The Containment Era is here. →Explore

Executive Summary

In March 2025, Berkeley Research Group (BRG), a prominent consulting and legal advisory firm, suffered a devastating ransomware attack attributed to the RansomHub cybercriminal group. Attackers leveraged persistent dwell time to infiltrate BRG’s network, exfiltrated sensitive data including M&A intelligence and confidential client materials, and encrypted key systems. The breach occurred during BRG's $700 million buyout by TowerBrook Capital Partners, amplifying the incident’s impact and resulting in exposure of information related to hundreds of active deals and thousands of individuals. The attackers’ extortion included threats of blackmail and public data leaks, leveraging their knowledge of both firm structure and sensitive client engagements.

This attack spotlights a surge in professional services sector targeting—especially legal and advisory firms—by highly organized ransomware groups in 2024–2025. Threat actors like RansomHub have adopted prolonged infiltration tactics, optimized affiliate compensation, and leveraged industrialized extortion, mirroring broader ransomware trends and underscoring urgent vendor risk management needs.

Why This Matters Now

Legal and consulting firms now serve as high-value targets, holding critical market intelligence for multiple clients and deals. With dwell times increasing and ransomware groups refining their extortion playbooks, failure to treat professional service providers as high-risk vendors creates a real-time risk of strategic data exposure and cascading regulatory, financial, and competitive fallout.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach revealed a lack of strong segmentation, prolonged data retention, insufficient breach detection, and limited vendor access controls—highlighting gaps against frameworks like NIST, HIPAA, and PCI.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust CNSF controls—including least privilege segmentation, egress policy enforcement, encrypted east-west inspection, and threat detection—would have sharply limited attacker movement, reduced data exfiltration risk, and accelerated detection. Properly implemented, these controls restrict unauthorized access, detect anomalous behavior, and contain ransomware activity before business-critical impact.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked or monitored unauthorized inbound access attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited the attacker's ability to escalate privileges across network segments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevented or detected unauthorized lateral movement between sensitive resources.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detected and blocked outbound C2 communication attempts.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Blocked or alerted on unauthorized data exfiltration attempts.

Impact (Mitigations)

Early identification of ransomware behaviors reduced business impact.

Impact at a Glance

Affected Business Functions

  • Legal Services
  • Client Confidentiality
  • Data Management
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Sensitive client information, including M&A intelligence and litigation strategies, was exfiltrated, leading to potential legal and reputational consequences.

Recommended Actions

  • Enforce Zero Trust Segmentation and least privilege policies to limit attacker movement within cloud and hybrid environments.
  • Implement robust egress filtering and policy enforcement to prevent unauthorized data transfer and detect malicious outbound activity.
  • Deploy inline IPS and traffic monitoring to detect, alert, and block known command-and-control and ransomware communication patterns.
  • Apply continuous east-west traffic inspection and microsegmentation to expose and block lateral movement by adversaries.
  • Mandate centralized visibility and anomaly detection across cloud, on-prem, and SaaS assets to enable rapid response to evolving ransomware TTPs.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image