Contents
Law firm cybersecurity stopped being an IT line item the moment an extortion crew started picking firms off one by one. Luna Moth attack—tracked by the FBI as the Silent Ransom Group (SRG)—has turned legal practices into its preferred target, and the payouts now reach eight figures. This group does not encrypt your files. It steals them, then threatens to publish your clients’ secrets unless you pay. For partners and operations managers at small-to-mid-size firms, the threat is concrete, current, and largely defeatable with disciplined controls.
This guide explains how Luna Moth operates, why the legal sector sits in its crosshairs, what recent victims paid, and the specific steps that stop the attack before exfiltration begins.
Who Luna Moth Is and Why It Matters
Luna Moth—also known as Silent Ransom Group, Chatty Spider, and UNC3753—has operated since at least 2022, emerging in the wake of the Conti ransomware syndicate’s collapse. The group abandoned the conventional ransomware model entirely. It deploys no malware and no encryption. Instead, it conducts data theft and extortion, demanding payment under threat of publishing or selling stolen files.
The FBI confirms the group has “consistently targeted US-based law firms since Spring 2023,” and notes that “most of SRG’s victims are law firms or companies with similar naming conventions”. One vendor analysis of confirmed victims from April 2024 through April 2025 found the legal industry represented 40.28% of targets—the single largest share.
The reason is blunt: the FBI attributes the targeting to “the highly sensitive nature of legal industry data”. Privileged communications, merger documents, regulatory correspondence, and personal client records concentrate enormous leverage in a single network. A firm that cannot guarantee confidentiality cannot function.
The Attack Chain: How a Single Phone Call Becomes a Breach
Luna Moth’s tradecraft is social engineering, not exploitation. There is no zero-day to patch. The group convinces a human to grant access. Three active methods exist as of mid-2026.
Callback phishing. The original method sends an email impersonating a subscription service, charging a small “subscription fee.” The FBI notes these small amounts are deliberate, “as they are less likely to generate immediate suspicion”. To cancel the fake charge, the victim calls a number in the email. The operator then emails a link that downloads remote access software.

IT helpdesk impersonation (vishing). As of Spring 2026, actors directly call or email staff and pose as the firm’s own IT department. While on the phone, the operator directs the employee to grant a remote desktop session. To make the lure convincing, the group registered at least 37 typosquatting helpdesk domains through GoDaddy in March 2025, using patterns like [firmname]-helpdesk.com.
Physical intrusion. If remote access fails, SRG sends a person to the firm’s office. Posing as an IT contractor, the operator inserts a USB or external drive into a workstation, claiming to “image the device” or create a backup.
Once inside, the group escalates privileges minimally and pivots fast to exfiltration. It uses legitimate tools—Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera for access, and WinSCP or a renamed Rclone to move data to Google Drive, OneDrive, or external servers. Because these are sanctioned administrative tools, traditional antivirus rarely flags the activity, and campaigns “leave few artifacts on compromised machines”.
After exfiltration, a ransom email arrives threatening to post or sell the data on the group’s clear-web leak site, business-data-leaks[.]com. The group also calls employees and clients directly to pressure negotiations.
What It Costs: The 2026 Payment Record
Luna Moth’s documented demand range runs from $1 million to $8 million per victim (Malpedia). Recent disclosed incidents show the real exposure is larger, and the outcomes diverge sharply depending on whether firms paid.
| Firm | Demand / Payment | Outcome | Source |
| Jones Day | $13M demanded | Refused; data of 10 clients published March 30, 2026 | DataBreaches.net |
| Orrick, Herrington & Sutcliffe | $1M+ demanded | Negotiations failed; full tranche leaked, including files marked “CONFIDENTIAL” | DataBreaches.net |
| Weil, Gotshal & Manges | $18M–$20M paid | Suppression payment within three days; no publication | Legal Cheek |
The Weil payment—reportedly between $18 million and $20 million—sits “substantially above Luna Moth’s documented demand range” and ranks among the largest single extortion payments ever attributed to a data-theft-only group.
These figures exclude the broader cost of a breach. IBM puts the 2025 U.S. average data breach cost at a record $10.22 million, and notes breaches involving stolen credentials take an average of 292 days to identify and contain—the longest of any vector. For the legal sector specifically, the 2024 average breach cost reached $5.08 million, a more than 10% year-over-year increase.
These are large firms. The lesson for smaller practices is not that they are too small to matter—Luna Moth’s $1 million floor scales down to mid-market targets, and smaller firms typically run thinner security controls.
Law Firm Cybersecurity as a Compliance Duty: Your Ethical Obligation Is Already Triggered
A Luna Moth breach is not only a financial event. It implicates a lawyer’s professional obligations directly. ABA Model Rule 1.6(c) requires that “a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client”.
Model Rule 1.1, Comment 8, requires lawyers to keep abreast of “the benefits and risks associated with relevant technology”. The standard is reasonable security, not absolute security—a risk-based analysis weighing the sensitivity of the data, the likelihood of disclosure, and the cost and difficulty of safeguards.
Two consequences follow. First, a firm that ignores a publicized, sector-specific threat like Luna Moth weakens any argument that its efforts were reasonable. Second, the ABA framework imposes a breach-response duty: lawyers must investigate what was compromised and notify affected clients. Failure can trigger malpractice liability and bar discipline, separate from any ransom.
Do not assume cyber insurance backstops a social-engineering loss. A 2026 federal decision found no coverage under a cyber policy for a law firm defrauded by an imposter, a reminder that policy language and social-engineering sublimits matter. Review your policy’s social-engineering and extortion provisions before you need them.
The Defense Playbook: Stopping the Attack Before Exfiltration
Luna Moth’s reliance on human trust and legitimate tools means the strongest defenses are procedural and identity-based, not signature-based antivirus. The controls below map directly to the attack chain in Section 2. The FBI’s own mitigation list anchors them.
| Control | What it stops | Priority |
| Out-of-band IT verification policy | Helpdesk impersonation calls and emails | Critical |
| Phishing-resistant MFA (FIDO2 / passkeys) | Credential theft and account takeover | Critical |
| Application allow-listing for RMM tools | Unauthorized AnyDesk, Atera, Zoho installs | High |
| Disable USB / external-drive write access | In-person USB exfiltration | High |
| Egress monitoring and DLP alerts | WinSCP / Rclone bulk transfers | High |
| Visitor credential verification | Physical intruders posing as IT | Medium |
| Targeted callback-phishing training | The initial lure | Critical |
Establish an out-of-band IT verification rule. No employee should install software or grant remote access because of an inbound call or email. The FBI advises firms to “develop and communicate policies regarding when and how IT support will communicate and authenticate themselves”. Staff should hang up and call IT through a pre-published internal number.
Deploy phishing-resistant MFA. The FBI recommends “phishing-resistant multi-factor authentication for as many services as possible”. FIDO2 security keys and passkeys bind authentication to the legitimate domain, so credentials fail automatically on a spoofed page—unlike SMS or one-time codes, which attackers can phish or relay. Prioritize partners, finance staff, and IT administrators first.
Restrict the tools the attackers need. Allow-list approved remote-access software and block the rest, so an employee cannot silently install RustDesk or Atera. Disable remote access and external-drive permissions on machines holding sensitive data, and where feasible block port 22 to cut off encrypted file transfer.

Watch the exits. Because the intrusion is quiet, detection shifts to data movement. Alert on large outbound transfers, WinSCP or Rclone connections to external IPs, and cloud-sync activity at odd hours.
Verify physical visitors. Require ID verification for anyone accessing firm spaces, and brief reception and staff that “IT contractors” with USB drives are a documented attack vector.
Train for the specific lure. Most phishing training covers links and attachments. Staff also need to understand that a phone number in an email can be the attack, and that a caller claiming to be IT may be the threat.
Detection: Indicators Your Firm Is Already Under Attack
If prevention slips, early detection limits the damage. Treat any of the following as an incident-response trigger:
- New, unauthorized downloads of Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera.
- Unauthorized installation of external hard drives or USB drives.
- WinSCP or Rclone connections to external IP addresses.
- Data exfiltration to OneDrive, Google Drive, or external servers.
- Employees reporting unsolicited calls from people claiming to be internal IT.
- Unidentified individuals on-site claiming to be IT support.
- Emails, calls, or voicemails from an unnamed group claiming data was stolen.
Maintain regular, isolated backups and a tested incident-response plan so the firm can act in hours, not days. If breached, report to your local FBI Cyber Squad and the Internet Crime Complaint Center, and preserve the ransom note, attacker contact details, and the original phishing message.
Frequently Asked Questions
Is Luna Moth a ransomware group?
No. Luna Moth conducts data theft and extortion without encryption. It steals files using legitimate tools, then threatens to publish or sell them unless paid. This means clean backups alone will not protect you—your confidentiality is already breached once data leaves the network.
Why are law firms specifically targeted?
The FBI attributes the focus to “the highly sensitive nature of legal industry data.” Privileged communications, deal documents, and client records create powerful extortion leverage. One 2024–2025 analysis found law firms made up over 40% of confirmed Luna Moth victims.
Will antivirus stop this attack?
Usually not. Luna Moth uses sanctioned remote-access and file-transfer software that antivirus treats as legitimate, leaving few artifacts. Defense depends on identity controls, application allow-listing, egress monitoring, and staff verification procedures rather than signature detection.
How much do Luna Moth ransoms cost?
Documented demands range from $1 million to $8 million, but disclosed 2026 cases ran higher. Jones Day faced a $13 million demand and refused; Weil Gotshal reportedly paid $18–20 million to suppress publication. Total breach costs, including legal and reputational harm, exceed the ransom itself.
What is the single most effective defense?
An out-of-band IT verification policy paired with phishing-resistant MFA. Together, they break the two pillars of the attack: tricking an employee into granting access, and stealing credentials. The FBI explicitly recommends both as core mitigations.
Does my ethical duty require me to act on this threat?
Yes. ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information, and Rule 1.1 requires technological competence. Ignoring a publicized, sector-specific threat undermines any “reasonable efforts” defense and can expose the firm to discipline and malpractice claims.
Resources
- FBI FLASH (FLASH-20260526-01): Silent Ransom Group Impersonating IT Personnel through Social Engineering, 26 May 2026
- FBI FLASH (20250523-001): Silent Ransom Group Targeting Law Firms, 23 May 2025
- Malpedia: Luna Moth threat actor profile
- EclecticIQ research via Cyber Threat Post: Luna Moth Launches Callback Phishing Attacks on U.S. Legal and Financial Sectors
- SC Media: Intensified Luna Moth callback phishing aims for data extortion
- DataBreaches.net: Jones Day confirms breach after phishing attack by Silent Ransom Group
- DataBreaches.net: Silent Ransom Group leaked another big law firm — Orrick, Herrington & Sutcliffe
- Legal Cheek: Weil reportedly pays up to $20 million after hackers steal client data
- The Insurer via LinkedIn: Weil Gotshal paid double-digit-millions suppression payment
- Reuters: Law firm Jones Day says hackers accessed client files
- shattered.io: Luna Moth Targets US Law Firms — $20M Ransom, 100+ Attacks
- IBM Cost of a Data Breach 2025 via CyberScoop: data breach costs reach all-time high
- Embroker / Clio: Law firm cyberattacks — stats and trends
- ABA Model Rule 1.6: Confidentiality of Information
- State Bar of Michigan: Cybersecurity for Attorneys — Legal and Ethical Duties
- Breach Craft: ABA Cybersecurity Guidelines summary
- Simpson Thacher: No Coverage Under Cyber Policy For Law Firm Defrauded By Imposter
- UK NCSC: Comparing traditional user and FIDO2 credentials
- Artech Solutions: The FBI Says This Hacking Group Is Targeting Law Firms
Disclaimer: The content provided on this blog is for informational purposes only and does not constitute legal, financial, or professional advice.


