← Back to Blog

Why Law Firms Have Become Cybercrime’s Prime Target

Why Law Firms Have Become Cybercrime’s Prime Target

Is your law firm ready for what’s coming? I just published a deep‑dive analysis on why the legal sector has become cybercrime’s #1 target—and the numbers are alarming:

The legal profession is under siege. And the numbers prove it.

For years, law firms have been attractive targets for cybercriminals because of the sensitive client data they hold—merger and acquisition strategies, litigation strategy, financial records, medical information, and attorney-client privileged communications. But in 2025 and 2026, the threat has escalated from a persistent nuisance into an all-out assault.

Here is what the data tells us.


The Scale of the Attack

Professional services—which includes law firms, accountancies, consulting practices, engineering firms, and managed service providers—now faces more cyber intrusion activity than any other industry SonicWall tracks.

In the first half of 2026 alone, the sector recorded 3 billion intrusion prevention system (IPS) events—the largest absolute attack volume of any industry. During the same period, professional services also recorded 69.9 million ransomware hits, again more than any other monitored sector.

Law firms specifically rank as the fourth most targeted industry by ransomware actors in the first months of 2026, behind only critical infrastructure sectors. Between 2025 and early 2026, security researchers tracked more than 200 ransomware incidents targeting the legal sector. The INC ransomware group alone claimed attacks against ten law firms within a single 48-hour window.


Attacks Are Accelerating—Not Slowing Down

The pace of attacks is increasing rapidly. According to BakerHostetler’s 2026 Data Security Incident Response Report—the only report published by a law firm based on actual incident data—the firm’s Digital Assets and Data Management Practice Group guided clients through more than 1,250 data security incidents in 2025.

While BakerHostetler responded to more than 30 law firm incidents in 2024, that number “nearly doubled” in 2025. The report attributed the increase in part to “the emergence of a threat actor known interchangeably as Chatty Spider, Silent Ransomware and Luna Moth, which specifically targeted law firms”.


The Ransomware Price Tag

The financial stakes are staggering.

According to the BakerHostetler report, the average initial ransomware demand spiked 70% to $4.2 million in 2025, while the average actual payment increased 36% to $682,702. Ransomware demands against professional services firms in 2025 and 2026 have ranged from $500,000 to $21 million, with the average just under $2 million.

Wire fraud alone siphoned over $15 million in 2025, with only 27% recovered.

The cost of a data breach for a law firm now averages $5.08 million, a 10% increase from the previous year. For a small or mid-sized practice, a ransom demand of that scale—arriving alongside the threat to publish privileged client communications—creates pressure to pay that no other industry faces quite the same way.


A New Kind of Attacker: The Silent Ransom Group

Perhaps the most alarming development is the emergence of the Silent Ransom Group (SRG) —also known as Luna Moth, Chatty Spider, and UNC3753.

On May 26, 2026, the FBI issued a FLASH advisory warning that this cybercrime group has “consistently targeted U.S.-based law firms,” likely because of the highly confidential nature of legal records. According to the FBI, SRG actors have recently begun using sophisticated social engineering schemes to pose as employees from victims’ IT departments.

The attack pattern is chilling:

  • Attackers either call employees directly or send phishing emails urging recipients to contact someone posing as IT support.

  • While on the phone, “the SRG actor directs the employee to grant access to a remote desktop session,” the FBI said.

  • If that attempt fails, SRG sends a threat actor to the victim’s location to gain access and insert a storage device into the victim’s computer. “In this scheme, the threat actor tells the victim they need to image the device or create a backup file”.

Mandiant/Google Threat Intelligence Group observed the complete attack lifecycle—from first contact to data exfiltration and extortion demand—completing in under one hour in the most recent incidents.

The group does not deploy traditional ransomware encryption. Instead, the threat is purely data theft paired with explicit threats of client notification, regulatory reporting, and data publication as extortion leverage. As of late May 2026, the group’s data leak site had published data from at least 38 law firms.


The Unique Threat Profile of Law Firms

Why are law firms so disproportionately targeted? Security researchers point to three characteristics:

1. The value of what they hold. Client files contain financial data, intellectual property, merger and acquisition details, litigation strategy, medical records, and confidential communications. This information has direct value to competitors, foreign intelligence services, and criminal extortion operations.

2. The time pressure built into legal practice. Ransomware actors time attacks to maximize pressure: before court deadlines, during trial, during deal closings, or at tax filing periods. A firm that loses access to its case management system three days before a major motion is due faces a very different calculus.

3. The privilege problem. Attorney-client privileged communications are the crown jewels of a law firm’s data. Modern ransomware groups do not just encrypt files—they exfiltrate data first and threaten to publish privileged communications if the ransom is not paid. Double extortion creates pressure that backups cannot resolve.

“Professional services holds the kind of data that carries built-in leverage,” said Michael Crean, Senior Vice President of Managed Services at SonicWall. “Client records tied to active legal matters, financial transactions, privileged communications … For the client, it represents massive financial, legal, and reputational risk. Attackers know this value, and the data bears that out”.


The Prevalence of Breaches

The scale of the problem is reflected in breach statistics:

  • 20% of U.S. law firms were hit by cyberattacks in the past 12 months, and nearly 1 in 10 lost or exposed sensitive data.

  • The American Bar Association’s 2025 TechReport found that 29% of law firms experienced a security breach at some point, with firms of 10-49 attorneys reporting the highest incident rates.

  • Of law firms that suffered a breach, 56% lost sensitive client information.

  • 22.4% of law firms do not meet the standards of ABA Rule 1.6 for protecting client data.

  • Only 36% of law firms have an incident response plan.


The Ripple Effects

The consequences extend beyond the immediate financial cost. Post-breach class action lawsuits are rising: lawsuits were filed in 68 of 482 disclosed incidents in 2025, up from 51 of 518 in 2024. Class actions were filed in 14% of incidents in 2025, up from 9% the previous year.

Client expectations are also shifting. A 2025 Integris Law Firm Cybersecurity Report found that 37% of clients are willing to pay a premium for firms with strong cybersecurity, while 66% are hesitant to work with firms that rely on outdated technology. More than 70% of firms report that their clients have exerted pressure on them to increase internal data security.


A Warning for Every Firm

The message from the data is clear: no law firm is too small to be a target. Smaller firms actually accounted for the majority of reported breaches in 2025. And the threat landscape is only becoming more sophisticated—AI is showing up more often as a factor in incidents and is increasing the speed and scale of cyberattacks.

Law firms that continue to treat cybersecurity as an IT afterthought rather than a core business and ethical obligation are not just risking financial loss—they are risking their clients’ trust, their reputations, and their very ability to practice law. As ABA Model Rule 1.6(c) makes clear, protecting client confidentiality is not optional; it is a professional ethical duty.

The attackers are coming. The only question is whether your firm will be ready.

← Back to Blog