top of page

BigLaw Just Paid $50 Million in Ransom.

Here's What CPA and Law Firms Should Learn From It...


Ransomware doesn't always look like a locked screen and a countdown timer.


Over the past few months, some of the largest law firms in the country, including Weil Gotshal & Manges, WilmerHale, and Goodwin Procter, have reportedly paid a combined total near $50 million to a cyber extortion group. No systems were encrypted. No ransom note appeared on a screen. In each case, the attacker stole client files and threatened to publish them unless paid.


The group behind these attacks, known as Silent Ransom Group, Luna Moth, or Chatty Spider, has been targeting law firms since 2023, and the FBI has issued more than one industry warning about it. The tactics involved are not sophisticated exploits. They are phone calls, impersonation, and social engineering, the same kinds of attacks that can succeed against a firm of any size.


What Happened


Weil Gotshal & Manges reportedly paid between $18 million and $20 million in May, within three days of receiving the demand.


WilmerHale reportedly paid at least $18 million to the same group.


Goodwin Procter reportedly paid around $10 million, marking its third cybersecurity incident since 2021.


Together, these three payments represent close to $50 million paid since May, according to reporting from The Insurer and Law.com. Other firms have been named in connection with related incidents this year, including Jones Day, which reportedly did not pay a $13 million demand, and Fox Rothschild, which now faces a class action related to its breach.


None of these attacks involved encrypting the firm's network. Each firm said its operations continued without disruption. The attacker's leverage wasn't downtime. It was the data itself, and the threat of making it public.


This Isn't the Ransomware You're Picturing


Traditional ransomware locks a network and demands payment to restore access. The damage is immediate and visible. What hit these firms was different: the attacker copied sensitive files, then threatened publication rather than encryption.


The tactics behind it are what should concern every firm, regardless of size. Silent Ransom Group has historically sent mass emails impersonating subscription services, then provided a phone number to call. Callers were then socially engineered into installing remote access software. More recently, the FBI has warned that the group has evolved to impersonating internal IT staff, and in some cases, physically showing up at offices to gain access to devices.


These attacks target people, not infrastructure. Firewalls and endpoint protection can't stop an employee who is convinced they're talking to their own IT department.


Why This Matters Even If You're Not BigLaw


These firms had cyber insurance, outside counsel, and dedicated IT resources most small and mid-sized CPA and law firms don't have. They still ended up negotiating within days of an attack.


Smaller firms aren't safer from this trend. They're often more exposed, with fewer controls in place and less capacity to absorb the cost or negotiate down a demand. The insurance market is already reacting: carriers have reportedly raised law firm premiums 10 to 20 percent at renewal, and at least one major carrier has said it doesn't want new law firm business. That makes coverage harder and more expensive to secure right when firms need it most.


Client data held by CPA and law firms, financial records, privileged communications, Social Security numbers, is exactly what this type of attacker is after.


What CPA and Law Firms Should Do Now


  1. Train every employee who answers phones or fields IT requests to verify identity before granting remote access or making system changes. No caller should be able to talk their way into a device, however convincing they sound.

  2. Put a verification protocol in place for any request that appears to come from internal IT, especially requests involving software installs or credential sharing.

  3. Review how client data is stored and shared, and limit which employees can move files to external or personal cloud storage.

  4. Make sure your incident response plan accounts for data theft and extortion, not just system outages. Suppression payments involve different decisions and different stakeholders than a traditional ransomware event.

  5. Talk to your cyber insurance broker now about how these incidents are underwritten and what your policy actually covers, before a claim is on the table.

  6. Get an outside assessment of your firm's vulnerabilities before an attacker finds them first.


The firms above had far more resources than most CPA and law firms. They still ended up paying within days of an attack. The tactic behind these breaches, social engineering and impersonation, is preventable with the right training and protocols. The firms that stay safest going forward will be the ones that treat this as a today problem, not a someday one.


About Shield IT Networks


Shield IT Networks helps CPA firms, law firms, and other professional service organizations strengthen their cybersecurity, reduce risk, and prepare for evolving threats and regulatory requirements.


Our Cyber Readiness Assessment identifies vulnerabilities, security gaps, and incident response weaknesses before they become costly problems.


Schedule your Cyber Readiness Assessment today to understand where your firm stands and what needs to be addressed before the next cyber incident occurs.



 
 
 

Comments


Contact

PO Box 801478

Santa Clarita, CA

91380

(800) 711-5522

Be in the Know

Enter your email to be added to our weekly tech tip emails!

Follow us on

  • Facebook
  • LinkedIn

© 2026 by Shield IT Networks, Inc®

bottom of page