What happened this month
This is for managing partners and COOs at small and mid-size law firms who think of a data breach as a technology problem that lives with their IT vendor. In the second week of September 2026, two firms with real security budgets, Greenberg Traurig and Eckert Seamans Cherin & Mellott, separately disclosed data breaches within days of each other, and neither started with a firewall failure. Both trace back to social engineering: someone talking their way past a person, not a piece of software. According to Law360 Pulse's coverage of the disclosures, Greenberg Traurig said an unauthorized actor accessed and posted client documents, including Social Security numbers, to the dark web, while stating its own firm systems were never compromised. Eckert Seamans' breach, as teiss reported, stemmed from a social engineering attack that targeted an individual attorney in August 2026 and exposed dates of birth and Social Security numbers; two proposed class actions followed within a week.
That same month, Massachusetts alone logged breach notification filings from four law firms: Eckert Seamans, Abramson Brown & Dugan, Fraser Trebilcock Davis Dunlap & Cavanaugh, and Brown Jake & McDaniel, according to the Massachusetts attorney general's public breach notification list for September 2026. Three of those four are not AmLaw firms with dedicated security operations centers. They are regional shops that look, operationally, like most of the firms reading this.
Why this week matters more than the headline
Firms get breached constantly, so the headline count is not what matters here. What matters is the method: small and mid-size firms are structurally worse positioned to catch it than large ones, and the gap has nothing to do with patch levels or antivirus coverage.
The attack that skips the firewall entirely
The threat actor behind most of the current wave is tracked by the FBI as the Silent Ransom Group, also known as Luna Moth, Chatty Spider, and UNC3753. The FBI's advisory on the group, first published in May 2025 and updated in January 2026, states the group has "consistently targeted US-based law firms" since spring 2023. Its methods do not rely on exploiting software vulnerabilities. They rely on a phone call.
The pattern the FBI describes: an "IT themed social engineering call" comes in, someone claiming to be internal or outsourced IT support. If that gets traction, the group either walks an employee through installing legitimate remote access software (AnyDesk, Splashtop, Zoho Assist, Atera are named in the advisory) or, in a tactic the FBI flagged as active starting in April 2025, sends someone in person, posing as an IT technician, to plug a storage device directly into a firm's computer. Once inside, the group copies files using ordinary tools like WinSCP or a renamed copy of Rclone, then threatens to publish what it took unless paid. No ransomware payload, no encryption, no alarm from endpoint detection tuned to catch malware.
Mandiant's own research, reported by BleepingComputer, found the group hit "dozens of organizations across the legal, financial, and professional services sectors" between January and May 2026 alone, with extortion demands often arriving within 30 minutes of the attackers leaving the victim's environment and a three-day deadline attached. Security firm Halcyon has tracked a ransom demand of $20 million against one law firm in May 2026 tied to the same group's tactics.
Why encryption-era defenses miss it
Most firm security spending over the last decade went toward stopping ransomware that encrypts files: backups, endpoint detection, email filtering. Those controls do real work, but none of them stop a receptionist transferring a call to an attorney who is told their "IT vendor" needs remote access to fix a ticket that was never opened. The control that stops that call is a verification step, and verification steps are a process decision, not a purchase order.
Why small and mid-size firms are the softer target
Greenberg Traurig has a security team large enough to contain its incident to a limited set of documents without touching core systems, according to its own statement to Law360. Most firms in the 10 to 150 timekeeper range do not have that team. They have one managed service provider, sometimes a single generalist contractor, handling everything from password resets to server patching. That arrangement is efficient day to day, but it also means staff are already used to fielding calls from an outside number claiming to be "IT." A caller impersonating that MSP does not sound unusual. It sounds like Tuesday.
This is not a hypothetical gap. The American Bar Association's 2025 Legal Technology Survey found that while 73% of firms now use cloud-based legal tools, only 60% have a formal cybersecurity policy in place at all. That means roughly four in ten firms have no written standard for something as basic as verifying who is calling before granting remote access, which is exactly the gap Silent Ransom Group is built to exploit.
Firm leadership tends to treat this as an IT problem to delegate. It is closer to a front-desk and intake problem: who is allowed to say yes to a remote access request, what they are required to check before saying it, and what happens if they get it wrong. None of that requires a security budget increase. It requires a decision and a two-line script.
Platform sprawl is a security problem, not just an efficiency one
Ask most firm administrators how many vendors have a legitimate reason to call claiming an IT issue, and the honest answer is usually "I'm not sure." Practice management, a separate billing system, a document automation tool, a CRM bolted on for business development, a cloud storage provider, a VoIP phone vendor, an e-discovery platform, each with its own support line and its own login. When a firm runs eight or ten disconnected platforms, staff have no reliable baseline for what a real support call sounds like, because real support calls come from that many different places already.
Consolidating onto fewer, better-integrated platforms with a single identity provider does two things at once. It cuts the number of plausible cover stories a social engineer can use ("this is Clio support," "this is your document automation vendor"), and it lets a firm enforce one verification standard, one multi-factor setup, one login to lock down, instead of ten. That is the same argument for consolidation firms usually hear framed around cost or staff time. Here it is a direct security control.
What a breach actually costs a firm this size
The 2026 Cost of a Data Breach Report, produced by the Ponemon Institute and sponsored by IBM, put the global average cost of a data breach at $4.99 million, a figure that includes detection, notification, legal response, and lost business. A firm with 40 timekeepers is not absorbing a number that size, but the components scale down with the firm, not away from it: forensic investigation, mandatory notification letters like the ones Eckert Seamans and the three smaller Massachusetts firms filed this month, credit monitoring for affected clients, outside counsel to handle the resulting class actions, and the time of every partner who has to explain to a client why their Social Security number is on a dark web listing.
Cyber insurance helps, but only for firms that can show the insurer they had reasonable controls in place at the time of the incident. A policy purchased after a decade of ad hoc vendor additions and no written verification policy is a policy an insurer can contest at claim time. The ABA's own finding, that 40% of firms lack a formal cybersecurity policy, is the exact gap an insurer's claims adjuster will look for first.
Building a verification protocol that holds up
None of the fixes here require new software. They require the firm to write down what already should be true and hold people to it.
For any remote access or "IT support" request
- Require a callback to a number pulled from the firm's own vendor contract, never a number the caller provides.
- Maintain a short, current list of every vendor authorized to request remote access, and check unfamiliar requests against it before granting anything.
- Treat unsolicited calls referencing a "ticket" no one opened as a red flag by default, not an inconvenience to resolve quickly.
For physical office access
- Anyone claiming to be a technician, in person and unscheduled, gets verified by phone with the firm's actual IT contact before touching a machine, no exceptions for people who look the part.
- Disable USB and external storage device access on machines that hold client files, unless a specific business reason requires it.
For the platform layer
- Inventory every platform with a login tied to client data, and note who at the firm can approve support access for each one.
- Move toward a single identity provider with multi-factor authentication enforced everywhere, so there is one login policy to defend instead of ten.
- Ask the firm's cyber insurer, in writing, what controls it expects to see at renewal, and close any gap before the policy lapses rather than after a claim.

