Someone at the firm picks up the phone. The voice on the other end says there’s a problem with their mailbox, or a stalled update, or a security alert that needs clearing. The caller knows the firm’s name. They sound like they’ve done this a hundred times. They ask the person to open a screen-sharing session so they can take a look.
Twenty minutes later, client files are moving out of the firm.
This is not hypothetical, and it is not rare. On May 26, 2026, the FBI issued FLASH-20260526-01, warning that the Silent Ransom Group — also tracked as Luna Moth, Chatty Spider, and UNC3753 — is impersonating IT personnel to gain access to law firms. It was the Bureau’s second law-firm-specific alert about this group in roughly a year, following a similar warning in May 2025. According to the FBI, the group has been active since 2022 and has focused consistently on U.S. law firms since the spring of 2023.
What makes this campaign worth your attention isn’t its sophistication. It’s the opposite. The attack works because it asks your people to do something they do every week.
Why firms are the target
Legal work concentrates on exactly what an extortion crew wants. Settlement terms. Deal documents. Medical records attached to a personal injury matter. Social Security numbers for every member of a class. It arrives at your firm already organized, already sensitive, and already covered by an obligation you can’t negotiate away.
Halcyon’s Ransomware Research Center reported in June that one demand against a law firm reached $20 million in May 2026. Halcyon’s tracking through the first quarter of 2026 placed law firms among the most heavily targeted industries for ransomware activity. Cynthia Kaiser, who leads that research center, told Dark Reading the appeal comes down to “the sensitivity of client data, regulatory pressure to resolve incidents quickly, and a perceived willingness to pay ransoms to protect attorney-client privilege.”
The exposure is real and recent. On August 21, DataBreaches.net reported that the group had published more than 64,000 records tied to a large U.S. firm, including full Social Security numbers, mediation files, and privileged attorney-client documents. Notably, the attackers themselves described the firm’s security as strong.
That last detail matters. A firm can have solid technical controls and still lose data to a phone call.
How the attack actually runs
The FBI’s alert describes a straightforward sequence. Contact comes first — a call, an email, or both, framed as IT support or a routine invoice question. Then the attacker asks for a remote session or installs a legitimate remote management tool. Once inside, data leaves through ordinary channels: WinSCP, Rclone, or a cloud storage account. Extortion follows, with the threat of publication on a leak site.
Two variations deserve specific mention because they defeat controls that firms reasonably assume are working.
The first is physical. Halcyon traced the group’s escalation from callback phishing to direct voice phishing in March 2025 to sending people into offices in person beginning around April 2025 — posing as technicians and inserting storage devices directly into machines. The FBI alert confirms this tactic. Most firms have a cybersecurity program and a visitor policy, and in most firms, those two things have never been introduced to each other.
The second is speed. A Cloud Security Alliance research note published in June documented full intrusions completed in under an hour, including cases where attackers pivoted from a compromised personal device into the firm’s virtual desktop environment. There is no long dwell time to detect. By the time anyone thinks to ask whether that call was legitimate, the data is gone.
What the FBI actually recommends
The Bureau’s mitigation list is short and operational. Verify the credentials of everyone entering the firm’s premises, and keep a copy of each visitor’s ID. Limit access to sensitive data from home and public networks. Write down — and tell your staff — exactly how IT will contact them and how they can verify who it is. Train people to recognize and report phishing. Keep regular backups. Require phishing-resistant multi-factor authentication wherever you can. Where practical, disable remote access and external drive permissions on machines that touch confidential material.
Read that list again with your firm in mind. Most of it is policy and process, not new software. Which is good news, and also the reason it tends to sit undone.
Where we come in
This is work Innovative Computing Systems takes on directly, because it shouldn’t land on an administrator’s desk on top of everything else already there.
We establish the verification protocol — a documented, firm-specific way for your team to confirm that a support call is really support — so nobody has to make that judgment alone under pressure. We deploy phishing-resistant multi-factor authentication and single sign-on, and we run security awareness training that reflects how this group actually operates, so your staff recognizes the pretext before the screen share starts. We restrict which devices can access your environment and lock down external drive permissions on machines that hold client data, which means a USB stick inserted into a workstation has nowhere to go. And we monitor around the clock, with live answers from a 100% U.S.-based team, so when someone calls to say I think I just did something wrong, someone picks up.
We also work alongside your internal IT staff rather than around them. If you have an IT Director carrying patching, vendors, and security at once, we take the operational load so they can spend time on the planning the firm actually needs.
You should not have to lose client data to a preventable problem. Firms deserve better than a technology environment where a well-timed phone call can undo a year of careful work. We’ve got your back on this one.
Start with a conversation
If you’re not sure how your firm would handle that call today, that’s the right thing to find out now rather than during an incident.
Request a free Legal IT consultation. You’ll fill out a short form, and a Solutions Consultant will reach out to walk through your current setup — security posture, access controls, staff training, and where the gaps are. No debt, and no contract required to work with us afterward.
