Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-09-13By Securing Your Law Firm

Law Firm Ransomware: Would Your Staff Recognize the First Request?

Recent law firm breaches show why phishing readiness matters. Learn what to test, what to document, and how managed campaigns work for small firms.

Blog post - By Securing Your Law Firm

Get your free Zero-Access Exposure Review™ | See Phishing Testing & Staff Training

An email says a document is ready for review. A caller says they need to fix an account. A vendor asks someone to resolve a charge.

Before anyone sees a ransom demand, someone may face a simpler decision: Should I trust this request?

For a small law firm, that decision may fall to a busy attorney, legal assistant, receptionist, or office manager. Preparing those people deserves a place alongside technical controls.

Recent law firm breaches make the issue timely. They also show why ransomware readiness must account for stolen documents and compromised accounts, even when computers remain operational.

Why phishing readiness matters for law firms

The first sign of a ransomware incident is rarely a lock screen. More often, it starts with a request that looks routine: a shared document, an account notice, a payment change, or a phone call from someone claiming to be IT.

A law firm can do everything right on paper and still be exposed if a staff member makes a rushed decision under pressure. That is why phishing readiness belongs in the same conversation as backups, MFA, and incident response.

What recent law firm breaches tell us

On September 3, 2026, Reuters reported breaches at Quinn Emanuel and McDermott involving social engineering. Quinn described access through one temporarily compromised account, and McDermott said its incident affected a single user. Those examples show how a narrow compromise can still expose sensitive files. Reuters reporting.

On September 10, Reuters reported that Greenberg Traurig said an unauthorized actor obtained a limited number of documents and posted them on the dark web. The firm said its systems were not compromised. The public account did not establish phishing as the entry point. Reuters reporting.

These reports do not show that every incident involved ransomware, the same attacker, or the same technique. The practical lesson is consistent: protecting client information requires attention to the people and accounts that can access it, as well as the systems storing it.

Ransomware, data extortion, and phishing are related, but not the same

Ransomware commonly encrypts files and demands payment. Data extortion can involve stealing information and threatening to disclose it without encrypting anything. An attack can involve both. Phishing is one route into an organization, not a synonym for either outcome.

The FBI's advisory on Silent Ransom Group, also known as Luna Moth, describes targeting of U.S. law firms, including callback phishing. A fake subscription notice prompts a call; the subsequent interaction can lead to remote access, data theft, and an extortion demand. The advisory also addresses impersonation of IT support. FBI advisory.

For partners, the distinction matters. Restoring your own files does not recover copies already stolen by an attacker.

That is why staff preparation should cover more than spotting typos. It should include requests to sign in, disclose information, approve access, install software, and move a conversation to a phone call.

What should law firm staff practice recognizing?

Start with the decisions people actually make during the workday. These examples are illustrative, not claims about how the firms named above were breached.

  • A shared document requires a fresh sign-in: confirm the request through a known channel before entering credentials into an unexpected page.
  • An urgent account notice asks for approval: verify through the firm's established support process before approving an unexpected authentication prompt.
  • A subscription notice provides a cancellation number: check the supposed charge independently rather than relying on contact details supplied in the message.
  • A caller claiming to be IT requests remote access: contact the known IT provider or internal administrator through a verified number before granting access.
  • An apparent partner or vendor changes payment instructions: follow the firm's independent payment-verification process, even when the message sounds familiar.

A useful exercise asks whether people know how to verify and report a request. Recognizing poor spelling is not enough when the request fits the recipient's work.

What a useful phishing test should measure

A phishing simulation sends controlled test messages to authorized participants. Awareness training explains how to respond. A managed program handles the administration and connects the exercise to follow-up learning.

A good report should help the owner answer a few practical questions:

  • Did the intended staff receive the exercise?
  • What interactions were observed?
  • Did anyone report the message, and through which channel?
  • Was assigned training completed?
  • What should the firm change or practice next?

Avoid treating the click rate as a security grade. NIST's Phish Scale helps interpret simulation results by accounting for how difficult a message is for a person to recognize. An easy test and a convincing work-related message are not interchangeable measures. NIST Phish Scale guidance.

In a ten-person firm, one person represents ten percentage points. Reports should show counts as well as percentages, explain scenario difficulty, and account for automated email-security activity where possible.

Use those findings to coach staff and improve process. Staff should feel able to report a mistake promptly, without fear that a bad outcome will become a negative performance record.

Need someone to run the exercise? Explore managed phishing testing and staff training for small law firms, including setup, follow-up training, and documented results.

Can phishing training prevent law firm ransomware?

It can provide practice and reveal gaps, but it cannot guarantee prevention. Evidence about training effectiveness is mixed: a 2025 study involving more than 12,000 employees at one financial technology firm found no significant overall improvement in click or reporting rates from the training interventions it studied. That is a reason to measure outcomes and avoid sweeping claims, not a finding about every possible training program or law firm. Research paper.

Our recommendation is to use simulations as one part of a broader readiness program. Maintain strong account protection, current software, appropriate access restrictions, controlled remote-support tools, tested backups, and a clear incident-response process.

An email exercise also does not establish how staff will respond to a live caller or unexpected visitor. If those scenarios matter to the firm, scope them separately and verify the underlying procedures.

For help examining the controls around staff decisions, consider the Law Firm Security Baseline. It is a separate service, not a prerequisite for phishing testing.

What if your cyber insurer asks for phishing testing?

Begin with the exact question or requirement. Do not assume that watching a training video, completing one simulation, and running quarterly campaigns are equivalent.

Before commissioning work, establish the basics:

  1. Activity: Is the request for awareness training, simulated phishing, or both?
  2. Frequency: Is testing needed once, quarterly, or on another schedule?
  3. Coverage: Which employees, partners, and contractors must participate?
  4. Evidence: What dates, completion records, results, and follow-up documentation are needed?

A useful evidence package records what actually happened, including incomplete participation and limitations. Your broker or insurer should confirm whether it meets the stated requirement. A completed simulation does not guarantee coverage, renewal, or a premium reduction.

A practical model for small law firms

Securing Your Law Firm can handle campaign setup, scheduling, administration, short follow-up training, and reporting. We coordinate with the person administering your email environment when setup requires their assistance.

For a small firm, a sensible starting point is often a one-time campaign, followed by a repeat cycle if the firm has ongoing risk or insurance requirements. Pricing is typically structured as follows:

  • 1 to 10 staff: $395 one-time or $995 per year
  • 11 to 25 staff: $595 one-time or $1,495 per year
  • 26 to 50 staff: $895 one-time or $2,495 per year

The one-time engagement includes one selected scenario, standard setup and delivery testing, short follow-up training with completion tracking, a dated report, and a 20-minute readout.

The annual program includes four campaigns over 12 months, four short training assignments, completion reminders, campaign reports, and an annual summary and readout.

Prices include standard setup and platform costs for one domain and one email environment. Additional environments, unusual delivery requirements, and bespoke exercises are scoped separately. The standard program does not include live telephone or in-person impersonation exercises. Prices are current as of September 13, 2026; see the service page for current scope and pricing.

You can purchase a campaign directly. No Security Baseline or free exposure review is required.

Questions law firm owners ask

We already have an MSP. Who runs the campaign?

Securing Your Law Firm manages the agreed campaign and documentation, coordinating necessary configuration with your existing provider. First check whether your current contract already includes an equivalent service.

How often should we test staff?

Match the schedule to your firm's needs and any documented requirements. Quarterly testing is our standard annual offering, not a universal insurance rule. Revisit the scope when staffing, threats, or requirements change.

What should we do if someone responds to a real suspicious request?

Have a known reporting contact and escalation procedure ready before an incident. Encourage immediate reporting, including when someone has already clicked or granted access. A scheduled simulation is not an incident-response service.

Give your staff a process they can use under pressure

The next suspicious request may arrive while someone is preparing a filing, answering a client, or processing an invoice. They need a workable way to pause, verify, and report, and the firm needs to know whether that process works in practice.

Request a managed phishing campaign for your law firm We will confirm the scope, run the agreed exercise, and explain the results.