A Law Firm Offered $520,000 to Stop the Leak. It Got Posted Anyway.
Luna Moth's law firm leak site now includes firms far smaller than WilmerHale and Goodwin Procter. Here's what that means if your firm isn't AmLaw 100.
Luna Moth's leak site is no longer limited to the largest names in the legal industry. Recent listings reportedly include firms with revenue closer to the range of a regional or mid-sized practice, including one firm associated with a reported $520,000 offer that did not prevent publication.
That changes how smaller firms should read the extortion campaign that has reportedly taken roughly $46 million from WilmerHale, Weil Gotshal, and Goodwin Procter this year. It is easy to see those names and think: that's a BigLaw problem, with BigLaw budgets and BigLaw-sized targets on their backs. The leak site the attackers use to pressure victims into paying has made that argument harder to hold onto.
The roster just changed
According to reporting from The Insurer, the same group's leak site now lists Farella Braun + Martel, a San Francisco firm with reported revenue around $21 million, and Sandberg Phoenix, a Midwest firm, alongside Mayer Brown and Fox Rothschild. The site reportedly states that Farella Braun + Martel offered $520,000 to keep its data from being published. The figure has not been independently verified, and the firm has been approached for comment. According to the reporting, the data was published despite the reported offer.
The Insurer notes that firms now listed on the site range from roughly $21 million to $2.2 billion in revenue. That's no longer a BigLaw story. That's a "law firm" story.
For a small firm, the risk is not that an attacker mistakes it for BigLaw. The risk is that the attacker sees a valuable target with fewer layers of verification between a convincing phone call and access to sensitive files.
Why paying doesn't guarantee anything here
It's worth sitting with why a reported offer to pay did not stop publication, because it points to something small and mid-sized firms often get backwards.
Traditional ransomware encrypts your files and sells you the key back. Paying, however uncomfortable, at least buys a predictable outcome. This group – tracked as Silent Ransom Group, Luna Moth, or Chatty Spider – doesn't encrypt anything. It steals documents through social engineering, then uses the threat of publication as leverage. There's no key changing hands, no guarantee, and no mechanism forcing the group to hold up its end once it already has the files. Farella Braun + Martel's reported experience is a fairly direct illustration of that gap.
The attack method itself hasn't changed from what we covered previously: a call posing as internal IT support, followed in some cases by someone showing up in person claiming to be IT staff, ending with an attacker physically or remotely gaining access to plug in a device and pull data out. If you want the full breakdown of how that plays out step by step, our earlier post covers it in detail.
What a $21 million firm has in common with a five-person one
Farella Braun + Martel is a real law firm with a real security budget – far more than most solo and small firm practices have available. If a firm at that scale can still end up on a leak site with a six-figure offer on the table, the operating assumption for a smaller firm should not be "we're too small for this." It should be "we're a valuable target with fewer people positioned to catch the same approach."
The practical defenses are unglamorous but effective, and don't require BigLaw budgets:
- Require staff to verify every IT-support request through a known internal number or approved vendor contact. Do not trust caller ID or a number supplied by the caller.
- Keep a short, current list of approved IT providers and support contacts. No unfamiliar person should receive access to a workstation or office based on a phone call alone.
- Restrict unauthorized USB storage devices where practical so a visitor cannot simply plug in a drive and copy files.
- Give staff a short script: "I don't grant access from an unsolicited call. I'll contact the help desk directly."
- Train staff on this specific scenario, because "IT is calling about your computer" is designed to sound routine.
The first question to ask your team is simple: if someone called claiming to be IT support today, who would verify that person before granting access? If the answer is unclear, the free Proprietary Exposure Review is a low-risk place to begin.
Where to start
If you want to know what an attacker can learn about your firm before making contact, start with the free Proprietary Exposure Review. It uses public DNS and web records only, requires no credentials or private-system access, and sends the results only to the verified work inbox that requested them. Your submitted domain is retained only during the verification window, typically up to 60 minutes; the report is never saved, and we only keep the requesting work email for follow-up purposes.
This article is informational and does not constitute legal or compliance advice. Details regarding Farella Braun + Martel and Sandberg Phoenix are drawn from reporting by The Insurer; the $520,000 figure is as reported and has not been independently verified, and neither firm has been found liable for any wrongdoing.
