Professional Services
METRCComplianceSystems Integration

Law firm breaches this month trace back to one phone call, not malware

A phone call, not malware, caused the latest wave of law firm data breaches. Here is what managing partners and firm COOs should change first.

What happened this month

This is for managing partners and COOs at small and mid-size law firms who think of a data breach as a technology problem that lives with their IT vendor. In the second week of September 2026, two firms with real security budgets, Greenberg Traurig and Eckert Seamans Cherin & Mellott, separately disclosed data breaches within days of each other, and neither started with a firewall failure. Both trace back to social engineering: someone talking their way past a person, not a piece of software. According to Law360 Pulse's coverage of the disclosures, Greenberg Traurig said an unauthorized actor accessed and posted client documents, including Social Security numbers, to the dark web, while stating its own firm systems were never compromised. Eckert Seamans' breach, as teiss reported, stemmed from a social engineering attack that targeted an individual attorney in August 2026 and exposed dates of birth and Social Security numbers; two proposed class actions followed within a week.

That same month, Massachusetts alone logged breach notification filings from four law firms: Eckert Seamans, Abramson Brown & Dugan, Fraser Trebilcock Davis Dunlap & Cavanaugh, and Brown Jake & McDaniel, according to the Massachusetts attorney general's public breach notification list for September 2026. Three of those four are not AmLaw firms with dedicated security operations centers. They are regional shops that look, operationally, like most of the firms reading this.

Why this week matters more than the headline

Firms get breached constantly, so the headline count is not what matters here. What matters is the method: small and mid-size firms are structurally worse positioned to catch it than large ones, and the gap has nothing to do with patch levels or antivirus coverage.

The attack that skips the firewall entirely

The threat actor behind most of the current wave is tracked by the FBI as the Silent Ransom Group, also known as Luna Moth, Chatty Spider, and UNC3753. The FBI's advisory on the group, first published in May 2025 and updated in January 2026, states the group has "consistently targeted US-based law firms" since spring 2023. Its methods do not rely on exploiting software vulnerabilities. They rely on a phone call.

The pattern the FBI describes: an "IT themed social engineering call" comes in, someone claiming to be internal or outsourced IT support. If that gets traction, the group either walks an employee through installing legitimate remote access software (AnyDesk, Splashtop, Zoho Assist, Atera are named in the advisory) or, in a tactic the FBI flagged as active starting in April 2025, sends someone in person, posing as an IT technician, to plug a storage device directly into a firm's computer. Once inside, the group copies files using ordinary tools like WinSCP or a renamed copy of Rclone, then threatens to publish what it took unless paid. No ransomware payload, no encryption, no alarm from endpoint detection tuned to catch malware.

Mandiant's own research, reported by BleepingComputer, found the group hit "dozens of organizations across the legal, financial, and professional services sectors" between January and May 2026 alone, with extortion demands often arriving within 30 minutes of the attackers leaving the victim's environment and a three-day deadline attached. Security firm Halcyon has tracked a ransom demand of $20 million against one law firm in May 2026 tied to the same group's tactics.

Why encryption-era defenses miss it

Most firm security spending over the last decade went toward stopping ransomware that encrypts files: backups, endpoint detection, email filtering. Those controls do real work, but none of them stop a receptionist transferring a call to an attorney who is told their "IT vendor" needs remote access to fix a ticket that was never opened. The control that stops that call is a verification step, and verification steps are a process decision, not a purchase order.

Why small and mid-size firms are the softer target

Greenberg Traurig has a security team large enough to contain its incident to a limited set of documents without touching core systems, according to its own statement to Law360. Most firms in the 10 to 150 timekeeper range do not have that team. They have one managed service provider, sometimes a single generalist contractor, handling everything from password resets to server patching. That arrangement is efficient day to day, but it also means staff are already used to fielding calls from an outside number claiming to be "IT." A caller impersonating that MSP does not sound unusual. It sounds like Tuesday.

This is not a hypothetical gap. The American Bar Association's 2025 Legal Technology Survey found that while 73% of firms now use cloud-based legal tools, only 60% have a formal cybersecurity policy in place at all. That means roughly four in ten firms have no written standard for something as basic as verifying who is calling before granting remote access, which is exactly the gap Silent Ransom Group is built to exploit.

Firm leadership tends to treat this as an IT problem to delegate. It is closer to a front-desk and intake problem: who is allowed to say yes to a remote access request, what they are required to check before saying it, and what happens if they get it wrong. None of that requires a security budget increase. It requires a decision and a two-line script.

Platform sprawl is a security problem, not just an efficiency one

Ask most firm administrators how many vendors have a legitimate reason to call claiming an IT issue, and the honest answer is usually "I'm not sure." Practice management, a separate billing system, a document automation tool, a CRM bolted on for business development, a cloud storage provider, a VoIP phone vendor, an e-discovery platform, each with its own support line and its own login. When a firm runs eight or ten disconnected platforms, staff have no reliable baseline for what a real support call sounds like, because real support calls come from that many different places already.

Consolidating onto fewer, better-integrated platforms with a single identity provider does two things at once. It cuts the number of plausible cover stories a social engineer can use ("this is Clio support," "this is your document automation vendor"), and it lets a firm enforce one verification standard, one multi-factor setup, one login to lock down, instead of ten. That is the same argument for consolidation firms usually hear framed around cost or staff time. Here it is a direct security control.

What a breach actually costs a firm this size

The 2026 Cost of a Data Breach Report, produced by the Ponemon Institute and sponsored by IBM, put the global average cost of a data breach at $4.99 million, a figure that includes detection, notification, legal response, and lost business. A firm with 40 timekeepers is not absorbing a number that size, but the components scale down with the firm, not away from it: forensic investigation, mandatory notification letters like the ones Eckert Seamans and the three smaller Massachusetts firms filed this month, credit monitoring for affected clients, outside counsel to handle the resulting class actions, and the time of every partner who has to explain to a client why their Social Security number is on a dark web listing.

Cyber insurance helps, but only for firms that can show the insurer they had reasonable controls in place at the time of the incident. A policy purchased after a decade of ad hoc vendor additions and no written verification policy is a policy an insurer can contest at claim time. The ABA's own finding, that 40% of firms lack a formal cybersecurity policy, is the exact gap an insurer's claims adjuster will look for first.

Building a verification protocol that holds up

None of the fixes here require new software. They require the firm to write down what already should be true and hold people to it.

For any remote access or "IT support" request

  • Require a callback to a number pulled from the firm's own vendor contract, never a number the caller provides.
  • Maintain a short, current list of every vendor authorized to request remote access, and check unfamiliar requests against it before granting anything.
  • Treat unsolicited calls referencing a "ticket" no one opened as a red flag by default, not an inconvenience to resolve quickly.

For physical office access

  • Anyone claiming to be a technician, in person and unscheduled, gets verified by phone with the firm's actual IT contact before touching a machine, no exceptions for people who look the part.
  • Disable USB and external storage device access on machines that hold client files, unless a specific business reason requires it.

For the platform layer

  • Inventory every platform with a login tied to client data, and note who at the firm can approve support access for each one.
  • Move toward a single identity provider with multi-factor authentication enforced everywhere, so there is one login policy to defend instead of ten.
  • Ask the firm's cyber insurer, in writing, what controls it expects to see at renewal, and close any gap before the policy lapses rather than after a claim.
Common questions

Questions worth answering up front.

What is the Silent Ransom Group and why is it targeting law firms?
+

The Silent Ransom Group, also tracked as Luna Moth, Chatty Spider, and UNC3753, is a cybercriminal group that the FBI has documented targeting US law firms since spring 2023. It targets law firms because they hold concentrated, sensitive client data (financial records, personal information, deal terms) and often lack the dedicated security staff of larger enterprises. The group steals data through social engineering rather than encrypting systems, then threatens to publish it unless paid, a method Mandiant's research found hit dozens of legal, financial, and professional services organizations between January and May 2026.

How do vishing and fake IT support scams target law firms?
+

The attacker calls or shows up claiming to be internal or outsourced IT support, often referencing a fabricated support ticket, and asks an employee to install remote access software or grant physical access to a machine. Per the FBI's advisory, tactics escalated in April 2025 to include in-person visits where the attacker poses as a technician and inserts a storage device to copy files directly. The approach works because it targets a person's willingness to be helpful rather than a technical vulnerability, and it leaves no malware for endpoint security tools to catch.

What should a law firm do if someone claiming to be IT support calls or shows up in person?
+

Do not act on the request using any contact information the caller provides. Instead, call the firm's actual, contracted IT vendor back using a number already on file, and confirm whether the ticket or visit is legitimate before granting remote access or allowing physical contact with any machine. Firms should put this callback requirement in writing so front-desk and administrative staff are not making the judgment call alone under time pressure.

Are small and mid-size law firms really at risk, or just large firms like Greenberg Traurig?
+

Small and mid-size firms are often more exposed, not less. Massachusetts's own September 2026 breach notification filings list three regional firms alongside Eckert Seamans, none of them AmLaw-sized. Smaller firms typically rely on a single external IT contractor for support, which makes an impersonation call sound routine rather than suspicious, and the ABA's 2025 survey found 40% of firms have no formal cybersecurity policy at all.

Does consolidating a law firm's software vendors actually reduce breach risk?
+

Yes, in a specific and measurable way. Fewer platforms means fewer plausible "this is your vendor calling" cover stories for a social engineer to use, and it lets a firm enforce one identity and multi-factor authentication standard instead of separately securing every practice management, billing, CRM, and document tool it runs. Consolidation does not eliminate social engineering risk, but it shrinks the number of doors an attacker can claim to be knocking on.

Keep reading

More from the Zerobreak blog

All articles →
eCommerce

Shopify Retired Its REST Catalog API. Your Product Data Now Runs on MCP

Shopify quietly retired its REST Catalog API for MCP-based tools built on UCP. If your product data isn't structured for it, agents won't find it.

Cannabis

New York moves cannabis credit and delinquency reporting into Metrc

New York just moved its cannabis credit rules inside Metrc, and a new public dashboard runs on the same data. Here is what operators need to know.

Professional Services

The efficiency paradox starts at your front door

Your firm adopted AI and got faster. The prospect who called Thursday at 4:47 still got voicemail. Here is where the growth leaks, and what to fix in what order.