The extortion crew tracked as Luna Moth, Silent Ransom Group (SRG), Chatty Spider, UNC3753 and LeakedData has spent 2025 and 2026 working its way through the US legal sector using telephone calls, fake IT technicians and, in at least some cases, operators who physically walked into law firm offices and plugged in removable storage. The group claims more than 100 attacks since 2022. The FBI has issued two FLASH alerts in roughly 13 months. At least one firm reportedly paid an eight-figure ransom in May 2026, with reported figures ranging from $18 million to $20 million depending on the account. Every source available for this brief is secondary or aggregator tier, and several of the payment figures trace back to a single insurance trade report, so read the numbers below as reported rather than confirmed. The regulatory filings and notification letters quoted inside those reports are the closest thing to primary documentation currently on the public record.
What Happened
The campaign is not a single breach. It is a sustained sector-wide targeting effort that multiple outlets date to at least spring 2023 and that escalated sharply through 2025 and 2026.
Shattered.io reports that the group has claimed more than 100 attacks since 2022 without deploying ransomware code, and that Mandiant documented dozens of organizations breached between January and May 2026 alone. That volume claim originates with the group itself and has not been independently validated in the sources reviewed here.
The named victims across the reporting stack up as follows, with the caveat that most have not confirmed the financial details:
- WilmerHale. Settlement Insight quotes the firm's own notification letter, dated July 15, 2026 and filed with the Washington State Attorney General: "On May 8, 2026, one of our personnel mistakenly provided information to an unauthorized third party who misrepresented their identity." The letter states the investigation "determined that this was an isolated incident, and that the third party did not directly access our systems." Aardwolf Security reports the firm paid at least $18 million; Settlement Insight characterizes the same $18 million figure as an unconfirmed insurance-press report. A class action has been filed in Washington, D.C. There is no settlement and no claims administrator; the only live deadline is an Experian enrollment code that expires October 31, 2026.
- Goodwin Procter. Aardwolf Security reports a payment of roughly $10 million, sourced to confidential claims data reported by insurance trade publication The Insurer on 7 August. Coverage reportedly came through Brit; WilmerHale's $10 million primary layer was reportedly covered by CNA. Neither firm has publicly confirmed the figures.
- Weil Gotshal. Aardwolf Security reports a payment of between $18 million and $20 million in May. Shattered.io separately describes a $20 million payment by an unnamed victim in May 2026. These are most plausibly the same event described at different points in a reported range, but the sources do not explicitly link them, and the $20 million headline figure sits at the top of that range rather than being an independently confirmed number.
- Jones Day. Faced a $13 million demand in April and, per Aardwolf Security, appears to have refused it.
- Troutman Pepper Locke. Noah Intelligence reports SRG claimed a fresh remote intrusion on 7 August 2026. The same reporting, citing DataBreaches, notes the firm disclosed an April 2025 incident to New Hampshire regulators in July 2025, describing it as a physical intrusion involving a single laptop and stating its systems were secure. SRG now alleges that account is incomplete, claims it accessed a broader set of corporate files, and says negotiations collapsed after the firm allegedly offered $700,000. Accounts here genuinely conflict: the firm's regulatory characterization and the threat actor's claim cannot both be complete, and the actor has an obvious incentive to inflate.
- Greenberg Traurig. Dark Web Decoded reports the firm confirmed a breach to the Vermont Attorney General on September 8, 2026, six days after SRG posted its data to the group's leak site on September 2. The filing identifies Social Security numbers as exposed and names 10 Vermont residents. The firm separately confirmed to Reuters that "limited data" had been posted. Total affected individuals have not been published.
- HSF Kramer and Mayer Brown. A Law.com headline indicates both were targeted in the same wave. The article body was not retrievable, so treat this as a targeting signal only, with no confirmed outcome, scope or payment.
Dark Web Decoded counts Greenberg Traurig as the sixth confirmed or claimed law firm breach in a three-week window tied to the same group.
What Was Taken
No source in this set provides a record count for any individual victim, which is itself notable. The clearest data-type confirmations come from regulator filings quoted secondhand:
- WilmerHale's notification letter says the exposed information "was obtained through the course of providing certain legal services and may have included your name and Social Security Number." That framing matters: this is client and legal-matter data, not employee HR records.
- Greenberg Traurig's Vermont filing confirms Social Security numbers and 10 Vermont residents. As Dark Web Decoded points out, Greenberg Traurig has no Vermont office, so that number is a regulatory floor reflecting one jurisdiction's notification threshold, not a scope estimate. The true total is unpublished.
- Troutman Pepper Locke's 2025 New Hampshire disclosure described a single laptop. SRG disputes that, claiming a broader corporate file set. Unresolved.
The category of material at risk across the sector is consistent across every source: attorney-client privileged communications, litigation strategy, pre-announcement M&A detail, regulatory findings, and PII tied to thousands of client matters. As several outlets note, that material is worth more under extortion threat than it would ever be encrypted.
Why It Matters
This campaign breaks the defensive assumptions most enterprises built over the past decade.
There is no encryption event. There is no ransom note on a locked screen. There is frequently no malware at all. Shattered.io describes the group as operating almost entirely through legitimate remote access and data transfer tooling, the "living off the land" pattern, which means endpoint detection tuned for mass-file-modification behavior never fires. Backups and disaster recovery, the two controls that actually blunted the 2019 to 2023 ransomware wave, are irrelevant against data that has already been copied out.
The economics are brutal for defenders. As vpn.social frames it, a law firm's product is discretion, so the disclosure threat itself carries leverage that a retailer or hospital would not feel as sharply. The reported payments, clustering between roughly $10 million and $20 million, are paid not to restore operations but to avoid publication. Jones Day's apparent refusal of a $13 million demand and Troutman Pepper Locke's alleged $700,000 counteroffer show the negotiation floor is set by the victim's confidentiality exposure, not by downtime cost.
There is also a structural warning in the insurance angle. Aardwolf Security reports the payment figures came from confidential claims data, with named carriers on named layers. Cyber insurance is currently absorbing eight-figure extortion payments for incidents that involved no technical compromise. That is not a sustainable posture, and pricing will follow.
Finally, the single most damning detail in the WilmerHale letter is that the firm's own investigation concluded the third party "did not directly access our systems." A staff member was deceived and handed the data over. There is no patch for that.
The Attack Technique
The tradecraft has escalated in stages, and the progression is well documented across the reporting.
Stage one, callback phishing. The group formed in March 2022 out of the BazarCall phone-scam crew following the Conti collapse. Through early 2025, targets received fake subscription-renewal invoices by email. Each invoice carried a phone number to call and dispute the charge. That call connected the victim to an operator posing as IT support, who talked them into installing legitimate remote access software.
Stage two, direct impersonation. Operators began calling help desks, reception desks and staff directly, skipping the email lure entirely. The FBI alert covered by Hyperlegy describes actors posing as employees of the victim's own IT department. This is the pattern in the WilmerHale disclosure: no exploit, no vendor compromise, no zero-day, just a convincing call on May 8, 2026.
Stage three, physical intrusion. The escalation that prompted the second FBI FLASH alert. Shattered.io reports operators walking into US law firm offices in 2025 and 2026, presenting as IT technicians, and plugging USB devices into workstations. Dark Web Decoded describes the same pattern: physical operators entering offices as IT support and leaving with data on a storage device. Troutman Pepper Locke's own 2025 New Hampshire filing describes a physical intrusion, which is a rare instance of a victim's regulatory language corroborating the actor's methodology.
Attribution is presumed Russia-based on infrastructure and operational patterns, per Shattered.io, but has not been legally confirmed by any government agency in the sources reviewed.
What Organizations Should Do
- Break the trust chain on inbound IT contact. No help desk or staff member should act on an unverified inbound call claiming to be internal IT. Establish a mandatory callback to a directory-listed internal number, and make it a fireable-offense-level policy that remote access tooling is never installed at the request of a caller. This is the single control that would have stopped the WilmerHale incident as the firm itself describes it.
- Treat visitor and physical access as a security control, not a facilities function. Anyone presenting as an IT technician needs a pre-logged ticket, a named internal sponsor, and escort. The USB-drop vector only works if a stranger can reach a workstation unaccompanied.
- Enforce USB and removable media policy at the endpoint. Block mass storage class devices by default across the fleet, allowlist by hardware ID where a business case exists, and alert on any new storage device enumeration. This is a solved technical problem that most firms have simply never turned on.
- Alert on legitimate remote access tooling, not just malware. Build detections for the installation or first execution of any RMM or remote support binary that is not on your approved list. Since the group deploys no custom malware, unapproved-but-signed tooling is the highest-value signal available.
- Instrument for bulk egress. Monitor document management systems and file shares for anomalous volume access and outbound transfer to cloud storage and file transfer services. Data theft extortion is detectable at the exfiltration stage even when the access itself looked authorized.
- Rehearse the extortion-only scenario specifically. Tabletop an incident where nothing is encrypted, systems are fully operational, and the only decision is whether to pay to suppress publication of privileged client material. Settle the legal, regulatory notification and client-communication posture before you are on the clock, and involve your carrier in that exercise.
- Train for the pretext, not the phish. Awareness programs built around suspicious links do not cover an operator standing at a desk in a company polo. Run voice and in-person social engineering simulations against reception, help desk and administrative staff.
Sources: Luna Moth: $20M Ransom, 100+ Law Firm Attacks 2026 | WilmerHale and Goodwin Procter Paid Millions After a Ransomware Gan... | HSF Kramer, Mayer Brown Targeted in Latest Law Firm ... | Silent Ransom Group's latest breach exposes extensive law firm data... | Greenberg Traurig Data Breach: SilentRansomGroup Targets Big Law | FBI Alert: Silent Ransom Group Targets Law Firms with In-Person Dat... | WilmerHale Data Breach: No Settlement Yet (Aug 2026) Settlement In... | Luna Moth Hits Jones Day, WilmerHale With $13M Demand — vpn.social