Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
█ Ransomware LUNA-MOTH-LAW 2026-09-13

US Law Firms: Luna Moth Social Engineering and USB Extortion Campaign

"The extortion crew tracked as Luna Moth, Silent Ransom Group (SRG), Chatty Spider, UNC3753 and LeakedData has spent 2025 and 2026 working its way through the US legal sector using telephone calls, fake IT technicians…"

The extortion crew tracked as Luna Moth, Silent Ransom Group (SRG), Chatty Spider, UNC3753 and LeakedData has spent 2025 and 2026 working its way through the US legal sector using telephone calls, fake IT technicians and, in at least some cases, operators who physically walked into law firm offices and plugged in removable storage. The group claims more than 100 attacks since 2022. The FBI has issued two FLASH alerts in roughly 13 months. At least one firm reportedly paid an eight-figure ransom in May 2026, with reported figures ranging from $18 million to $20 million depending on the account. Every source available for this brief is secondary or aggregator tier, and several of the payment figures trace back to a single insurance trade report, so read the numbers below as reported rather than confirmed. The regulatory filings and notification letters quoted inside those reports are the closest thing to primary documentation currently on the public record.

What Happened

The campaign is not a single breach. It is a sustained sector-wide targeting effort that multiple outlets date to at least spring 2023 and that escalated sharply through 2025 and 2026.

Shattered.io reports that the group has claimed more than 100 attacks since 2022 without deploying ransomware code, and that Mandiant documented dozens of organizations breached between January and May 2026 alone. That volume claim originates with the group itself and has not been independently validated in the sources reviewed here.

The named victims across the reporting stack up as follows, with the caveat that most have not confirmed the financial details:

Dark Web Decoded counts Greenberg Traurig as the sixth confirmed or claimed law firm breach in a three-week window tied to the same group.

What Was Taken

No source in this set provides a record count for any individual victim, which is itself notable. The clearest data-type confirmations come from regulator filings quoted secondhand:

The category of material at risk across the sector is consistent across every source: attorney-client privileged communications, litigation strategy, pre-announcement M&A detail, regulatory findings, and PII tied to thousands of client matters. As several outlets note, that material is worth more under extortion threat than it would ever be encrypted.

Why It Matters

This campaign breaks the defensive assumptions most enterprises built over the past decade.

There is no encryption event. There is no ransom note on a locked screen. There is frequently no malware at all. Shattered.io describes the group as operating almost entirely through legitimate remote access and data transfer tooling, the "living off the land" pattern, which means endpoint detection tuned for mass-file-modification behavior never fires. Backups and disaster recovery, the two controls that actually blunted the 2019 to 2023 ransomware wave, are irrelevant against data that has already been copied out.

The economics are brutal for defenders. As vpn.social frames it, a law firm's product is discretion, so the disclosure threat itself carries leverage that a retailer or hospital would not feel as sharply. The reported payments, clustering between roughly $10 million and $20 million, are paid not to restore operations but to avoid publication. Jones Day's apparent refusal of a $13 million demand and Troutman Pepper Locke's alleged $700,000 counteroffer show the negotiation floor is set by the victim's confidentiality exposure, not by downtime cost.

There is also a structural warning in the insurance angle. Aardwolf Security reports the payment figures came from confidential claims data, with named carriers on named layers. Cyber insurance is currently absorbing eight-figure extortion payments for incidents that involved no technical compromise. That is not a sustainable posture, and pricing will follow.

Finally, the single most damning detail in the WilmerHale letter is that the firm's own investigation concluded the third party "did not directly access our systems." A staff member was deceived and handed the data over. There is no patch for that.

The Attack Technique

The tradecraft has escalated in stages, and the progression is well documented across the reporting.

Stage one, callback phishing. The group formed in March 2022 out of the BazarCall phone-scam crew following the Conti collapse. Through early 2025, targets received fake subscription-renewal invoices by email. Each invoice carried a phone number to call and dispute the charge. That call connected the victim to an operator posing as IT support, who talked them into installing legitimate remote access software.

Stage two, direct impersonation. Operators began calling help desks, reception desks and staff directly, skipping the email lure entirely. The FBI alert covered by Hyperlegy describes actors posing as employees of the victim's own IT department. This is the pattern in the WilmerHale disclosure: no exploit, no vendor compromise, no zero-day, just a convincing call on May 8, 2026.

Stage three, physical intrusion. The escalation that prompted the second FBI FLASH alert. Shattered.io reports operators walking into US law firm offices in 2025 and 2026, presenting as IT technicians, and plugging USB devices into workstations. Dark Web Decoded describes the same pattern: physical operators entering offices as IT support and leaving with data on a storage device. Troutman Pepper Locke's own 2025 New Hampshire filing describes a physical intrusion, which is a rare instance of a victim's regulatory language corroborating the actor's methodology.

Attribution is presumed Russia-based on infrastructure and operational patterns, per Shattered.io, but has not been legally confirmed by any government agency in the sources reviewed.

What Organizations Should Do

  1. Break the trust chain on inbound IT contact. No help desk or staff member should act on an unverified inbound call claiming to be internal IT. Establish a mandatory callback to a directory-listed internal number, and make it a fireable-offense-level policy that remote access tooling is never installed at the request of a caller. This is the single control that would have stopped the WilmerHale incident as the firm itself describes it.
  2. Treat visitor and physical access as a security control, not a facilities function. Anyone presenting as an IT technician needs a pre-logged ticket, a named internal sponsor, and escort. The USB-drop vector only works if a stranger can reach a workstation unaccompanied.
  3. Enforce USB and removable media policy at the endpoint. Block mass storage class devices by default across the fleet, allowlist by hardware ID where a business case exists, and alert on any new storage device enumeration. This is a solved technical problem that most firms have simply never turned on.
  4. Alert on legitimate remote access tooling, not just malware. Build detections for the installation or first execution of any RMM or remote support binary that is not on your approved list. Since the group deploys no custom malware, unapproved-but-signed tooling is the highest-value signal available.
  5. Instrument for bulk egress. Monitor document management systems and file shares for anomalous volume access and outbound transfer to cloud storage and file transfer services. Data theft extortion is detectable at the exfiltration stage even when the access itself looked authorized.
  6. Rehearse the extortion-only scenario specifically. Tabletop an incident where nothing is encrypted, systems are fully operational, and the only decision is whether to pay to suppress publication of privileged client material. Settle the legal, regulatory notification and client-communication posture before you are on the clock, and involve your carrier in that exercise.
  7. Train for the pretext, not the phish. Awareness programs built around suspicious links do not cover an operator standing at a desk in a company polo. Run voice and in-person social engineering simulations against reception, help desk and administrative staff.

Sources: Luna Moth: $20M Ransom, 100+ Law Firm Attacks 2026 | WilmerHale and Goodwin Procter Paid Millions After a Ransomware Gan... | HSF Kramer, Mayer Brown Targeted in Latest Law Firm ... | Silent Ransom Group's latest breach exposes extensive law firm data... | Greenberg Traurig Data Breach: SilentRansomGroup Targets Big Law | FBI Alert: Silent Ransom Group Targets Law Firms with In-Person Dat... | WilmerHale Data Breach: No Settlement Yet (Aug 2026) Settlement In... | Luna Moth Hits Jones Day, WilmerHale With $13M Demand — vpn.social