top of page

When Your Law Firm Becomes the Breach Defendant

Aug 28
4 min read

Attorneys spend their careers advising clients on data breaches, regulatory exposure, and litigation risk. This year, a growing number of law firms have had to sit on the other side of that conversation, as the breach defendant rather than breach counsel.


Two developments this month make that shift hard to ignore. A threat intelligence report has confirmed an active campaign built specifically around law firms, and a national firm is now defending itself in a proposed class action over a breach earlier this year. Together, they point to something firm leadership can't treat as purely an IT issue: cybersecurity is now a professional responsibility question.


What's Happening


Google's Mandiant and Google Threat Intelligence Group published a report documenting an active campaign by a group tracked under several names, including Silent Ransom Group, UNC3753, Luna Moth, and Chatty Spider. The report describes a fast-moving data-theft extortion operation aimed specifically at US law firms, along with other professional and financial services organizations.


The FBI has issued its own alert describing the same pattern. The group poses as internal IT support over the phone and through phishing emails, gains access using legitimate remote access tools, and in some cases sends someone in person to a firm's office to physically access computers and remove data with USB storage media. The FBI notes the group has consistently targeted US-based law firms since spring 2023, and frequently skips traditional ransomware encryption altogether, relying on data theft and the threat of publication instead.


Meanwhile, Fox Rothschild, a national law firm, is now facing a proposed class action in federal court alleging the firm failed to protect client names and Social Security numbers exposed in a May breach connected to a well known extortion group. As with any newly filed complaint, the allegations have not been proven in court, but the case illustrates the exposure firms face once client data is compromised.


Why This Is Different for Law Firms


Every business that holds client data has some duty to protect it. Law firms carry an additional, explicit one. Model Rule of Professional Conduct 1.6(c) requires attorneys to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Reasonableness is measured against factors including the sensitivity of the information, the likelihood of disclosure without safeguards, and the cost and difficulty of implementing them.


A breach at a law firm also raises a complication most businesses never face: privilege. Stolen files may include privileged communications and attorney work product. Privilege generally belongs to the client, not the firm, and unauthorized disclosure doesn't automatically waive it. But that doesn't resolve the problem. The firm still has to determine what was accessed, whether protective orders were violated, whether courts need to be notified, and whether its own breach investigation and incident response communications are themselves privileged.


Notification gets complicated fast, too. A firm may hold personal information governed by the laws of dozens of states, protected health information as counsel to a healthcare client, and litigation materials under a protective order, all at once. Notice may be owed to individuals, clients, courts, regulators, insurers, and sometimes opposing counsel. Premature or poorly drafted notice can waive privilege, reveal litigation strategy, or create inconsistent narratives across jurisdictions.


The Attack Methods Aren't Exotic. That's the Problem


None of the tactics behind this campaign require custom malware or a zero-day exploit. Attackers use voice phishing, help-desk impersonation, invoice-themed pretexts, legitimate remote monitoring and screen-sharing tools, and occasionally in-person visits using USB drives to move data out.


Because these are ordinary business tools already in daily use, most firms can't simply block them without disrupting legitimate work. That shifts the real question away from whether a firm has endpoint protection, and toward whether it has a process for verifying IT-support contacts, controlling remote access tools, limiting administrative privileges, and training lawyers and staff to treat an unexpected help-desk call as a possible intrusion attempt.


What Law Firms Should Do Now


  1. Build or update an incident response plan that explicitly addresses privilege, multi-jurisdiction client notification, and coordination between IT, outside breach counsel, and firm leadership, not just system recovery.

  2. Run a tabletop exercise that includes the managing partner, general counsel, IT lead, and outside breach counsel, so responsibilities are clear before an incident, not during one.

  3. Put a written verification protocol in place for anyone calling or emailing as internal IT support, especially requests to install remote access software or share credentials.

  4. Apply phishing-resistant MFA to privileged accounts and enforce least-privilege access to your document management system, so a single compromised login doesn't expose every matter in the firm.

  5. Restrict and log USB device use, and formally approve which remote access and screen-sharing tools are permitted in your environment.

  6. Get an outside cybersecurity assessment now, before a regulator, a client, or a plaintiff's attorney asks whether your firm's safeguards were reasonable.


Model Rule 1.6(c) doesn't require perfect security. It requires firms to take the risk seriously and be able to show they did. As this campaign continues to target the legal industry specifically, the firms best positioned won't be the ones that never get targeted. They'll be the ones that can point to documented, reasonable steps taken before an incident happened.

About Shield IT Networks


Shield IT Networks helps law firms, CPA firms, and other professional service organizations strengthen their cybersecurity, reduce risk, and prepare for evolving regulatory and ethical requirements.


Our Cyber Readiness Assessment identifies vulnerabilities, security gaps, and incident response weaknesses before they become costly problems.


Schedule your Cyber Readiness Assessment today to understand where your firm stands and what needs to be addressed before the next cyber incident occurs.



 
 
 

Comments


Contact

PO Box 801478

Santa Clarita, CA

91380

(800) 711-5522

Be in the Know

Enter your email to be added to our weekly tech tip emails!

Follow us on

  • Facebook
  • LinkedIn

© 2026 by Shield IT Networks, Inc®

bottom of page