SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
█ Ransomware WILMERHALE-GOODWIN 2026-08-22

WilmerHale and Goodwin Procter: Luna Moth Helpdesk Impersonation Extortion

"Two of the largest law firms in the United States reportedly paid eight-figure extortion demands this year to a group that never wrote a line of malware. Insurance trade press first reported the payments on 7 August…"

Two of the largest law firms in the United States reportedly paid eight-figure extortion demands this year to a group that never wrote a line of malware. Insurance trade press first reported the payments on 7 August 2026: WilmerHale paid at least $18 million and Goodwin Procter roughly $10 million to Luna Moth, also tracked as Silent Ransom Group and Chatty Spider. Neither firm has confirmed a payment or named the group. What both firms have confirmed, in filings to US state regulators and in statements to legal press, is that a person was deceived over the phone or by email into handing something over. Reuters reported on 7 August that at least three more firms, including Herbert Smith Freehills Kramer, Goodwin Procter and Taft Stettinius, disclosed breaches to state regulators in the space of a single week.

What Happened

The payment figures trace back to a single reporting chain. Aardwolf Security and Non-Billable both attribute them to The Insurer; Lawfare attributes the same two figures to The Cyber Risk Insurer. The underlying sourcing is described as confidential claims data, not firm disclosure. Aardwolf reports that WilmerHale's insurer CNA covered a $10 million primary layer and that Goodwin's cover came through Brit. Treat the amounts as trade-press reporting from insurance channels, not as confirmed fact.

The two payments sit inside a larger run. Law.com reported on 11 and 16 August that Weil Gotshal & Manges, Goodwin Procter and WilmerHale have reportedly paid about $50 million in total this year, a figure Non-Billable repeats. The Weil figure itself varies by source: Aardwolf puts it between $18 million and $20 million and dates it to May, while Law.com's 11 August piece carries a correction note recording a report that Weil paid $20 million to Silent Ransom Group. Aardwolf additionally reports that Jones Day faced a $13 million demand in April and appears to have refused it. That last claim appears in only one OTHER-tier source and should be treated as unconfirmed.

The firms' own accounts of the mechanics differ in ways worth noting. Goodwin told Law.com that "a single Goodwin employee was deceived into turning over their credentials to an unauthorized party." WilmerHale, in a statement to Bloomberg Law, said an unauthorized third party "targeting firms across the legal industry" obtained a limited set of information, and specifically said the attacker did not "directly access the firm's systems or network." Mayer Brown described something different again: personnel "mistakenly sent a small number of documents to an unauthorized third party who misrepresented their identity," with the third party never touching its systems. These are three distinct failure modes, credential handover, indirect data access, and direct document exfiltration by pretext, grouped under one campaign narrative. Accounts differ on whether a single technique explains all of them.

What Was Taken

Concrete numbers are thin, and the ones that exist come from regulator filings rather than from press.

For Goodwin Procter, a Texas Attorney General filing published 31 July 2026 confirms at least 1,550 Texas residents affected, with full names, Social Security numbers, and an additional unspecified category of personal information exposed. That is a state-level count, not a national total; no source in this set gives a full figure. Goodwin's own notice letter, as described by Emery Reddy, makes an important point about who is affected: the firm received the data while providing legal advice to clients, so recipients of a breach letter may be employees, opposing parties, witnesses, or other third parties who never chose to deal with Goodwin at all. Emery Reddy, citing Law360 Pulse, also reports this is Goodwin's third incident since the start of 2021, after a 2021 file-transfer vendor breach and an April 2025 Commvault-linked incident affecting 363 individuals disclosed in July 2025.

For WilmerHale, the class action complaint states the firm discovered the breach in early May and notified clients on 10 July that their personal information could have been obtained. The complaint claims "thousands" of clients could have been affected. WilmerHale calls the incident "isolated" and "quickly contained" and says it has no evidence the data has been misused or disclosed. There is obvious tension between a reported $18 million payment and a characterisation of "a limited set of information," and no source in this set resolves it.

Herbert Smith Freehills Kramer's Vermont regulatory filing of 29 July, per Law.com, involved Social Security numbers, government IDs and health records taken from the firm's US office. HSF Kramer told Non-Billable the incident was "in a part of our US IT environment," was investigated and contained, and that "the small number of people affected have been notified." Reuters reports HSF Kramer's own characterisation as hackers accessing a limited portion of its systems in May.

Why It Matters

The economics here are the story. Lawfare, citing Google's Threat Intelligence Group, notes that Silent Ransom often completes the entire chain, from first contact through data theft to extortion, inside a single day. Against payments in the eight figures, that is an extraordinary return on a phone call.

Because Luna Moth does not encrypt, the controls most firms bought to survive ransomware do not fire. Backups do not help when nothing is locked. Endpoint detection does not help when the "intrusion" is an employee installing legitimate remote-access software at the request of someone claiming to be IT, or emailing documents to a convincing impostor. There is no ransom note on a screen, often no dwell time to detect, and, in the Mayer Brown pattern, no system access at all.

The consequence stack is also now visible. WilmerHale was sued on 14 July in the US District Court for the District of Columbia (Perry v. Wilmer Cutler Pickering Hale & Dorr LLP, No. 1:26-cv-02470), a putative class action seeking negligence and contract damages. Bloomberg Law notes that similar suits have been filed against Blank Rome, Wiley Rein, Fried Frank and Pillsbury Winthrop within the past year. Paying the extortion demand does not close the file; it adds a line item to a case that plaintiffs will cite.

The Attack Technique

Luna Moth formed in 2022 out of the BazarCall phone-scam crew, per Aardwolf, and has stayed with social engineering ever since. Lawfare dates its focus on law firms to 2023.

Through early 2025 the standard approach was a fake subscription-renewal invoice delivered by email, carrying a phone number for the recipient to call and dispute the charge. That call connected the victim to an operator posing as IT support, who talked them into installing legitimate remote monitoring and management software. The tooling is legitimate, which is precisely the point: it is signed, commonly present in enterprise environments, and rarely blocked outright.

The escalation is what defenders should focus on now. Both Lawfare and Law.com report that operators have begun calling the helpdesk directly rather than waiting for a victim to call them, and, in the most aggressive cases, physically showing up at offices posing as IT support staff. Law.com's 16 August piece reports three firms describing surprisingly similar social-engineering encounters within a single week. Lawfare notes the group's exfiltration prioritises speed over completeness, which explains both the one-day turnaround and why firms may honestly describe the take as limited while still paying to keep it private.

A related actor is worth tracking alongside this. Lawfare, citing GTIG, describes BlackFile, now calling itself Redact, which emerged in early 2026 and uses high-volume vishing to steal credentials, then pulls data from OneDrive and SharePoint and pivots into other SaaS applications. GTIG reports Redact targeting real estate, healthcare and insurance in April and May, shifting in June to large technology, transportation and hospitality organisations with valuable intellectual property. Its exfiltration is described as more comprehensive than Luna Moth's.

Attribution and Confidence

Luna Moth is named as the actor by Aardwolf, Lawfare and Non-Billable, all OTHER-tier. Lawfare's attribution carries additional weight because it cites GTIG for the tradecraft. No victim firm in this set has publicly named the group, and the ransom amounts rest entirely on insurance trade reporting from confidential claims data. What is independently confirmed through regulator filings and firm statements is narrower: that breaches occurred at Goodwin, WilmerHale, HSF Kramer, Mayer Brown and Taft Stettinius; that social engineering was the vector in at least the Goodwin and Mayer Brown cases; and that the exposed data includes Social Security numbers, government IDs and health records. The payments, the $50 million total, and the group attribution should all be carried as reported rather than confirmed.

What Organizations Should Do

  1. Kill password and MFA resets over unauthenticated voice. The Goodwin case reduces to one employee handing over credentials. Require an out-of-band verification step that the caller cannot supply from public information: a manager callback to a directory number, an in-band push through an authenticated channel, or a video check against HR records. Publish it as policy and hold the helpdesk to it under pressure.

  2. Treat the helpdesk itself as the target. Luna Moth now calls IT rather than waiting to be called. Script and rehearse the inbound scenario, including a caller claiming urgency, a named partner, or a matter deadline. Give agents an explicit, blameless authority to refuse and escalate, and measure them on it rather than on ticket close time.

  3. Allowlist remote-access tooling. The initial access step is the victim installing legitimate RMM software. Maintain an explicit inventory of approved remote-access tools, block execution of everything else, and alert on first-run of any RMM binary on a workstation. This is the single highest-value technical control against this specific chain.

  4. Instrument for bulk egress, not encryption. Assume nothing will ever be encrypted. Alert on anomalous volume from SharePoint, OneDrive and document management systems, on new external sharing links, and on large mail attachments to unfamiliar domains. With a one-day attack chain, detection windows measured in days are worthless.

  5. Verify physical identity for anyone claiming to be IT. Reception and facilities staff are now part of the attack surface. Require badge and ticket verification before granting anyone claiming an IT role access to floors, desks or unlocked machines, and give front-desk staff a direct escalation number.

  6. Minimise and segment third-party personal data. Much of the exposed data belonged to people who were never firm clients. Enforce retention limits on matter files containing Social Security numbers, government IDs and health records, and segment them away from general-purpose document stores that a single compromised account can enumerate.

  7. Decide the payment question before you need to. Three of these firms reportedly paid a combined $50 million and one still ended up in federal court. Work through the legal, regulatory and insurance consequences with counsel and your carrier now, not during a one-day extortion window.

Sources: WilmerHale and Goodwin Procter Paid Millions After a Ransomware Gan... | Law firms Herbert Smith, Goodwin hit by data breaches | Hackers Have Found Big Law's Weakest Point: You Law.com | HSF Kramer, Mayer Brown Targeted in Latest Law Firm Data Breaches... | Data Theft Extortion Is Booming! Hooray! | WilmerHale Sued Over Client Personal Information Data Breach | Goodwin Procter Data Breach Lawsuit Emery Reddy | Big Law hackers pocket $50m in ransoms this year as fresh breaches...