All Posts
Cybersecurity

Law Firms Are Ransomware Target #1 in 2026

· Infonaligy

INC Ransom has claimed 20+ law firms this year. Silent Ransom Group is calling front desks pretending to be IT support. What managing partners need to know.

Law firms have become the most targeted professional services sector for ransomware in 2026. INC Ransom, one of the most active ransomware operations this year, has publicly claimed more than 20 law firm victims on its leak site since January. Silent Ransom Group (also tracked as Luna Moth) is running a parallel campaign that skips phishing emails entirely, calling firm front desks and impersonating IT help desk staff to trick employees into granting remote access.

These are not random attacks. Law firms hold exactly what ransomware operators want: privileged client communications, financial records, M&A deal data, litigation strategy, and personal information for hundreds or thousands of clients. The data is high-value, time-sensitive, and covered by confidentiality obligations that make firms more likely to pay.

Why Law Firms Keep Getting Hit

Three characteristics make law firms structurally vulnerable.

Client data concentration. A single firm stores confidential information for every client it has ever represented. One breach exposes not just the firm but every client relationship. Ransomware operators know this creates enormous pressure to pay and to pay quickly, before client notifications become necessary.

Flat network architectures. Many firms still run flat networks where a compromised workstation can reach file shares, document management systems, billing platforms, and email archives without restriction. Once an attacker gets initial access, lateral movement to sensitive data takes hours, not weeks.

Decentralized IT decisions. Partners often choose their own devices, install their own software, and resist security controls they perceive as friction. This creates gaps in endpoint protection, inconsistent patching, and shadow IT that security teams cannot monitor. At smaller firms without dedicated IT staff, the problem compounds. Nobody owns the security posture.

How the Attacks Are Working

INC Ransom primarily gains access through exploiting unpatched VPN appliances and public-facing applications. Once inside, the group uses legitimate IT administration tools already present on the network (like Remote Desktop Protocol, PowerShell, and WMI) to move laterally and avoid triggering antivirus alerts. They exfiltrate data before encrypting, giving them two levers: pay to decrypt and pay to prevent publication. Their average dwell time before encryption is under 72 hours.

Silent Ransom Group uses a different playbook entirely. They call the firm’s main phone number or front desk, identify themselves as the firm’s IT support provider or Microsoft support, and ask the employee to install a remote access tool to “fix a reported issue.” Once the tool is installed, the attacker has legitimate remote access that bypasses every perimeter security control. They then install data exfiltration tools and demand payment to prevent data release, often without encrypting anything. This approach is effective specifically because it exploits trust and helpfulness rather than technical vulnerabilities.

The FBI issued a Private Industry Notification in 2026 specifically warning about Silent Ransom Group’s social engineering campaigns targeting professional services firms.

What Managing Partners Should Do

Treating this as an IT problem alone will not work. This requires firm-level decisions about security investment, staff training, and operational procedures.

Verify Every IT Support Call

Establish a policy that no employee installs software or grants remote access based on an inbound phone call, regardless of who the caller claims to be. If someone calls claiming to be from your IT provider, the employee should hang up and call the provider’s known number directly. This single policy neutralizes Silent Ransom Group’s entire attack method.

Train reception staff, paralegals, and legal assistants specifically. These roles are the primary targets for callback social engineering because they are accustomed to being helpful and responsive.

Segment Your Network

Separate your document management system, billing platform, and client file shares into distinct network segments with access controls between them. A compromised workstation in one segment should not be able to reach data in another without additional authentication. Network segmentation is the single most effective control for limiting the damage from any intrusion.

Deploy EDR With 24/7 Monitoring

Standard antivirus will not detect attackers using built-in Windows tools to move through your network. Endpoint detection and response with a managed SOC watching for suspicious behavior around the clock is what catches INC Ransom’s lateral movement techniques. Look for an MDR provider that can respond in minutes, not hours.

Encrypt and Control Access to Client Data

Encryption at rest and in transit protects client data if files are exfiltrated. Pair it with access controls that limit each attorney and staff member to only the matters they are actively working on. Firms that give everyone read access to the entire document management system are giving attackers the same access.

Test Your Incident Response Plan

If ransomware hits your firm tonight, do you know who makes the first call? Do you know whether your cyber insurance carrier requires pre-approval before engaging a forensics firm? Do you know your state bar’s breach notification requirements? Walk through a tabletop exercise before you need the answers for real.

The Ethics Dimension

ABA Model Rule 1.6© requires lawyers to “make reasonable efforts to prevent the inadvertent or unauthorized disclosure” of client information. State bar associations across the country have issued ethics opinions clarifying that reasonable efforts now include technical security measures, not just locked file cabinets. The Texas Disciplinary Rules of Professional Conduct impose similar obligations.

A firm that suffers a preventable breach faces not just financial and reputational damage but potential ethics complaints from affected clients. Several state bars have already opened investigations into firms that experienced breaches while lacking basic security controls like MFA and encryption.

What This Means for Your Firm

Twenty publicly claimed victims from a single ransomware group in seven months is a pattern, not a coincidence. Law firms that have been treating cybersecurity as a line item to minimize are the ones showing up on leak sites.

The firms that avoid this outcome share common traits: they treat security as a firm management issue (not an IT issue), they invest in managed security services with real-time monitoring, they train every employee on social engineering, and they test their defenses before an attacker does.

Infonaligy works with law firms across the Dallas-Fort Worth area and Texas on security programs built specifically for legal environments, covering endpoint protection, network segmentation, email security, and the compliance requirements that come with handling client data. If your firm has not had a security assessment in the past 12 months, the threat environment has changed enough to warrant one.

Is Your Firm Protected?

Get a security assessment built for law firm environments, covering client data protection, network architecture, and incident response.

Get a Free Assessment

Serving Businesses Across Texas & Oklahoma