A financially motivated extortion crew tracked as Silent Ransom Group (SRG), Luna Moth, Chatty Spider, LeakedData and UNC3753 has spent 2025 and 2026 systematically stripping data out of US law firms without deploying ransomware, without exploiting a vulnerability, and in at least some reported cases without ever touching the network remotely. The campaign is corroborated by two FBI FLASH alerts issued roughly 13 months apart (the most recent in May 2026) and by Mandiant reporting that documented dozens of breached organizations between January and May 2026 alone, per shattered.io's summary of the activity. Public reporting puts the group at more than 100 claimed attacks since 2022. The headline payment sits in a reported range: Law.com reported that Weil Gotshal & Manges paid $20 million to Silent Ransom Group, while Aardwolf Security, citing insurance trade publication The Insurer, put the same May 2026 payment at "between $18 million and $20 million." Reuters has separately confirmed that WilmerHale is facing a federal class action over a 2026 breach involving names and Social Security numbers.
What Happened
The confirmed spine of this story is narrow and worth separating from the reported figures around it.
Confirmed by Reuters: a class action was filed in Washington federal court on July 14, 2026 by Nevada resident Jason Perry against WilmerHale, alleging the firm failed to protect personally identifiable information including names and Social Security numbers. WilmerHale's position, per Reuters, is that the incident was isolated with no evidence of data misuse. Reuters also notes other law firms are facing similar suits in federal courts.
Confirmed via the victims' own words, as quoted by secondary outlets: Settlement Insight quotes WilmerHale's notification letter of July 15, 2026, filed with the Washington State Attorney General, which states that "On May 8, 2026, one of our personnel mistakenly provided information to an unauthorized third party who misrepresented their identity," and that the investigation "determined that this was an isolated incident, and that the third party did not directly access our systems." Mayer Brown issued a materially similar statement to Law.com: "one of our personnel mistakenly sent a small number of documents to an unauthorized third party who misrepresented their identity," with its investigation confirming the third party "did not access our systems." vpn.social reports that Mayer Brown's documents were subsequently published on Luna Moth's extortion leak site, which is the part firms tend not to say out loud.
Reported but not independently confirmed: the payment figures. Aardwolf Security, sourcing The Insurer's August 7 reporting on confidential claims data, states WilmerHale paid at least $18 million (with insurer CNA covering a $10 million primary layer) and Goodwin Procter roughly $10 million (covered through Brit). Neither firm has publicly confirmed those numbers. Law.com's August 11 piece frames it in aggregate, reporting that Weil Gotshal, Goodwin Procter and Wilmer paid "about $50 million ransom in total." Aardwolf also reports Jones Day faced a $13 million demand in April and appears to have refused it. Treat all of these as insurance-press claims, not disclosures.
Accounts differ on framing more than on facts. The victim firms describe discrete, isolated incidents in which a single employee was deceived. The FBI, Mandiant and the trade press describe a sustained campaign against the sector. Both can be true simultaneously, and that gap is itself the story: an "isolated incident" at 100 firms is a campaign.
What Was Taken
There is no single record count in this campaign, because it is not a single breach. What is documented:
- WilmerHale: names and Social Security numbers, obtained "through the course of providing certain legal services," per the firm's notification letter as quoted by Settlement Insight. This is client and matter-related data, not employee HR records. Affected individuals were offered Experian enrollment with a code that expires October 31, 2026. There is no settlement, no claims administrator and no payout as of that reporting.
- Herbert Smith Freehills Kramer: Social Security numbers, government IDs and health records taken from the firm's US office, per Vermont regulatory filings dated July 29, 2026 and reported by Law.com.
- Mayer Brown: a "small number of documents," per the firm, subsequently posted to Luna Moth's leak site per vpn.social.
- Goodwin Procter, Weil Gotshal: breach reported, contents not publicly itemized.
Volume is the wrong metric here. The reason law firms are the target is qualitative: attorney-client privileged material, litigation strategy, M&A detail, regulatory findings and PII across thousands of client matters. shattered.io characterises law firm data as a uniquely coercive asset, and the coercion math is straightforward. A firm can restore encrypted files from backup. It cannot un-publish a client's privileged litigation strategy, and the professional and ethical exposure of that disclosure dwarfs the ransom.
Why It Matters
This campaign breaks the assumptions most ransomware defence programs are built on.
There is no encryption event. There is no malware sample, no C2 beacon, no suspicious binary, no signature to write. The group operates almost entirely with legitimate remote access and data transfer tooling, the pattern usually described as living off the land. Endpoint detection tuned to mass file modification will not fire. Backups, the single highest-value ransomware control, are irrelevant to a pure data-theft extortion model.
It also relocates the attack surface from the network to the staff directory. In the WilmerHale and Mayer Brown accounts, the compromise is a person sending files to someone they believed was authorized. No perimeter was crossed, which is precisely why firms can accurately state that their systems were never accessed while their client data sits on a leak site.
The economics reward repetition. The reported payments suggest an eight-figure yield from an operation whose capital requirement is a phone call, a plausible pretext and, in the escalated cases, a lanyard. CompassMSP notes that Law.com reporting shows attackers deliberately pursuing smaller and mid-size firms, where lower individual payoffs are offset by higher success rates. If your firm is not in the Am Law 100, that is not cover.
Finally, the insurance layer is now visible. The reported CNA and Brit involvement means these payments are being underwritten, which stabilises the group's revenue model and makes the sector a more predictable target, not a less one.
The Attack Technique
The tradecraft escalated in stages, and the sources are consistent on the arc.
Phase one, through early 2025, was callback phishing inherited from the group's BazarCall lineage. Aardwolf Security describes fake subscription renewal invoices sent by email, each carrying a phone number for the victim to call and dispute the charge. The call reached an operator posing as IT support, who talked the victim into installing remote access software. The group formed in 2022 out of that phone-scam crew, following the collapse of the Conti syndicate, per shattered.io.
Phase two inverted the direction. Rather than waiting for a callback, operators call the firm directly, posing as internal IT or as the firm's outsourced IT provider, and walk an employee into granting a remote session or simply sending files.
Phase three is the reason the FBI issued a second FLASH. Per CompassMSP's account of the May 2026 FBI advisory, operators in some cases physically show up at offices while pretending to work for the firm's IT provider, insert a storage device, and copy sensitive data on the spot. shattered.io describes this as USB devices plugged into workstations during 2025 and 2026 in-office visits. Every source describing the in-person USB component is OTHER-tier reporting on the FBI alerts rather than the alerts themselves, so treat the specific mechanics as reported rather than independently verified. The strategic point holds regardless: the group has demonstrated willingness to put a human being inside the building.
Attribution is presumed Russia-based on infrastructure and operational patterns, per shattered.io, and has not been legally confirmed by any government agency.
What Organizations Should Do
- Kill the inbound IT identity assumption. Establish a rule that no one from IT will ever call, email or visit to request credentials, a remote session, or file transmission, and that any such contact must be verified by the employee calling a known internal number independently. Publish it, drill it, and make it explicit that refusing a caller is never a career risk.
- Enforce physical escort and device control. Any technician arriving on site must be verified against a scheduled ticket with the IT provider before entry, and escorted throughout. Pair this with USB mass storage blocking via device control policy on all workstations. This single control defeats the escalated in-person variant outright.
- Instrument for exfiltration, not encryption. Alert on unsanctioned remote access tool installation or execution, on large outbound transfers to consumer file-sharing and cloud storage services, and on anomalous bulk access to document management systems. Your DMS access logs are the highest-value telemetry in this campaign and are frequently unmonitored.
- Restrict bulk document egress by policy. Apply DLP controls to matter data containing SSNs, government IDs and health information, and require secondary approval for bulk exports. In the disclosed incidents, a single employee had the standing ability to send sensitive client data outside the firm with no friction.
- Rehearse the extortion scenario specifically. Backups do not resolve a data-theft extortion event. Run a tabletop that covers leak-site publication, client notification under professional responsibility obligations, multi-state regulator filings (Vermont and Washington filings both surfaced in this campaign), and the payment decision, with counsel and your cyber insurer in the room before the event, not during it.
- Extend all of the above to your MSP and vendors. CompassMSP's framing is correct on the liability point: the firm remains responsible when a vendor is the weak link. Confirm your IT provider's own callback verification and on-site dispatch procedures in writing.
Sources: Luna Moth: $20M Ransom, 100+ Law Firm Attacks 2026 | Law firm WilmerHale sued in class action after data breach | HSF Kramer, Mayer Brown Targeted in Latest Law Firm ... | WilmerHale and Goodwin Procter Paid Millions After a Ransomware Gan... | FBI Alert: Silent Ransom Group Targets Law Firms with In-Person Dat... | What the FBI's Silent Ransom Warning Means for Small ... | WilmerHale Data Breach: No Settlement Yet (Aug 2026) | Mayer Brown Data Leaked by Luna Moth Impersonation Scam — vpn.social