Mathew Potter
Security Analyst
If you skimmed the headlines in August 2026, you probably noticed the same pattern: another large law firm disclosed a breach, another regulator filing, another rumour about a multi-million dollar payment to keep client files off the internet.
What is different from the ransomware stories we got used to is how little encryption matters now. Groups like Silent Ransom (also tracked as Luna Moth or UNC3753) often move from first contact to data theft in hours, sometimes less. Mandiant has documented cases where exfiltration and the first extortion email landed inside a single business day.
The playbook is social, not exotic. Voice phishing. Callers who sound like IT. Emails that push you to install remote support tools you already trust. In a few cases, attackers have shown up in person pretending to be help desk staff or tried USB drops on unlocked machines.
That is uncomfortable for firms that budget for firewalls and endpoint suites but spend less time on remote access hygiene and user verification. If someone can talk a receptionist or a junior associate into opening a session, the rest is often just file copying.
Law firms hold exactly the data criminals price highest: identity numbers, financial records, health information tied to matters, and privileged correspondence. Reputation is the product. The threat of public disclosure is leverage even when systems still boot normally.
Regulatory filings this summer from firms including Herbert Smith Freehills Kramer, Mayer Brown, Goodwin Procter, Fox Rothschild, and others describe the same categories of loss: government IDs, financial account details, and sensitive personal data. Troutman Pepper Locke was hit again in mid-August. The details differ, but the shape of the problem does not.
We are not going to pretend one checklist stops a determined actor. Practical steps we see hold up under review:
The industry is shifting from "pay to decrypt" to "pay to suppress." That is still a crisis, but it is a different one. Firms that only measured success by uptime are recalibrating. If you want an independent read on mail, access, and exposed services before renewal season, that is the work we do at Forensic Five. Scoped, written, and explicit about limits.