Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Law Firm Cybersecurity2026-09-16By Securing Your Law Firm

Your Law Firm’s Backups Can Restore Files. They Cannot Undo a Data Leak.

Backups can restore your law firm’s files after ransomware, but they cannot undo data theft. Learn what to ask your IT provider and where to start.

Your Law Firm’s Backups Can Restore Files. They Cannot Undo a Data Leak.

A law firm’s name. A countdown. A threat to publish documents.

That is the pressure visible in a recent screenshot of a ransomware leak-site listing naming Resolve Law Group. Another screenshot names Bauman Law Group and displays a published status.

For a managing partner or office manager, those images raise a question that a successful backup test cannot answer:

If someone copied our confidential files, what would restoring our systems actually fix?

What these ransomware listings show – and what remains unverified

The supplied Resolve Law Group screenshot displays a September 15, 2026 listing date, a publication countdown, and purported document previews.

Attacker-controlled listing showing Resolve Law Group with a publication countdown
Resolve Law Group listing screenshot

Attacker-controlled screenshot showing a claimed Resolve Law Group listing and publication countdown. The listing is not independent proof of an intrusion or data theft.

The Bauman Law Group screenshot displays a September 5, 2026 listing date and a status suggesting publication.

Attacker-controlled listing showing Bauman Law Group with a published status
Bauman Law Group listing screenshot

Attacker-controlled screenshot showing a claimed Bauman Law Group listing marked “Published.” The status is not independent proof that the displayed material is authentic.

These are representations made on an attacker-controlled site. They do not independently establish that the displayed material is authentic, that it came from the named firms’ systems, or that publication occurred as claimed. Listing dates also do not establish when an intrusion happened.

SOCRadar’s reporting on Bauman Law Group attributes the listing to Qilin and explicitly describes it as an alleged claim, not a confirmed intrusion. As of September 16, 2026, we have not independently verified either underlying incident, the claimed data, or an initial access method.

The screenshots illustrate an extortion tactic. They are not a basis for assigning fault to either firm.

Why backups do not prevent ransomware data leaks

Backups help a firm recover information and resume work. They cannot retrieve a copy already taken by someone else.

CISA explains that attackers may combine file encryption with threats to release stolen information, commonly called double extortion. Data theft and publication threats can also occur without encryption. A firm does not need to lose access to its files to face an extortion demand. CISA’s StopRansomware Guide

For law firm leaders, that creates two separate questions:

  • Recovery: Can we restore the systems and documents needed to serve clients?
  • Confidentiality: Can we prevent unauthorized access, spot suspicious activity, and determine what information may have been taken?

A strong answer to the first question does not automatically answer the second. Review how law-firm document security should work beyond the network to see why access and sharing controls matter after files move to cloud systems.

Ordinary client records can become pressure points

A firm does not need a celebrity client or a billion-dollar lawsuit to hold sensitive information.

Consider what an ordinary matter may contain: identity documents, financial records, settlement discussions, medical information, or private correspondence. These are general examples of law-firm information, not verified descriptions of either alleged incident.

If such records were exposed, the firm could face difficult client conversations and an investigation into what happened – even after everyone was back at their desks.

“Our systems are working again” does not answer “Who else has our documents?”

Five questions to ask your IT provider

Use these questions to start a specific conversation about your firm’s environment:

  1. What could one compromised account reach? Ask whether a typical employee account can access only necessary matters or a much larger collection of client records.
  2. Which access paths deserve attention? Request a current view of remote access services, public-facing systems, former employee accounts, and outside collaborators.
  3. What protects our sign-ins? Ask how multifactor authentication is enforced, where exceptions exist, and how suspicious sign-ins are investigated.
  4. Who would notice unusual file activity? Ask which systems record downloads and sharing changes, who reviews alerts, and what evidence would be available afterward.
  5. Have we practiced a data-theft scenario? A recovery exercise should be complemented by a discussion of who coordinates the investigation, preserves evidence, and handles communications when files may have been copied.

CISA recommends protecting remote access, addressing public-facing weaknesses, testing backups, and exercising incident-response and communications plans. Those controls deserve verification before an incident. CISA’s prevention and response guidance

These are general preparedness questions. The screenshots do not establish that any particular control failed at either named firm. For a practical planning framework, see the first 72 hours of a law-firm incident response.

Start with evidence about your own firm

You do not need to wait for an extortion threat to identify what deserves attention.

Our free Zero-Access Exposure Review™ examines publicly observable exposure without requiring internal access or passwords. It is a practical starting point for understanding what outsiders can see. It cannot establish whether confidential information has already been stolen.

For deeper verification, the Law Firm Security Baseline evaluates essential controls protecting your firm’s information, identities, devices, email, and Microsoft 365 environment. You can also review Microsoft 365 data-protection priorities for law firms before meeting with your IT provider.

When findings call for action, our Priority Security Improvements provide scoped remediation or coordination with your existing IT provider, with the scope and price agreed before work begins.

Know what outsiders can see – and what needs attention before your firm faces a countdown. Start your free exposure review.