Silent Ransom Group (SRG), also tracked as Luna Moth and Chatty Spider, added Sheppard, Mullin, Richter & Hampton LLP to its leak site on October 5, 2026, with a $4.9 million figure tied to stopping the publication of data. Sheppard Mullin has not confirmed the claim. Three days earlier, though, the firm filed breach notices with the California and Vermont Attorneys General. Those notices disclosed that on August 31, 2026, one of its attorneys fell for a "sophisticated social engineering event" and documents went to an unknown third party. The two events fit together, since SRG's known method is to socially engineer law firm staff. Still, no source we reviewed confirms they are the same incident, and the firm's notices do not name an actor.
What Happened
What the firm has disclosed. Several sources quote the notice the firm filed with the California AG. Severity Daily, AcidPeak and Class Action U all say it is dated October 2, 2026 and printed on the firm's Los Angeles letterhead. According to the notice:
- On August 31, 2026, "a single Sheppard attorney was the victim of a sophisticated social engineering event which resulted in the unauthorized disclosure of certain documents to an unknown third-party."
- The firm learned of it on September 1, called in outside forensic help, and notified law enforcement.
- It says the incident "was limited to this individual" and that there was no unauthorized access to, or compromise of, its systems or network (AcidPeak, Class Action U).
- A parallel Vermont filing counts 21 Vermont residents. Neither filing gives a total number of affected people (AcidPeak).
Severity Daily also notes that Sheppard Mullin was one of four professional services firms to appear on California's breach list on October 1 and 2. The others were Aldrich, Greenberg Traurig and Fragomen. In each of the three notices Severity Daily could read, the entry point was a single compromised account.
What the threat actor claims. On October 5, ransomware trackers indexed an SRG listing for the firm (Today In Cyber via Ransomware Live, Breach House, CyberThreatIntelligence.net). The sources describe that listing differently:
- The $4.9M figure. Today In Cyber and one Undercode News piece call it a ransom demand. A second Undercode piece says the listing claims the firm offered $4.9M to stop publication, and notes that the wording leaves unclear whether this was a demand, a negotiated amount, or a victim offer. One Undercode headline says "9 Million," but its own body says $4.9M, so the headline looks like a typo.
- Proof of data. Undercode News says the listing shows no samples, file tree or screenshots. Breach House marks the leak status "leaked" and says a captured screenshot shows a download link. We have not verified what is behind that link. The two accounts conflict.
- A second law firm. Undercode News reports that SRG listed Nelson Mullins Riley & Scarborough at the same time, with an alleged $8M figure. That claim is also unverified.
What Was Taken
The firm has not said what was taken. Its notice says it is still running a "thorough and time-intensive analysis of the impacted files to determine what personal information they contained and to whom that information belongs." Class Action U notes that many people receiving the letters were never clients. Their data reached the firm through client matters, transactions or disputes.
SRG has published no data volume or data types. The only hard number in any source is the 21 Vermont residents from the state filing. Because the files belong to a law firm, they may include privileged client communications, deal documents and litigation material, but that is a risk assessment, not something the firm has confirmed.
Affected individuals are being offered 24 months of TransUnion credit monitoring through Cyberscout, with $1M in identity theft insurance. The enrollment deadline is December 31, 2026 (Severity Daily).
Why It Matters
- Law firms are SRG's core target. SRG goes after law firms specifically. Their client data is valuable for extortion, and staff can be talked into granting access. A timing link between an August social engineering breach and an October leak-site listing is consistent with how SRG usually works.
- "No systems compromised" can still mean data was lost. The firm's statement that its network was not breached does not reduce the exposure if one attorney's access was enough to get documents out. SRG is known to steal data without any encryption or network-wide intrusion.
- Aggregator profiles can be unreliable. CyberThreatIntelligence.net describes SRG as a "former Conti team" running double extortion with encryption. Its own page gives two different victim counts, 172 and 145. Today In Cyber calls SRG a high-volume, opportunistic operation. Both read as generic templates, and they do not match SRG's known profile of targeted, encryption-free data theft. Defenders should not plan around them.
- Legal exposure is building. Class Action U already has a page soliciting affected individuals, so class action risk is following the disclosure quickly.
The Attack Technique
The firm says only "sophisticated social engineering" against one attorney. Neither the notice nor any source we reviewed gives the method. SRG's public tradecraft includes:
- callback phishing (fake subscription or invoice emails that push the target to call a phone number)
- impersonating IT staff by phone
- persuading victims to install legitimate remote management tools
- copying files out with standard file transfer utilities
If SRG is behind this incident, those methods would fit a breach that the firm describes as confined to one person and not involving its network. Treat that as an inference until the firm or investigators attribute the incident.
What Organizations Should Do
- Make callback phishing and IT impersonation part of training, especially for attorneys and executive assistants. Set a rule that IT will never ask anyone by phone to install remote support software.
- Block or allowlist remote management tools. Use application control so that only approved RMM tools can run, and alert on any new installation of AnyConnect, Zoho Assist, Syncro, AnyDesk or similar.
- Watch for data leaving through a single user. Alert on large outbound transfers, new cloud sync clients, or WinSCP/rclone-style activity from end-user devices.
- Limit document access per user. Restrict each attorney's access to the matters they work on, so one compromised person cannot expose the whole document management system.
- Prepare client notification ahead of time. Law firms hold third-party data, so build out-of-band verification and client notification steps into incident response before an extortion contact arrives.
- Verify leak-site claims before acting on them. Check SRG listings against your own forensic evidence. The demand wording and whether samples exist may both be unreliable.
Sources: 🏴☠️ Silentransomgroup has just published a new victim : Sheppard,... | Sheppard Mullin, Fragomen, and Aldrich filed California breach noti... | Sheppard, Mullin, Richter & Hampton LLP data breach notice, Oct 2,... | SilentRansomGroup Claims 9 Million Ransom Demand Against Sheppard,... | SilentRansomGroup Claims Two Major US Law Firms — Sheppard Mullin a... | Sheppard, Mullin, Richter & Hampton — SILENTRANSOMGROUP Ransomware... | Sheppard, Mullin, Richter & Hampton Ransomware Attack by Silentrans... | Sheppard Mullin Data Breach Lawsuit - Class Action U