Global law firm Greenberg Traurig confirmed to Vermont's Attorney General on September 8, 2026 that an unauthorized actor accessed firm documents and that the stolen material included Social Security numbers. The ransomware operation SilentRansomGroup had already published the firm on its dark web leak site on September 2, roughly six days before the regulatory filing. Reuters reported on September 10 that the firm characterised the exposure as "limited" data. No total number of affected individuals has been published, and the two state filings that are public point in noticeably different directions on scale: the Vermont notice names 10 residents, while a California filing dated the incident to August 26, 2026 and triggered that state's sample-notification requirement, which applies only when more than 500 California residents are notified.
What Happened
The timeline that emerges across the sources is tight. Greenberg Traurig detected suspicious activity on its network and determined that files may have been accessed or acquired by an unauthorized actor on August 26, 2026, the date listed in the California Attorney General filing reported by breachnews.com and repeated in a class action investigation notice from Migliaccio & Rathod. SilentRansomGroup posted the firm to its .onion leak site on September 2. Security Arsenal, monitoring the leak site via ransomware.live, recorded the listing as one of four victims posted in a 48-hour window spanning September 1 and 2, alongside fellow AmLaw firm Holland & Knight (published September 1) and two partially redacted entries the analysts transcribed as "G... ...g" and "S... M...". Breach House, which indexes leak-site listings, logged the Greenberg Traurig entry on September 2 and confirmed leak status on September 4, with a two-day "exposure gap" before public acknowledgement.
Notification to affected individuals went out on September 8, per the Migliaccio & Rathod notice, the same date as the Vermont filing. California received its report on September 9. Reuters published the firm's public comment on September 10.
Greenberg Traurig's own framing is narrow. The firm has said the incident touched a limited number of documents associated with a small number of clients, and that its broader systems were not compromised. That claim sits alongside a regulatory record establishing Social Security number exposure, and the two are not contradictory: a small document set can carry concentrated, high-sensitivity PII. Readers should note the firm has not released a nationwide figure, so the true scope is unestablished rather than small.
One data point worth discounting: the Breach House record lists the victim's employee count as 51 to 100. Greenberg Traurig employs more than 2,600 attorneys across dozens of offices worldwide, per NILE1. Leak-site-derived metadata is frequently wrong on firmographics and should not be used to size a victim.
What Was Taken
The only verified data category is Social Security numbers, identified in the Vermont Attorney General filing and corroborated by Reuters, breachnews.com, NILE1 and vpn.social. The Vermont filing names 10 affected Vermont residents. That number is a regulatory floor, not a ceiling. As darkwebdecoded.com points out, Greenberg Traurig has no Vermont office, so those 10 individuals are most plausibly employees, clients or third parties connected to legal matters rather than a local client base, which tells you the exposed population is distributed by matter, not by geography.
Migliaccio & Rathod, a plaintiffs' firm investigating potential class claims, lists the impacted data as Social Security numbers, names, contact information and dates of birth. Only the SSN element is confirmed by the primary regulatory record; treat names, contact details and dates of birth as claimed by a single interested source rather than established.
On volume, the accounts genuinely diverge and none of them resolve it. Vermont: 10 residents. California: a sample notification requirement that implies at least 500 residents in that state alone. The firm: "limited" data, a "small number" of clients. Nationwide total: not disclosed by any source. Anyone citing a single headline number for this breach is inventing it.
Breach House's leak gallery listing references generic file types of the kind SilentRansomGroup typically stages as proof material, including file trees, financial spreadsheets, passport scans and executed contracts, but that index presents these as a sample illustration rather than a verified inventory of the Greenberg Traurig listing, and the actual screenshots sit behind a login. The substantive risk is structural: as vpn.social and NILE1 both note, a law firm's document store aggregates deal terms, litigation strategy, intellectual property and personal identifiers belonging to clients, corporate executives and high-net-worth individuals who never had a direct relationship with the firm's security program.
Why It Matters
This is not a single-victim story. Darkwebdecoded.com counts Greenberg Traurig as the sixth confirmed or claimed law firm breach in three weeks tied to the same operation. Security Arsenal's leak-site telemetry independently supports a concentrated campaign: four victims in 48 hours, 100% US-based, 50% confirmed professional services. NILE1 adds the surrounding disclosures, with Goodwin Procter reporting a cybersecurity incident on August 7 and Quinn Emanuel Urquhart & Sullivan disclosing a social engineering attack on August 14.
The targeting logic is explicit. Security Arsenal assesses that legal-sector victims face extreme extortion leverage because breach disclosure obligations and attorney-client privilege concerns compress negotiation timelines, a defender is effectively negotiating with a clock that the regulator, not the attacker, is running. Attackers also increasingly go after outside counsel instead of the fortified corporate network the counsel serves, which makes every law firm a lateral path into its entire client roster.
The trend data supports it. NILE1 cites BakerHostetler's 2026 Data Security Incident Response Report, drawn from more than 1,250 incidents in 2025, which found that firm's law-firm incident caseload nearly doubled year over year to roughly 60 matters, with phishing accounting for 30% of all incidents analysed and human error and social manipulation remaining the most common entry points.
The Attack Technique
Initial access at Greenberg Traurig has not been confirmed by the firm or by any regulatory filing. What follows is campaign-level attribution and should be read as such.
Security Arsenal profiles SILENTRANSOMGROUP as a ransomware-as-a-service operation with a vetted affiliate base, where the core team maintains the encryptor, leak site and negotiation infrastructure while affiliates carry out intrusion and deployment. It assesses ransom demands in the USD $1M to $10M band for mid-market professional services, with AmLaw-tier legal targets expected at the top of that range. The analysts note overlapping tooling and leak-site infrastructure suggesting lineage ties to former Silence and BlackCat-adjacent affiliate ecosystems, but flag that link at only moderate confidence. The batch posting of four victims in two days is consistent with disclosure following failed negotiations.
Darkwebdecoded.com reports that the group has escalated from telephone-based social engineering, callback pretexting against help desks and staff, to sending physical operators into law firm offices posing as IT support and exfiltrating data onto a storage device. That is the most operationally significant claim in the entire source set and it appears in only one OTHER-tier source. It is uncorroborated by Reuters, by any regulatory filing, or by Security Arsenal's leak-site analysis. Treat it as a reported claim to validate, not as established tradecraft, though it aligns with the broader pattern of human-layer attacks documented in the BakerHostetler figures and with the confirmed social engineering vector in the Quinn Emanuel incident.
What Organizations Should Do
- Harden the help desk against voice and in-person pretexting. Require verification that cannot be socially engineered before any credential reset, MFA re-enrolment or device enrolment, ideally a callback to a number of record or manager approval through a separate channel. This closes both the confirmed vector in the Quinn Emanuel disclosure and the escalation darkwebdecoded.com describes.
- Enforce physical identity verification for anyone claiming IT or vendor status. Badge checks, escort requirements, pre-registered vendor visits, and a standing rule that no unscheduled "IT support" touches an endpoint. Brief reception and floor staff directly, since they are the control point.
- Block and alert on mass USB and removable-media writes from workstations and file servers. If the physical-operator technique is real, exfiltration to a storage device is the final step and is detectable at the endpoint even when nothing crosses the network perimeter.
- Instrument document repositories for bulk access anomalies. Alert on unusual volumes of matter files opened, downloaded or synced by a single account, especially outside that user's normal practice groups or hours. Security Arsenal's published detection rules and hunting queries for this campaign are a reasonable starting point.
- Segment client matter data and apply least privilege by matter, not by firm. A limited-document incident stays limited only when one compromised identity cannot reach the whole document management system.
- Pre-stage the regulatory response. Know your Vermont, California and sector-specific notification thresholds before an incident, map which matters contain SSNs and other regulated identifiers, and prepare client notification language in advance. The compressed disclosure clock is the attacker's leverage; removing the scramble removes some of it.
- Assume outside counsel is in scope for third-party risk. Inventory which firms hold your regulated data, require breach notification terms in engagement letters, and ask about MFA, help-desk verification and data retention before the next matter opens.
Sources: Greenberg Traurig Data Breach: SilentRansomGroup Targets Big Law | Law firm Greenberg Traurig says 'limited' data posted to dark web a... | Greenberg Traurig Confirms Data Breach, Files Leaked | SILENTRANSOMGROUP Ransomware Campaign: 4 Victims Posted in 48 Hours... | Greenberg Traurig Data Breach Investigation - M&R | Greenberg Traurig Joins Legal Sector’s Dark-Web Breach Wave - NILE1 | Greenberg Traurig Confirms Data Breach, SSNs Leaked Online — vpn.so... | Greenberg Traurig — SILENTRANSOMGROUP Ransomware Attack Breach House