Field note · Incident study
The Threat Actor That Walked Into BigLaw's Front Door
In 2026, a threat actor tracked as Silent Ransom Group (also known as Luna Moth, and as UNC3753 in Google’s naming) extorted a string of US law firms. WilmerHale paid roughly $18 million. Goodwin Procter paid roughly $10 million, its third breach in five years. Weil Gotshal paid between $18 and $20 million. Jones Day appears to have refused a $13 million demand and lost the contents of ten client matters. Herbert Smith Freehills Kramer, Mayer Brown, and Taft were all named victims. The FBI issued a Private Industry Notification about the group in May 2025, then a second in May 2026.
Some of them never saw a network attack. In late 2025, the group’s operators started showing up at law-firm offices in person, saying they were from IT, sitting down at a workstation, and plugging in a USB device. The industry read is that ransomware is getting worse. That’s true. The durable read is that the profession’s ethical rules (confidentiality, breach notification, technology competence) were written for a threat model where the attacker was somewhere else. In 2026, the attacker is at reception.
The playbook
Three stages, over three years. Every stage keeps the tactics that worked, sheds the friction that didn’t, and moves closer to the desk where the material actually lives.
March 2022 → early 2025 · Callback phishing
Fake subscription-renewal invoices with a phone number to call. The victim initiates contact. That single detail sidesteps most email-security tooling, because there is no malicious link to score and no attachment to detonate. The follow-up call establishes rapport, then walks the victim through a remote-support session that installs exfiltration tooling. Efficient and low-signal, but slow: acquisition cost per victim was high because the pretext needed the victim’s own imagination to complete.
March 2025 · Direct vishing, IT impersonation
The group compressed the funnel by calling directly, on the employee’s personal cellphone, and impersonating internal IT. Pretext was uniform: an urgent security migration required the employee to re-authenticate. The FBI issued its first Private Industry Notification about the tactic in May 2025. What made it productive was the target environment. BigLaw associates take calls from unfamiliar numbers as a matter of course, sit on personal devices during transactions, and route many operational asks through informal channels because that is what deal cadence requires.
April 2025 → present · In-person physical intrusion
The tactic that generated the second FBI advisory in May 2026. An operator walks into a law-firm office, presents as a contracted IT technician, sits down at a workstation, and plugs in a storage device to exfiltrate material. No network intrusion in the traditional sense: no phishing landing page, no vulnerable server, no lateral-movement trace. What the physical tactic buys the attacker is direct access to the material an associate has open on their desktop, meaning current-matter documents, the discovery cache, the memo in progress. What it buys the defender is nothing, because nothing in a modern SIEM is looking for a man at reception with a lanyard.
Why law firms became the target class
Four properties, all of them structural to the profession, make law firms an efficient target for this specific tactic.
One. Concentration of privileged material. A mid-size firm doing a normal week’s work is holding dozens of active matters at some depth: discovery caches, deposition prep, settlement math, board-communication files. That is the exact material extortion pricing is built to monetize. The threat actor does not have to be selective. Almost every document has either a buyer or a leverage value.
Two. Insurance appetite absorbs the pricing signal. Public reporting via The Insurer names CNA as WilmerHale’s primary cyber insurer and Brit as Goodwin Procter’s, with Aon brokering the placement. Carriers pay the ransoms, subrogate what they can, and price the next renewal. From the attacker’s perspective, this is a market with a functioning clearing mechanism. Extortion demands in the $10 to $20 million range are large enough to be serious and small enough that the carrier will authorize settlement rather than fight through discovery. That is a predictable payout curve.
Three. Deal workflows normalize what would look abnormal elsewhere. M&A cadence normalizes urgent off-hours requests, personal-device use, and informal escalation. A call from an unknown number at 8 PM claiming an urgent security migration is not culturally out of place in a firm running six transactions to close. The tactics that would trip a control at a bank read as ordinary friction at a firm.
Four. Mid-firms have less to spend on defense than BigLaw and more to lose than a solo. Law.com’s mid-market coverage in May 2026 explicitly names midsize and smaller firms as the growth segment for these incidents. BigLaw is spending its way into stronger controls, so the pressure is migrating downward. The firm-size distribution of ransomware victims is going to skew smaller through 2027.
Where the ABA ethical rules meet the tactic
Three rules, one for each face of the incident. Every firm hit this year was already bound by all three, and the rules already contemplated the possibility of exactly the situation the firms are now in.
The rules were written for a threat model where the attacker was somewhere else. In 2026, the attacker is at reception.
The ethical duties do not shift when the tactic does. The evidence of “reasonable efforts” that a bar counsel or a malpractice carrier will ask for very much has.
What vCISO Lite does for a firm facing this tactic
vCISO Lite is a compliance, evidence, and vCISO-advisory platform. For a law firm, it stands up the InfoSec program the ABA rules assume the firm already has, and produces the artifact a bar counsel or a malpractice carrier will ask to see.
The stack layer that would stop a USB device the moment it plugs in is a different stack layer than the compliance-and-evidence one. That is a purchase a firm makes separately.
When a breach is in progress, a firm needs an IR retainer with a paging phone number. vCISO Lite is what the retainer works from, not the retainer itself.
Rule: MR 1.6(c) requires reasonable efforts to prevent unauthorized access to client information. That standard is tested at incident post-mortem, when a bar counsel or a malpractice carrier asks what the firm had in place before the breach. Product:vCISO Lite ships a written InfoSec policy owned by a named partner, control-by-control evidence the policy is operating on the date in question, and an attestation trail on a defensible cadence. When Formal Op 483’s notification duty triggers, the client-by-client list and material-sensitivity classification are already in the platform, ready to run.
Rule: MR 1.6 confidentiality runs to every subcontractor with access to client material, and Formal Op 483 starts a notification clock on any vendor breach that touches client data. The likely next Silent Ransom Group tactic (managed-service-provider compromise) tests exactly this. Product:vCISO Lite tracks every practice-management vendor, MSP relationship, and co-counsel with a written agreement, a security questionnaire, and an incident-disclosure clock. When a peer firm’s vendor gets hit, the intelligence flows through the vendor track so the firm’s own notification timing comes from the platform, not from a news cycle.
Rule:“Reasonable efforts” is not satisfied by a breach playbook that has never been practiced. Carrier retrospectives ask the same question bar counsel does: did the people who would have to execute it know what to do. Product:vCISO Lite runs tabletops with the firm’s actual partners and associates, tracks who participated on what date, and produces the audit artifact that shows practice happened. The artifact is what a carrier and a bar counsel each want to see in the retrospective.
Rule: MR 1.1 Comment 8 says lawyers shall keep abreast of the benefits and risks of relevant technology. In a firm where an associate has to recognize a physical-intrusion attempt at reception or a vishing call at 8 PM, that duty needs a shareable artifact, not a CLE checkbox. Product: vCISO Lite ships one-page PDFs on physical-security-at-reception, vishing-verify, MSP-risk-signals, and incident-report-within-24-hours. A partner drops one on the staff-meeting agenda and there is evidence of ongoing competence education, without hiring a training vendor.
Our read
Three things we think this pattern makes true, in order of confidence.
One. Physical intrusion isn’t the ceiling, it’s the entry. Call-verification protocols and visitor-authentication procedures at reception will become table-stakes at every firm above ten attorneys inside 18 months, because malpractice carriers will require them at renewal. Right now, the firms that have those protocols wrote them last month, in reaction. That is not a settled posture. The category will keep moving. The next tactic the group is likely to formalize is credentialed remote access via managed-service-provider compromise, because that closes the in-person gap without giving up the “attacker is somewhere else” comfort victims lean on.
Two. Cyber insurance is doing the enforcement work the bar isn’t. The carriers named in public reporting (CNA, Brit, Aon) are the layer with the fastest feedback loop, the clearest financial interest, and the most direct visibility into what a firm has and has not done. Underwriting will price out firms without demonstrable vishing-defense and physical-security controls faster than any state bar will pass a rule. That is a market outcome, not an ethics outcome, but the effect on which firms survive the next 24 months is the same.
Three. “Technology competence” moves from ethical duty to operational discipline. The firms that will survive this next cycle treat MR 1.1 Comment 8 the way they treat conflicts checks. A written protocol. An assigned owner. An audit trail. Not a CLE checkbox and not a partner-lunch conversation. The Silent Ransom Group campaign is the incident that makes the operational treatment of Comment 8 legible to firm leadership as a survival question, not a professional-responsibility niche.
If you are at a firm trying to answer what “reasonable efforts” and “technology competence” look like as an operational program rather than a policy binder, that conversation starts on the vCISO Lite law-firm page.
Primary sources
- The Insurer · Goodwin Procter paid around $10M ransom to Luna Moth, with Brit lead (Aug 7, 2026)
- Aardwolf Security · WilmerHale, Goodwin, Weil Gotshal, Jones Day ransom figures (2026)
- Halcyon · Silent Ransom Group’s active use of physical intrusion against US law firms
- ABA Journal · Goodwin Procter 2021 breach precedent
- Emery Reddy · Goodwin Procter’s third breach in five years, with Texas AG filing detail
- JD Journal · Herbert Smith Freehills Kramer and Goodwin Procter breach disclosures (Aug 10, 2026)
- FBI IC3 · Silent Ransom Group targeting law firms, Private Industry Notification (May 2025, with 2026 follow-up)
- Law.com Pro Mid-Market · Midsize and smaller law firms facing more data breach threats (May 7, 2026)
