All field notes

Field note · Incident study

The Threat Actor That Walked Into BigLaw's Front Door

In 2026, a threat actor tracked as Silent Ransom Group (also known as Luna Moth, and as UNC3753 in Google’s naming) extorted a string of US law firms. WilmerHale paid roughly $18 million. Goodwin Procter paid roughly $10 million, its third breach in five years. Weil Gotshal paid between $18 and $20 million. Jones Day appears to have refused a $13 million demand and lost the contents of ten client matters. Herbert Smith Freehills Kramer, Mayer Brown, and Taft were all named victims. The FBI issued a Private Industry Notification about the group in May 2025, then a second in May 2026.

Some of them never saw a network attack. In late 2025, the group’s operators started showing up at law-firm offices in person, saying they were from IT, sitting down at a workstation, and plugging in a USB device. The industry read is that ransomware is getting worse. That’s true. The durable read is that the profession’s ethical rules (confidentiality, breach notification, technology competence) were written for a threat model where the attacker was somewhere else. In 2026, the attacker is at reception.

$46M+Known ransoms paid by BigLaw victims in 2026
200+Ransomware incidents targeting law firms, 2025–early 2026
$5.08MAverage 2026 law-firm breach cost, up 10% YoY
2FBI advisories: May 2025 (vishing), May 2026 (physical intrusion)

The playbook

Three stages, over three years. Every stage keeps the tactics that worked, sheds the friction that didn’t, and moves closer to the desk where the material actually lives.

01

March 2022 → early 2025 · Callback phishing

Fake subscription-renewal invoices with a phone number to call. The victim initiates contact. That single detail sidesteps most email-security tooling, because there is no malicious link to score and no attachment to detonate. The follow-up call establishes rapport, then walks the victim through a remote-support session that installs exfiltration tooling. Efficient and low-signal, but slow: acquisition cost per victim was high because the pretext needed the victim’s own imagination to complete.

Victim-initiated contactBypasses email tooling
02

March 2025 · Direct vishing, IT impersonation

The group compressed the funnel by calling directly, on the employee’s personal cellphone, and impersonating internal IT. Pretext was uniform: an urgent security migration required the employee to re-authenticate. The FBI issued its first Private Industry Notification about the tactic in May 2025. What made it productive was the target environment. BigLaw associates take calls from unfamiliar numbers as a matter of course, sit on personal devices during transactions, and route many operational asks through informal channels because that is what deal cadence requires.

Personal cellphone pretextIT-help-desk impersonationDeal-cadence exploit
03

April 2025 → present · In-person physical intrusion

The tactic that generated the second FBI advisory in May 2026. An operator walks into a law-firm office, presents as a contracted IT technician, sits down at a workstation, and plugs in a storage device to exfiltrate material. No network intrusion in the traditional sense: no phishing landing page, no vulnerable server, no lateral-movement trace. What the physical tactic buys the attacker is direct access to the material an associate has open on their desktop, meaning current-matter documents, the discovery cache, the memo in progress. What it buys the defender is nothing, because nothing in a modern SIEM is looking for a man at reception with a lanyard.

Physical premises accessUSB exfiltrationZero-SIEM signature

Why law firms became the target class

Four properties, all of them structural to the profession, make law firms an efficient target for this specific tactic.

One. Concentration of privileged material. A mid-size firm doing a normal week’s work is holding dozens of active matters at some depth: discovery caches, deposition prep, settlement math, board-communication files. That is the exact material extortion pricing is built to monetize. The threat actor does not have to be selective. Almost every document has either a buyer or a leverage value.

Two. Insurance appetite absorbs the pricing signal. Public reporting via The Insurer names CNA as WilmerHale’s primary cyber insurer and Brit as Goodwin Procter’s, with Aon brokering the placement. Carriers pay the ransoms, subrogate what they can, and price the next renewal. From the attacker’s perspective, this is a market with a functioning clearing mechanism. Extortion demands in the $10 to $20 million range are large enough to be serious and small enough that the carrier will authorize settlement rather than fight through discovery. That is a predictable payout curve.

Three. Deal workflows normalize what would look abnormal elsewhere. M&A cadence normalizes urgent off-hours requests, personal-device use, and informal escalation. A call from an unknown number at 8 PM claiming an urgent security migration is not culturally out of place in a firm running six transactions to close. The tactics that would trip a control at a bank read as ordinary friction at a firm.

Four. Mid-firms have less to spend on defense than BigLaw and more to lose than a solo. Law.com’s mid-market coverage in May 2026 explicitly names midsize and smaller firms as the growth segment for these incidents. BigLaw is spending its way into stronger controls, so the pressure is migrating downward. The firm-size distribution of ransomware victims is going to skew smaller through 2027.

Where the ABA ethical rules meet the tactic

Three rules, one for each face of the incident. Every firm hit this year was already bound by all three, and the rules already contemplated the possibility of exactly the situation the firms are now in.

What the ABA rules requireStandard: LONG SETTLED
MR 1.6 · Confidentiality of client information.A lawyer shall make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. The 1.6(c) obligation is affirmative: the lawyer has to try, not just avoid disclosing.
Formal Opinion 483 (2018) · Breach notification.When a data breach involves or is likely to involve material client information, the lawyer has an ethical duty to notify the affected client promptly. State-bar and statutory obligations layer on top.
MR 1.1 Comment 8 · Technology competence.A lawyer shall keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Forty-plus states have adopted this language. Technology competence is not aspirational. It is part of the underlying competence duty.
What the tactic exploits at eachDirection: RULE-INWARD
Against MR 1.6.The exfiltrated material is privileged. The unauthorized-access branch of 1.6(c) is triggered the moment the USB device is plugged in. “Reasonable efforts” is the standard that gets tested when a firm has to answer whether the practices in place at the time of the incident met that bar.
Against Formal Op 483.The breach-notification duty runs to every client whose material is in the stolen cache. For a firm handling deal work, that is often dozens of counterparties, each with their own reputational sensitivity and litigation exposure. The Texas AG filing in the Goodwin matter (1,550+ Texas residents with names and SSNs, from a single state’s filing) is a preview of the class-notification volume.
Against MR 1.1 Comment 8. The tactic that defeats the firm is not obscure. Callback phishing has been public since 2022. Vishing has been an FBI-advisory topic since May 2025. Physical intrusion by fake IT contractors is old-world tradecraft. The technology-competence question becomes hard to answer if the answer requires accounting for why the firm had no operational discipline against a tactic described in a federal advisory a year earlier.

The rules were written for a threat model where the attacker was somewhere else. In 2026, the attacker is at reception.

The ethical duties do not shift when the tactic does. The evidence of “reasonable efforts” that a bar counsel or a malpractice carrier will ask for very much has.

What vCISO Lite does for a firm facing this tactic

vCISO Lite is a compliance, evidence, and vCISO-advisory platform. For a law firm, it stands up the InfoSec program the ABA rules assume the firm already has, and produces the artifact a bar counsel or a malpractice carrier will ask to see.

×Where the boundary sits
Endpoint DLP, MDR, EDR.

The stack layer that would stop a USB device the moment it plugs in is a different stack layer than the compliance-and-evidence one. That is a purchase a firm makes separately.

Live incident response.

When a breach is in progress, a firm needs an IR retainer with a paging phone number. vCISO Lite is what the retainer works from, not the retainer itself.

✓What vCISO Lite delivers
Policy development that documents reasonable efforts.

Rule: MR 1.6(c) requires reasonable efforts to prevent unauthorized access to client information. That standard is tested at incident post-mortem, when a bar counsel or a malpractice carrier asks what the firm had in place before the breach. Product:vCISO Lite ships a written InfoSec policy owned by a named partner, control-by-control evidence the policy is operating on the date in question, and an attestation trail on a defensible cadence. When Formal Op 483’s notification duty triggers, the client-by-client list and material-sensitivity classification are already in the platform, ready to run.

Vendor management with industry-specific incident intelligence.

Rule: MR 1.6 confidentiality runs to every subcontractor with access to client material, and Formal Op 483 starts a notification clock on any vendor breach that touches client data. The likely next Silent Ransom Group tactic (managed-service-provider compromise) tests exactly this. Product:vCISO Lite tracks every practice-management vendor, MSP relationship, and co-counsel with a written agreement, a security questionnaire, and an incident-disclosure clock. When a peer firm’s vendor gets hit, the intelligence flows through the vendor track so the firm’s own notification timing comes from the platform, not from a news cycle.

Operational-resilience tabletops with participant tracking.

Rule:“Reasonable efforts” is not satisfied by a breach playbook that has never been practiced. Carrier retrospectives ask the same question bar counsel does: did the people who would have to execute it know what to do. Product:vCISO Lite runs tabletops with the firm’s actual partners and associates, tracks who participated on what date, and produces the audit artifact that shows practice happened. The artifact is what a carrier and a bar counsel each want to see in the retrospective.

One-page training lessons the firm can distribute.

Rule: MR 1.1 Comment 8 says lawyers shall keep abreast of the benefits and risks of relevant technology. In a firm where an associate has to recognize a physical-intrusion attempt at reception or a vishing call at 8 PM, that duty needs a shareable artifact, not a CLE checkbox. Product: vCISO Lite ships one-page PDFs on physical-security-at-reception, vishing-verify, MSP-risk-signals, and incident-report-within-24-hours. A partner drops one on the staff-meeting agenda and there is evidence of ongoing competence education, without hiring a training vendor.

Our read

Three things we think this pattern makes true, in order of confidence.

One. Physical intrusion isn’t the ceiling, it’s the entry. Call-verification protocols and visitor-authentication procedures at reception will become table-stakes at every firm above ten attorneys inside 18 months, because malpractice carriers will require them at renewal. Right now, the firms that have those protocols wrote them last month, in reaction. That is not a settled posture. The category will keep moving. The next tactic the group is likely to formalize is credentialed remote access via managed-service-provider compromise, because that closes the in-person gap without giving up the “attacker is somewhere else” comfort victims lean on.

Two. Cyber insurance is doing the enforcement work the bar isn’t. The carriers named in public reporting (CNA, Brit, Aon) are the layer with the fastest feedback loop, the clearest financial interest, and the most direct visibility into what a firm has and has not done. Underwriting will price out firms without demonstrable vishing-defense and physical-security controls faster than any state bar will pass a rule. That is a market outcome, not an ethics outcome, but the effect on which firms survive the next 24 months is the same.

Three. “Technology competence” moves from ethical duty to operational discipline. The firms that will survive this next cycle treat MR 1.1 Comment 8 the way they treat conflicts checks. A written protocol. An assigned owner. An audit trail. Not a CLE checkbox and not a partner-lunch conversation. The Silent Ransom Group campaign is the incident that makes the operational treatment of Comment 8 legible to firm leadership as a survival question, not a professional-responsibility niche.

If you are at a firm trying to answer what “reasonable efforts” and “technology competence” look like as an operational program rather than a policy binder, that conversation starts on the vCISO Lite law-firm page.

Primary sources