Law firms hold some of the most sensitive information that exists outside of hospitals and government agencies: merger details, litigation strategy, client financials, and personal records tied to ongoing cases. That combination of high value and, in many cases, thin cybersecurity budgets has made the legal sector an increasingly attractive target for a group known as the Silent Ransom Group (SRG). Also tracked under the aliases Luna Moth, Chatty Spider, and UNC3753, this group has built an extortion playbook that skips the part most people associate with ransomware entirely.
A Different Kind of Extortion
Traditional ransomware attacks follow a familiar pattern: malware locks up a victim's files, and the attackers demand payment for a decryption key. SRG does something quieter and, in some ways, more dangerous. Rather than encrypting systems, the group focuses on stealing data outright and threatening to publish it unless the firm pays up. There is no ransomware to detect, no scrambled files to alert IT staff that something is wrong. The first sign of trouble is often the extortion demand itself.
The access typically starts with a social engineering trick as simple as it is effective: SRG operatives impersonate IT support staff, calling or emailing employees to convince them to hand over credentials or install remote access tools. Once inside, the group quietly exfiltrates files rather than triggering the kind of network disruption that would set off alarm bells. By the time a law firm realizes something happened, the data is already gone and the threat of public exposure is already on the table.
This approach mirrors a broader shift in how extortion groups apply pressure to victims. Some ransomware operators have even started dressing up their threats with fabricated legal language to make demands sound more official and harder to ignore, a tactic detailed in ransomware gangs adding fake AI legal threats to ransom notes. Whether the pressure comes from fake legal memos or the simple threat of leaking client files, the goal is the same: make paying feel like the only reasonable option.
Why Law Firms Are Especially Vulnerable
Law firms occupy an unusual position in the cybersecurity world. They are custodians of extremely sensitive third-party data, often for multiple corporate clients at once, yet many operate with smaller IT teams and less formal security training than the industries they serve. Attorneys and support staff are frequently under time pressure, juggling calls from vendors, courts, and clients, which makes a convincing IT impersonation call easier to slip past someone's guard.
There is also a structural incentive problem. A breach at a law firm does not just expose the firm's own data, it exposes confidential information belonging to every client whose matter touched that system. That amplifies the reputational and legal stakes of any leak, which is exactly the leverage groups like SRG are counting on when they threaten publication instead of encryption.
What This Means For You
If you work at a law firm, or you are a client whose sensitive records pass through one, this trend matters even if you never see a ransom note yourself. Data theft through impersonation does not require a sophisticated technical exploit. It requires one employee trusting the wrong phone call or email. That means firms of any size, not just large corporate practices, are potential targets.
For clients, it is worth asking the firms handling your case or transaction what verification steps they require before granting remote access or resetting credentials. A firm that has clear, tested procedures for confirming IT requests is less likely to fall for the kind of impersonation SRG relies on.
Practical Steps Worth Taking Now
The good news is that this specific attack method has a fairly narrow point of failure: human verification. A few concrete steps can meaningfully reduce risk.
- Establish a strict callback policy for any IT request involving credentials, remote access, or software installation. Employees should independently verify requests through a known internal number rather than trusting the caller's identity at face value.
- Train staff to treat unsolicited IT contact, especially urgent-sounding requests, as a red flag rather than a routine task.
- Limit and monitor remote access tools so that unusual installations or logins trigger alerts rather than going unnoticed.
- Build an incident response plan that assumes data theft, not just encryption, since detection methods built around ransomware symptoms will miss this kind of intrusion.
The Silent Ransom Group's success depends on speed and trust: convincing someone to act quickly before they stop to verify. Law firms that build friction into that process, even something as simple as a callback policy, remove much of the group's advantage. Cybersecurity in the legal sector does not require a massive overhaul overnight, but it does require treating social engineering as seriously as any technical vulnerability. Firms that make that shift now will be far better positioned than those waiting for an extortion demand to force the conversation.




