Law Firm Ransomware and Business Email Compromise: The New Attack Pattern
Law firm ransomware and business email compromise are converging. Learn how attackers profile firms before using social engineering, impersonation, and extortion against law firms.
Blog post - By Securing Your Law Firm
Get your free Zero-Access Exposure Review™ | See Email & Sign-In Security
For many law firms, the first step in a law firm ransomware attack or extortion campaign is not malware. It is impersonation.
Attackers do research first. They look at a firm's public DNS records, email authentication, lookalike domains, and externally visible services. Then they decide whether a call, a fake IT request, or a spoofed client email is likely to work.
That matters because the goal is often not to break into a network at all. The goal is to gain trust, move laterally, steal files, and pressure the firm into paying.
The attack starts before the phone call
The important question for a managing partner is not what the attack is called. It is what an attacker can learn before they ever contact your firm.
An attacker can often determine:
- Whether your firm's domain is easy to spoof
- Whether DMARC is enforced
- Whether lookalike domains are already registered
- What public services or infrastructure are exposed
- What details could make a fake IT call or client email believable
None of this requires a breach. It is basic reconnaissance. And it is often enough to turn a generic phishing attempt into a believable story. For the broader threat picture, see Law Firm Cyberattacks Doubled: Why Small and Mid-Sized Practices Are Now Primary Targets.
Why this fits law firms so well
Law firms have three things attackers want: money, sensitive information, and trust.
A firm may hold settlement data, client records, privileged communications, deal information, and financial instructions. At the same time, attorneys and staff rely on fast communication with clients, vendors, and opposing counsel. That creates a perfect environment for impersonation.
The FBI has warned that attackers are using voice phishing, fake support calls, and social engineering to gain access and pressure victims. In many cases, the stolen data is then used for extortion, not simply for a traditional ransomware lock.
This is why the Luna Moth extortion pattern and the WilmerHale impersonation case are part of the same story. The weakness is not just malware. It is trust. If you want to understand how a one-character change in a domain can become a client-fraud problem, see What Is a Lookalike Domain? Why Your Law Firm Should Be Concerned. If you want the full mechanics of how spoofed legal communications lead to wire-fraud risk, read How Law Firm Email Spoofing Puts Clients at Risk.
The right place to start is outside the network
That is why we built the Zero-Access Exposure Review™.
It does not log into Microsoft 365. It does not ask for passwords. It does not access your internal network.
Instead, it checks the public-facing signals an outsider can already see, including:
- SPF, DKIM, and DMARC posture
- Lookalike domains that could be used for impersonation
- Externally visible services and infrastructure
- Public indicators of weak identity posture or exposure
The goal is not to tell you your firm is "secure." No outside-in review can do that.
The goal is much more practical:
See what an attacker can see before they decide how to approach your firm.
If your email domain is easier to impersonate than expected, you should know. If a lookalike domain creates a client-fraud opportunity, you should know. If your public footprint reveals more than it should, you should know.
Two minutes. Zero internal access.
The Zero-Access Exposure Review™ is free for eligible law firms with a matching work email.
You provide your firm's domain and your work email. We verify the request through that inbox, then run a passive, outside-in review using public data only. The report is shown in the browser after verification and is not emailed. No system access is required.
That is the right boundary for this problem. The review does not promise a clean bill of health. It tells you what an attacker can already learn from the outside, which is often the earliest and most useful signal in the sequence. If you want to see how this fits into the larger process, how the review works explains the verification, scope, and follow-up steps. If you want a practical next step, request the free review and start with what is already visible.
Start your free Zero-Access Exposure Review™ →
This article is informational and does not constitute legal or compliance advice. References to cyber incidents and threat-actor activity are based on publicly available government advisories, threat-intelligence reporting, breach disclosures, and news reporting. Attribution and details of individual incidents may remain subject to investigation.
