A briefing from S-RM on what it calls "the Luna Moth files" is drawing attention to how a data extortion group goes after the legal sector. The Luna Moth extortion group leak offers a rare look at the operations of a crew that does not rely on classic ransomware. For law firms, and for the clients who trust them with sensitive material, the lessons are practical and worth understanding.
This post sticks to what the briefing's summary and public reporting establish. The group is also tracked as Silent Ransom Group, UNC3753 and Storm-0252, and security researchers describe it as financially motivated.
What the Luna Moth files reveal
The S-RM briefing describes the leak as revealing insights into the operations of a sophisticated cyber extortion group targeting the legal sector. The central takeaway is about method. Luna Moth skips the encryption step that most people associate with ransomware. It steals data, then pressures the victim to pay to keep it from being published.
That distinction matters. Without encrypted systems, there may be no obvious outage and no ransom note on a screen. A firm can look operational while its documents are already gone. Backups, the usual answer to ransomware, do nothing to stop stolen files from being leaked.
The group's threats are not empty. Reporting on Luna Moth leaking data from Jones Day and Mayer Brown shows that two of the world's largest law firms confirmed sensitive files were stolen and, in at least one case, published online after extortion demands went unpaid.
How callback phishing and fake support calls work
The group's reliance on callback phishing is what makes it distinctive. Rather than sending a link or attachment that a mail filter might catch, the attacker sends a message that contains only a phone number. The message might suggest a subscription charge or an account problem. The target is encouraged to call.
When the victim phones in, they reach someone posing as IT support. That person walks them through steps that give the attacker remote access, often under the pretext of fixing a problem or cancelling a charge. Because the victim initiated the call, the interaction feels legitimate, and the usual suspicion drops away.
Public reporting on an FBI advisory describes the impersonation of IT support by telephone, email and in-person, used to steal data and extort victims, particularly US law firms. A security research note also describes vishing and physical intrusion at law firms. In other words, the social engineering is not limited to a single channel.
Once inside, the goal is quiet data theft. This pattern echoes other cases where attackers use legitimate tools and cloud services to move data out. Our coverage of how Vice Society abused OneDrive for data theft shows how ordinary business software can become the exfiltration route, which makes the activity harder to spot.
Why law firms and their clients are exposed
Law firms hold material that is valuable precisely because it is confidential: contracts, litigation strategy, merger plans, personal financial details and privileged communications. For an extortion group, that creates leverage. Even if a firm could rebuild its systems in a day, it cannot easily undo the exposure of a client's private affairs.
The pressure falls on more than the firm. Clients may find their information in a leak they never had any control over. Staff are exposed too, since their personal details sit in HR records and internal directories. And because the entry point is often a single employee taking a phone call, even firms with strong technical defenses can be caught by a convincing script.
There is also a trust problem. Clients choose firms in part because of their discretion. A public leak damages that relationship regardless of how the firm responds technically.
What to do if your law firm or provider is breached
If you are a client, you usually learn about a breach secondhand. A few steps can limit the damage:
- Ask what was taken. Request a clear account of which of your documents and personal details were involved, and when the firm first knew.
- Treat follow-up contact with suspicion. Extortion groups and opportunists may contact affected people directly. Verify any message through a number or address you already trust, not one supplied in the message.
- Change credentials and watch accounts. If any passwords, account numbers or identity documents were shared with the firm, rotate passwords and monitor financial accounts.
- Do not engage with demands on your own. Report any extortion attempt, and consider speaking to your own advisers.
If you work at a firm or provider, the priorities are different. Train staff to treat unexpected phone numbers in emails with caution, and to verify any "IT support" caller through an internal channel before granting access. Make it normal to hang up and call back using a known number. Restrict who can install remote access software, and make sure staff know how to report a suspicious call without fear of blame.
If an incident is already underway, our ransomware extortion response guide sets out what to do first, and the steps apply equally to data theft extortion where nothing was encrypted.
What This Means For You
The Luna Moth extortion group leak is a reminder that a breach does not need encrypted files to be serious. If you share sensitive information with a law firm, accountant or any other adviser, you are relying on their staff to resist a convincing phone call. You cannot control that, but you can ask how they train for it, limit what you hand over, and act quickly if they tell you something has gone wrong.
Takeaways
- Data theft extortion works without encryption, so backups alone are not a defense.
- Callback phishing turns the victim into the caller, which lowers suspicion.
- Verify any IT support request through a channel you already know is real.
- If a provider holding your data is breached, ask what was taken, rotate credentials and be wary of unsolicited contact.
For real-world impact, read our coverage of Luna Moth and the Jones Day and Mayer Brown leaks, and keep the ransomware extortion response guide handy for concrete first steps after a breach or extortion attempt.




