target.
The FBI and leading cybersecurity firms have issued warnings about the growing problem, calling out specific cybercriminal groups such as Luna Moth, also known as the Silent Ransom Group. These hard-to-detect attacks are designed to extract sensitive data and information for the purposes of extortion.
How the Attacks Work
Unlike traditional ransomware attacks that encrypt systems and disrupt operations, these threat actors focus on gaining access to sensitive information while remaining largely undetected. Using social engineering and impersonation tactics, attackers attempt to gain the trust of employees and create opportunities to access firm systems and data.
Bad actors may use tactics such as:
- Impersonating internal IT personnel through phone calls and emails.
- Convincing employees to install legitimate remote access tools.
- Gaining unauthorized access to firm networks and systems.
- Rapidly exfiltrating sensitive firm and client data.
- Demanding payment in exchange for not publicly disclosing stolen information.
These attacks can be difficult to identify in their early stages because legitimate software is often used, normal business operations continue uninterrupted and the breach goes unnoticed until extortion demands are made. More recently, the FBI has observed cases where attackers have escalated to in-person tactics, sending individuals to office locations while posing as IT support personnel to gain access to systems and extract sensitive data.
Cybercriminals are taking a comprehensive approach to data theft, combining both digital and physical tactics to gain access to sensitive information. As a result, law firms need an equally robust strategy to protect their people, systems and data.
Why Law Firms?
Law firms are particularly attractive targets for data theft and extortion campaigns because they possess exactly the type of information cybercriminals value most. Privileged communications, litigation strategy, M&A activity, intellectual property and sensitive client financial information can all command a high price in the hands of threat actors.
Groups like Luna Moth recognize that the sensitivity of this information can become a powerful bargaining chip. They understand that possession of valuable data can increase the pressure to resolve an incident quickly, as firms seek to avoid the reputational, legal and regulatory consequences that can arise from public exposure.
For many law firms, the greatest cyber risk is no longer operational disruption — it's the exposure of confidential information that clients entrust them to protect.
What You Should Do Now
The most effective defenses focus on both technology and employee behavior. These cybercrimes typically rely on a combination of trust, deception and access rather than malware alone. Law firms should consider the following actions:
- Require strict verification procedures for all IT-related requests.
- Train employees to identify and escalate social engineering attempts.
- Limit and closely monitor the use of remote access tools.
- Implement phishing-resistant multi-factor authentication (MFA).
- Establish clear protocols for how IT teams communicate with employees.
- Ensure incident response plans are current and include data exfiltration and extortion scenarios.
Carriers are already responding by placing greater scrutiny on employee training, MFA adoption and remote access controls during underwriting evaluations. As insurers report increased frequency and severity of cyber claims among law firms, many are showing a reduced underwriting appetite for certain risks while continuing to apply pressure on pricing, retentions and coverage terms.
Bottom Line
These cyber threats are active and targeted extortion-based campaigns against law firms that rely on speed, deception and access to sensitive data rather than system disruption — they're not a theoretical risk.
Taking a proactive approach by regularly assessing your cybersecurity can help identify potential vulnerabilities and develop strategies to prevent costly cyber incidents.
The FBI specifically recommends validating the identity of anyone requesting access to firm systems or physical office space and reinforcing employee awareness of these tactics.
Speak with your advisor about evaluating your cyber risk and mitigation strategies.