Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-14By Securing Your Law Firm

When BigLaw Pays $46 Million, Your Five-Attorney Firm Is the Easier Target

A cyber-extortion group took $46 million from BigLaw firms without deploying ransomware. Here's how the attack works and what small firms can do about it.

Over the past few months, a cyber-extortion group has taken roughly $46 million from three of the country's largest law firms – and it didn't need to write a single line of ransomware to do it.

What Actually Happened

Weil Gotshal & Manges reportedly paid between $18 million and $20 million in May 2026 after an extortion group threatened to publish stolen client documents. WilmerHale reportedly paid at least $18 million after a similar incident. Goodwin Procter reportedly paid around $10 million. Mayer Brown had client data leaked by the same group. Herbert Smith Freehills Kramer disclosed a related incident around the same time, and Jones Day faced – and reportedly did not pay – a $13 million demand earlier in the year.

The FBI has attributed the campaign to a group known as Silent Ransom Group, also called Luna Moth or Chatty Spider, which it says has been targeting U.S. law firms since 2023 specifically because of the sensitivity of the data they hold.

The Part That Should Worry Small Firms More Than the Dollar Figures

None of these firms had their systems encrypted or locked. Silent Ransom Group doesn't deploy ransomware at all. Its playbook is almost entirely social engineering:

  1. Call an employee, posing as internal IT support, and talk them into installing remote access software.
  2. In more recent cases – per an FBI alert issued in May 2026 – send someone in person to the office, still posing as IT support, to plug a storage device into a firm computer and walk out with the data.
  3. Threaten to publish what was taken unless a ransom is paid.

No malware signature to catch. No locked screen to notice. Just a phone call, a visit, and the data is on its way out the door long before anyone at the firm knows there's a problem.

Why "We're Too Small to Matter" Is the Wrong Instinct

It's tempting to read this as a BigLaw story. It isn't. The reasons attackers target law firms at all – privileged communications, financial records, trust account access, high urgency to resolve problems quietly – apply just as much to a ten-person firm as they do to one with a thousand attorneys. The real difference is that a BigLaw firm already has a cyber insurance program and an incident response retainer in place. Most small and solo firms have neither.

What a Small Firm Can Actually Do About This

You don't need an eight-figure security budget to close the door Silent Ransom Group walks through. A few controls stop this specific playbook cold:

  • Verify IT support out of band. No one – inside or outside the firm – should get remote or physical access to a machine based on an unsolicited call or visit alone. Confirm identity through a number or contact you already have on file, never one the caller provides.
  • Restrict who can plug external devices into firm machines. Basic device control policies stop the "walk in and copy the drive" step even if someone talks their way into the building.
  • Have a real incident response plan before you need one. Knowing who to call – counsel, forensics, insurance – in the first hour matters more than most firms realize.
  • Train staff on this specific scenario. Most security training covers phishing emails. Almost none of it covers "someone claiming to be IT support asked to come to the office."

The Bottom Line

Silent Ransom Group didn't need a zero-day exploit to take $46 million from three of the most well-resourced law firms in the country. It needed a phone call and an overwhelmed staff member willing to say yes. That's a solvable problem, and solving it doesn't require a BigLaw budget.

This article is informational and does not constitute legal or compliance advice.