Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Law Firm Cybersecurity2026-09-15By Tyson Benson

Your Law Firm's Client Files Could Become Someone Else's Bargaining Chip

Three groups have named U.S. law firms in reported extortion claims. Learn what is known and what your firm should ask about protecting client files.

Three threat groups have named U.S. law firms in recent extortion reports. The practical question for your firm is simple: could someone turn your client files into leverage?

Your systems may still work. Your calendar may still be open. A hearing may still be scheduled. But if someone has copied confidential files, restoring a backup will not restore their confidentiality.

The reports below are threat-actor claims, not independently verified breaches. The linked reporting does not confirm what was taken, how access occurred, or whether the firms negotiated.

What the reports say

Booba Project – Mestechkin Law Group

DeXpose reported on September 14, 2026, that Booba Project claimed to have taken approximately 37 GB from Mestechkin Law Group P.C. The amount is a reported claim, not a verified measure of compromised data. Read the report.

Eclipse – The Zhou Law Group

On September 8, DeXpose reported that Eclipse claimed an attack against The Zhou Law Group, a California family law firm, and threatened publication. The report does not establish which documents, if any, were obtained. Read the report.

Qilin – Bauman Law Group

DeXpose reported on September 6 that Qilin claimed an attack against Bauman Law Group and threatened to release confidential data. The report does not establish a coordinated campaign or how often law firms are targeted. Read the report.

The leadership takeaway

Backups help a firm resume operations. They do not retrieve a copy already held by an attacker.

Partners and office managers should ask two separate questions:

  • Can we keep working? Test restoration of the systems needed for client service.
  • Can we keep information confidential? Limit access, monitor downloads, and know who can export matter data.

The reports do not establish phishing as the entry method. Your review should still cover phishing readiness, account security, public-facing systems, and file permissions.

Five questions for your IT provider

Bring these questions to your next IT or leadership meeting:

  1. What can someone reach from the internet? Review remote-access services, login portals, old subdomains, and public systems.
  2. What could one compromised account access? Check matter permissions, shared folders, external sharing, and inactive accounts.
  3. Would an unusual download trigger a response? Identify what is logged, who reviews alerts, and what prompts investigation.
  4. Can we demonstrate recovery? Ask when a restore was last tested, what was restored, and how long it took.
  5. Who coordinates the first hour? Name the responsible partner, IT contact, incident-response support, and insurer contact.

These questions assess your controls. They are not conclusions about what the named firms did or did not have in place.

A practical next step

The free Zero-Access Exposure Review™ identifies publicly observable exposure. It requires no passwords or internal access and does not determine whether your firm has been breached.

For a deeper review, the Law Firm Security Baseline examines controls protecting client information, identities, email, devices, and Microsoft 365 within the agreed scope.

Managed Phishing Testing & Staff Training gives staff practice recognizing suspicious requests. It addresses one part of preparedness and is not a guarantee against ransomware or extortion.

Start with what you can document: request your free exposure review.

Related reading

Reporting reviewed September 15, 2026. Incident descriptions reflect the attributed claims in the linked sources. No stolen material was accessed or independently authenticated for this article.