Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-14By Securing Your Law Firm

When BigLaw Pays $46 Million, Your Five-Attorney Firm Is the Easier Target

A cyber-extortion group took $46 million from BigLaw firms without deploying ransomware. Here's how the attack works and what small firms can do about it.

Over the past few months, reporting has attributed roughly $46 million in alleged payments and demands involving several large law firms to a cyber-extortion group. The reported activity did not depend on encrypting files with ransomware.

What Actually Happened

Weil Gotshal & Manges reportedly paid between $18 million and $20 million in May 2026 after an extortion group threatened to publish stolen client documents. WilmerHale reportedly paid at least $18 million after a similar incident. Goodwin Procter reportedly paid around $10 million. Mayer Brown had client data leaked by the same group. Herbert Smith Freehills Kramer disclosed a related incident around the same time, and Jones Day faced – and reportedly did not pay – a $13 million demand earlier in the year.

The FBI has attributed the campaign to a group known as Silent Ransom Group, also called Luna Moth or Chatty Spider, which it says has been targeting U.S. law firms since 2023 specifically because of the sensitivity of the data they hold.

The Part That Should Worry Small Firms More Than the Dollar Figures

The reported incidents did not involve the usual locked-screen ransomware pattern. Public reporting and an FBI alert describe a playbook centered on social engineering:

  1. Call an employee, posing as internal IT support, and talk them into installing remote access software.
  2. In more recent cases – per an FBI alert issued in May 2026 – send someone in person to the office, still posing as IT support, to plug a storage device into a firm computer and walk out with the data.
  1. Threaten to publish what was taken unless a ransom is paid.

This approach may not produce the familiar malware alert or locked screen. A phone call or in-person visit can create a data-access risk before the firm recognizes the problem.

Why "We're Too Small to Matter" Is the Wrong Instinct

It's tempting to read this as a BigLaw story. The underlying reasons attackers target law firms – privileged communications, financial records, trust account access, and pressure to resolve problems quietly – can apply to smaller firms too. Smaller firms may also have fewer people available to verify an unexpected request.

What a Small Firm Can Actually Do About This

The following controls can reduce exposure to this specific playbook:

  • Verify IT support out of band. No one – inside or outside the firm – should get remote or physical access to a machine based on an unsolicited call or visit alone. Confirm identity through a number or contact you already have on file, never one the caller provides.
  • Restrict who can plug external devices into firm machines. Basic device control policies stop the "walk in and copy the drive" step even if someone talks their way into the building.
  • Have a real incident response plan before you need one. Knowing who to call – counsel, forensics, insurance – in the first hour matters more than most firms realize.
  • Train staff on this specific scenario. Most security training covers phishing emails. Almost none of it covers "someone claiming to be IT support asked to come to the office."

The Bottom Line

Silent Ransom Group didn't need a zero-day exploit to take $46 million from three of the most well-resourced law firms in the country. It needed a phone call and an overwhelmed staff member willing to say yes. That's a solvable problem, and solving it doesn't require a BigLaw budget.

If your firm doesn't have a dedicated security department, see Cybersecurity for Small Law Firms for practical starting points that don't require an internal IT team.

Related reading

This article is informational and does not constitute legal or compliance advice.