Two of the world's largest law firms have confirmed that sensitive files were stolen and, in at least one case, published online after extortion demands went unpaid. Jones Day confirmed in April that the Silent Ransom Group, also known as Luna Moth, released stolen files after a $13 million ransom demand was not met. Mayer Brown data later surfaced on a leak site tied to the same group, according to reporting from Cyber Risk Insurer. Cybersecurity firm Halcyon has now tracked more than 200 ransomware incidents targeting law firms between 2025 and early 2026, a pace that shows the legal sector has become one of the most consistently targeted industries for data extortion.
These incidents matter beyond the firms themselves. Law firm clients, including corporations, executives, and private individuals, often have no visibility into how their attorney's office handles cybersecurity, yet their most sensitive records (contracts, settlement terms, medical and financial disclosures, litigation strategy) sit inside those systems.
Why Law Firms Are a Prime Target for Extortion
Law firms occupy a unique position in the data economy. A single firm's servers can hold merger details before they're public, litigation records with embarrassing personal information, regulatory filings, and privileged communications for hundreds of clients across industries. That concentration of high-value, high-sensitivity data makes law firms attractive without needing to breach the actual companies involved. Attackers can get the same leverage, or more, by going after the intermediary instead.
Unlike a typical corporate breach where the affected company controls the response, law firm breaches put decision-making in the hands of an entity that may have competing interests: protecting its own reputation, preserving client relationships, and weighing the cost of a ransom against the cost of a public leak. That dynamic has made law firms a repeat target, and Halcyon's tracking of over 200 incidents in roughly a year suggests attackers see the sector as reliably profitable.
How Luna Moth Operates Without Ever Encrypting a File
What sets Luna Moth and the closely linked Silent Ransom Group apart from earlier ransomware waves is that they often skip encryption entirely. Rather than locking up systems with malware, the group has relied on social engineering, including phone calls impersonating IT staff, to trick employees into granting remote access or handing over credentials. Once inside, the group quietly exfiltrates files and then threatens to publish them unless a ransom is paid.
This approach sidesteps many of the detection tools built to catch encryption-based ransomware, since there's no obvious file-locking event to trigger an alert. It also means the extortion threat lingers indefinitely: a firm can restore its own systems from backup, but it can't undo the theft of documents that may already be sitting on an attacker's server. Readers who want a deeper look at the mechanics behind this approach can review our earlier coverage of how Luna Moth hit Jones Day and WilmerHale with a $13 million demand and our explainer on how Silent Ransom Group steals data by phone instead of encryption.
What Jones Day and Mayer Brown Reveal About Industry Gaps
Jones Day and Mayer Brown are not small, under-resourced operations. Both are among the largest law firms globally, with substantial IT budgets and established security teams. Their inclusion on Luna Moth's list of victims underscores a broader point: size and resources alone don't neutralize social engineering tactics that target human judgment rather than technical vulnerabilities. Halcyon's count of more than 200 law firm incidents in the same window suggests these two cases are not outliers but part of a sustained campaign spanning firms of many sizes.
The pattern also shows that publication of stolen data, rather than system lockup, is now the primary pressure point. When Jones Day's files went unmet at the ransom deadline, the group followed through and published them, a consequence that outlasts any single incident response effort.
What This Means for You
If you're a client of a law firm, whether as an individual, a small business, or part of a larger company, your documents may be sitting inside systems you have no direct control over. A breach at your attorney's office can expose the same categories of sensitive material you'd worry about in a breach of your bank or healthcare provider: contracts, personal identifiers, financial terms, and communications you assumed were private.
You can't audit your law firm's servers, but you can ask direct questions and take steps on your end. Ask your firm what encryption and access controls protect client files, and whether they've had any security incidents. Limit what you send by email or unsecured file-sharing links, and request encrypted portals for sensitive documents when available. Keep your own copies of critical records separately, so a firm-side breach doesn't leave you without documentation.
Key Takeaways
Law firm ransomware attacks like the Luna Moth and Silent Ransom Group campaigns show that data theft doesn't require encryption or a dramatic system lockout, just patience and a convincing phone call. With Halcyon tracking over 200 incidents against law firms in roughly a year, and confirmed victims including Jones Day and Mayer Brown, clients should treat their legal counsel's cybersecurity practices as part of their own risk picture. Ask questions before you share sensitive files, push for encrypted transfer methods, and stay alert for breach notifications from any firm you've worked with. The choice of how your information travels to and from your attorney is often still yours to make.




