← All posts

The Firm That Holds Your Secrets Just Became the Target

This week, a leaked archive of chat messages from an extortion crew landed in the hands of journalists and researchers. The crew is the Silent Ransom Group, also tracked as Luna Moth. The archive, which runs from August 2025 to September 2026, claims the group collected roughly $207 million from 27 law firms in about six months. The group did not encrypt a single file to do it.

Pause on the first number, because it is the attacker's own bookkeeping. Victims have not confirmed the payment amounts, and the researchers who examined the material are careful to say the totals are unverified. What has been corroborated is the shape of the operation. Blockchain analysts at Crystal Intelligence found on-chain movements that match dates and amounts referenced in the chats, and Chainalysis linked cryptocurrency addresses in the archive to known Silent Ransom Group extortions. The scale looks real even if the exact dollars are not.

If you sit on a board or run a company, the headline is not about law firms. It is about what you handed them.

Why Lawyers? Because They Hold Everyone's Secrets

Think about what your outside counsel holds: merger plans before they are announced, litigation strategy, employment disputes, regulatory correspondence, intellectual property filings, and privileged advice you would never email to a competitor. A law firm is a concentrated vault of other people's worst-day documents.

For an extortion crew, that makes the business model simple. Steal the files, skip the encryption, and threaten to publish. A firm cannot "restore from backup" its way out of a threat to leak client secrets. The leverage is the confidentiality itself, and the pressure comes from clients who will ask why their data was exposed.

How They Get In: A Phone Call

According to the FBI's May 2026 flash alert, the group's actors pose as employees of the victim's own IT department. They call staff directly, or send phishing emails urging staff to call a fake help desk number. The "technician" then talks the employee into opening a remote-desktop session and uses ordinary remote-access tools to copy data out. The tools are legitimate, so little of this looks like malware.

The leaked chats add a stranger detail. Recorded Future News reported that the group discussed recruiting people to physically enter law firm offices, and that the FBI alert warns that if remote access fails, the group may send someone to plug a storage device into a computer. Reporters could not verify the most extreme schemes in the archive, and the leader himself estimated that only about one in ten recruits was usable. But one firm's negotiation reportedly described someone entering its New York office and copying files to a flash drive. Treat the in-person angle as credible enough to plan for, and unproven enough not to panic over.

The Governance Gap Nobody Is Discussing

Here is where this connects to the argument I make in Cyber Risk Is Business Risk. Most boards run a vendor-risk program that asks the same questions of every supplier: Do you have a SOC 2 report? Do you carry cyber insurance? Have you had a breach?

Those are compliance questions. They tell you whether a vendor has paperwork. They do not tell you whether a determined caller could talk a first-year paralegal into granting remote access on a Tuesday afternoon.

This is the compliance-versus-security gap in its purest form. Your law firm may be fully "compliant" and still be one convincing phone call away from handing your privileged files to a criminal. And because the data is yours, the regulatory, contractual, and reputational consequences land on you, not on them.

It also changes the Three Questions. What are we protecting? includes the information you have shared with advisors. What are the threats? now includes attackers who have studied which professional-services firms hold the most valuable material per employee. Are we prepared? has to extend to the question of what you will do the morning your counsel calls to say they have been breached.

The Uncomfortable Part

Pay attention to what the chats reportedly show about negotiations. A firm authorized a seven-figure offer but demanded proof that all copies would be destroyed, citing LockBit's history of not deleting data after payment. That is the core problem with paying a data-theft extortionist: you are buying a promise from a criminal. Nothing guarantees deletion, and a payment can mark you as someone who pays.

Your advisors are also facing this decision with your information on the table. Do you know whether your counsel would pay, who would decide, and whether they would tell you?

What to Ask Your CISO and General Counsel This Week

Which outside firms and advisors hold our most sensitive material, and what is the list? Many organizations cannot produce it. Start with M&A counsel, litigation counsel, and any firm handling regulatory matters.

What do our engagement letters require when an advisor is breached? Look for notification timing, a named contact, and what happens to our data. If the answer is silence, that is a gap you can close in the next renewal.

Have we asked our top advisors how their help desk verifies a caller? The FBI's described attack pattern turns on an employee trusting a voice. A firm that has a callback-verification rule and trains on it is meaningfully safer than one that does not.

Could we send less data? Data you never shared cannot be stolen from someone else's network. Ask whether sensitive documents are being retained by advisors long after matters close.

Do we have a plan for the day an advisor calls us? Decide in advance who in the company takes that call, who talks to the SEC disclosure team, and who reaches out to affected counterparties.

The Takeaway

The Silent Ransom Group story will be argued over for weeks, and rightly so, since its numbers are unproven. But the lesson does not depend on the exact dollar figure. Attackers have realized that the quickest path to your secrets may run through the people you trust to keep them, and the best defense they face is a receptionist who says, "Let me call you back at the number we have on file."

Ask your counsel what they do when the phone rings. Then ask what you share with them in the first place.