Cyber & AI intelligence
Wasteland.
Briefs indexed3028
Issues31
Published Mondays07:30 CT
█ Ransomware SHEPPARD-MULLIN-SI 2026-10-06

Sheppard Mullin: Silent Ransom Group Lists Law Firm After Disclosed Social Engineering Breach

"Silent Ransom Group (SRG), also tracked as Luna Moth and Chatty Spider, added Sheppard, Mullin, Richter & Hampton LLP to its leak site on October 5, 2026, with a $4.9 million figure tied to stopping the publication of…"

Silent Ransom Group (SRG), also tracked as Luna Moth and Chatty Spider, added Sheppard, Mullin, Richter & Hampton LLP to its leak site on October 5, 2026, with a $4.9 million figure tied to stopping the publication of data. Sheppard Mullin has not confirmed the claim. Three days earlier, though, the firm filed breach notices with the California and Vermont Attorneys General. Those notices disclosed that on August 31, 2026, one of its attorneys fell for a "sophisticated social engineering event" and documents went to an unknown third party. The two events fit together, since SRG's known method is to socially engineer law firm staff. Still, no source we reviewed confirms they are the same incident, and the firm's notices do not name an actor.

What Happened

What the firm has disclosed. Several sources quote the notice the firm filed with the California AG. Severity Daily, AcidPeak and Class Action U all say it is dated October 2, 2026 and printed on the firm's Los Angeles letterhead. According to the notice:

Severity Daily also notes that Sheppard Mullin was one of four professional services firms to appear on California's breach list on October 1 and 2. The others were Aldrich, Greenberg Traurig and Fragomen. In each of the three notices Severity Daily could read, the entry point was a single compromised account.

What the threat actor claims. On October 5, ransomware trackers indexed an SRG listing for the firm (Today In Cyber via Ransomware Live, Breach House, CyberThreatIntelligence.net). The sources describe that listing differently:

What Was Taken

The firm has not said what was taken. Its notice says it is still running a "thorough and time-intensive analysis of the impacted files to determine what personal information they contained and to whom that information belongs." Class Action U notes that many people receiving the letters were never clients. Their data reached the firm through client matters, transactions or disputes.

SRG has published no data volume or data types. The only hard number in any source is the 21 Vermont residents from the state filing. Because the files belong to a law firm, they may include privileged client communications, deal documents and litigation material, but that is a risk assessment, not something the firm has confirmed.

Affected individuals are being offered 24 months of TransUnion credit monitoring through Cyberscout, with $1M in identity theft insurance. The enrollment deadline is December 31, 2026 (Severity Daily).

Why It Matters

The Attack Technique

The firm says only "sophisticated social engineering" against one attorney. Neither the notice nor any source we reviewed gives the method. SRG's public tradecraft includes:

If SRG is behind this incident, those methods would fit a breach that the firm describes as confined to one person and not involving its network. Treat that as an inference until the firm or investigators attribute the incident.

What Organizations Should Do

  1. Make callback phishing and IT impersonation part of training, especially for attorneys and executive assistants. Set a rule that IT will never ask anyone by phone to install remote support software.
  2. Block or allowlist remote management tools. Use application control so that only approved RMM tools can run, and alert on any new installation of AnyConnect, Zoho Assist, Syncro, AnyDesk or similar.
  3. Watch for data leaving through a single user. Alert on large outbound transfers, new cloud sync clients, or WinSCP/rclone-style activity from end-user devices.
  4. Limit document access per user. Restrict each attorney's access to the matters they work on, so one compromised person cannot expose the whole document management system.
  5. Prepare client notification ahead of time. Law firms hold third-party data, so build out-of-band verification and client notification steps into incident response before an extortion contact arrives.
  6. Verify leak-site claims before acting on them. Check SRG listings against your own forensic evidence. The demand wording and whether samples exist may both be unreliable.

Sources: 🏴‍☠️ Silentransomgroup has just published a new victim : Sheppard,... | Sheppard Mullin, Fragomen, and Aldrich filed California breach noti... | Sheppard, Mullin, Richter & Hampton LLP data breach notice, Oct 2,... | SilentRansomGroup Claims 9 Million Ransom Demand Against Sheppard,... | SilentRansomGroup Claims Two Major US Law Firms — Sheppard Mullin a... | Sheppard, Mullin, Richter & Hampton — SILENTRANSOMGROUP Ransomware... | Sheppard, Mullin, Richter & Hampton Ransomware Attack by Silentrans... | Sheppard Mullin Data Breach Lawsuit - Class Action U