Validated Containment Architectures are here. →Explore

Industry Category

Law Practice/Law Firms

Breach intelligence, attack campaigns, and threat reports targeting the Law Practice/Law Firms sector.

37 threat reports
Page 1 of 4

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Law Practice/Law Firms Threat Reports

Showing 112 / 37 reports
Ransom Cartel Leader Sentenced to 16 Years for Ransomware Attacks
Impact· HIGH

Ransom Cartel Leader Sentenced to 16 Years for Ransomware Attacks

Between 2021 and 2023, the Ransom Cartel ransomware group, led by Belarusian national Maksim Silnikau, targeted at least 18 organizations across various sectors, including law firms, medical technology startups, educational institutions, and multinational corporations in the United States. Silnikau orchestrated these attacks by recruiting participants from cybercrime forums, providing them with stolen credentials and encryption tools, and managing operations through a dedicated control site. The group's activities resulted in attempted extortions totaling approximately $5.2 million, causing significant operational disruptions for several victims.In August 2023, Silnikau was apprehended in Poland while attempting to return to Belarus and was subsequently extradited to the United States. In July 2026, he pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft, leading to a 16-year prison sentence. This case underscores the persistent threat posed by ransomware groups and highlights the importance of international cooperation in combating cybercrime.

3 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
UNC6671's 2026 Cyberattacks on Hedge Funds: A Wake-Up Call
Impact· HIGH

UNC6671's 2026 Cyberattacks on Hedge Funds: A Wake-Up Call

In August 2026, a series of cyberattacks targeted prominent hedge funds and private-equity firms, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers, identified as UNC6671 and associated with the BlackFile group, employed sophisticated voice phishing (vishing) techniques to impersonate corporate IT helpdesks. By directing employees to fraudulent login pages, they captured credentials and session cookies, enabling unauthorized access to corporate systems. This breach led to significant data exfiltration and subsequent extortion attempts, with ransom demands reaching up to $3 million, though settlements often averaged around $750,000. This incident underscores a concerning trend in cyber threats, where attackers leverage social engineering to bypass traditional security measures. The financial sector's increasing reliance on cloud-based services and single sign-on (SSO) platforms presents new vulnerabilities, emphasizing the need for enhanced employee training and robust security protocols to mitigate such risks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Ransom Cartel Ransomware Creator Sentenced to 16 Years
Impact· HIGH

Ransom Cartel Ransomware Creator Sentenced to 16 Years

In August 2026, Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for orchestrating attacks against at least 18 companies worldwide. Operating between 2021 and 2023, Ransom Cartel employed double extortion tactics, encrypting victims' data and threatening to leak it unless ransoms were paid. The group attempted to extort at least $5.2 million, causing over $6.7 million in losses. Notably, their operations disrupted a medical technology startup for two months and caused significant downtime for multiple law firms. This sentencing underscores the persistent threat posed by ransomware-as-a-service operations and highlights the critical need for robust cybersecurity measures. Organizations must remain vigilant against evolving ransomware tactics, as threat actors continue to adapt and exploit vulnerabilities across various sectors.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
HollowFrame and Matryoshka: Unveiling a Sophisticated Spear-Phishing Attack on a Law Firm
Impact· HIGH

HollowFrame and Matryoshka: Unveiling a Sophisticated Spear-Phishing Attack on a Law Firm

In July 2026, a sophisticated cyberattack targeted an undisclosed law firm using a previously undocumented Go-based loader named HollowFrame and a Rust-based backdoor called Matryoshka. The attack commenced with a spear-phishing email containing a link to an encrypted archive, which, when executed, initiated a multi-stage infection chain. This sequence involved privilege escalation, disabling Microsoft Defender protections, and downloading additional payloads. HollowFrame utilized DLL side-loading techniques to deploy Matryoshka, enabling persistent remote command execution, Active Directory reconnaissance, file transfers, and deployment of further malicious tools. These capabilities facilitated credential theft, lateral movement within the network, and potential broader domain compromise. This incident underscores the evolving threat landscape where attackers employ multi-stage, modular malware frameworks to infiltrate organizations. The use of spear-phishing as an initial vector highlights the critical need for robust email security measures and user awareness training to mitigate such sophisticated attacks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling Project CAV3RN: APT34's Covert Cyberespionage Tactics
Impact· HIGH

Unveiling Project CAV3RN: APT34's Covert Cyberespionage Tactics

In June 2026, Kaspersky's Threat Intelligence Reporting service detailed Project CAV3RN, a sophisticated modular cyberespionage framework targeting Israeli entities. Active since December 2025, the framework underwent a significant architectural shift in April 2026, transitioning from a three-component system to a controller-based architecture with a WebSocket-enabled C2 communication component and an extensible plugin system. Subsequently, a new .NET Native AOT communication module was identified, utilizing Outlook calendar events accessed via Microsoft Graph for command and control (C2) communications. This module also employs a DNS AAAA-based recovery mechanism to retrieve configuration settings if Microsoft Graph authentication fails. ([securelist.com](https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/?utm_source=openai)) The emergence of Project CAV3RN underscores the evolving tactics of state-sponsored threat actors, particularly the Iranian-linked group APT34 (OilRig). Their innovative use of legitimate services like Microsoft Graph and DNS for covert communications highlights the need for organizations to enhance monitoring of cloud services and implement robust detection mechanisms to identify and mitigate such sophisticated threats.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CyberAv3ngers' 2026 Attacks on U.S. Critical Infrastructure: A Wake-Up Call for OT Security
Impact· CRITICAL

CyberAv3ngers' 2026 Attacks on U.S. Critical Infrastructure: A Wake-Up Call for OT Security

In early 2026, the Iranian-affiliated cyber group CyberAv3ngers, linked to the Islamic Revolutionary Guard Corps (IRGC), launched a series of cyberattacks targeting U.S. critical infrastructure sectors, including water, energy, and local government facilities. The attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), such as CompactLogix and Micro850 models, to gain unauthorized access, manipulate data displayed on human-machine interfaces (HMIs), and disrupt operations. These incidents resulted in operational disruptions and financial losses for the affected organizations. ([risidata.com](https://www.risidata.com/Database/Detail/iran-cyberav3ngers-plc-us-infrastructure-2026?utm_source=openai)) This campaign underscores the escalating cyber threat posed by state-sponsored actors targeting industrial control systems (ICS) and operational technology (OT) environments. Organizations must prioritize securing internet-facing OT devices, implement robust access controls, and maintain up-to-date patch management to mitigate such risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Pegasus Spyware Targets PEGA Committee Member Amid Investigations
Impact· HIGH

Pegasus Spyware Targets PEGA Committee Member Amid Investigations

In 2022 and 2023, the European Parliament's PEGA Committee, established to investigate the misuse of surveillance spyware like NSO Group's Pegasus, faced an ironic security breach. Greek journalist and substitute committee member Stelios Kouloglou's phone was infected with Pegasus spyware twice: first around October 2022 and again in March 2023. These infections coincided with critical phases of the committee's work, including the drafting of its final report. The infections were confirmed by the University of Toronto's Citizen Lab, highlighting the persistent threat posed by sophisticated spyware even to those tasked with investigating its misuse. This incident underscores the ongoing challenges in protecting sensitive information from advanced surveillance tools. It also emphasizes the need for robust cybersecurity measures within governmental bodies and the urgency of implementing the PEGA Committee's recommendations to prevent future abuses of spyware technologies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Malicious Perplexity Chrome Extension Compromises User Data
Impact· MEDIUM

Malicious Perplexity Chrome Extension Compromises User Data

In June 2026, Microsoft identified a malicious Chrome extension named "Search for perplexity ai" that impersonated the AI search engine Perplexity. This extension intercepted users' search queries and address bar inputs, routing them through an attacker-controlled server before redirecting to legitimate search results. The extension set itself as the default search engine upon installation, capturing every character typed into the address bar and transmitting this data, along with browser headers, IP addresses, and user agents, to the attacker's server. Microsoft reported the extension to Google, leading to its removal from the Chrome Web Store. ([thehackernews.com](https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html?utm_source=openai)) This incident underscores a growing trend of malicious browser extensions exploiting the popularity of AI tools to harvest sensitive user data. Similar campaigns have targeted users by masquerading as AI assistants, leading to significant data breaches. Organizations must remain vigilant, implementing strict policies on browser extensions and educating users about the risks associated with unverified add-ons. ([techradar.com](https://www.techradar.com/pro/security/fake-chrome-ai-extensions-targeted-over-300-000-users-to-steal-emails-personal-data-and-more?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
'Lorem Ipsum' Malware Shifts to ClickFix Delivery in 2026
Impact· HIGH

'Lorem Ipsum' Malware Shifts to ClickFix Delivery in 2026

In May 2026, the operators of the 'Lorem Ipsum' malware campaign transitioned from using Trojanized Microsoft Teams installers to employing ClickFix lures hosted on compromised WordPress sites. This shift followed Microsoft's takedown of the Fox Tempest infrastructure, which had previously supplied the attackers with fraudulent Microsoft Trusted Signing certificates. The new delivery method involves fake browser update notifications that prompt users to execute malicious PowerShell commands, leading to the silent installation of the malware. This change significantly broadens the potential victim pool, as any visitor to the compromised sites is now at risk. The 'Lorem Ipsum' campaign is now believed to be linked to the Vice Society ransomware group, also known as Rapid Brigantine or Vanilla Tempest. Vice Society has a history of targeting sectors such as education, healthcare, and manufacturing, employing double extortion tactics by encrypting data and threatening to leak it unless a ransom is paid. The group's ability to rapidly adapt its delivery methods in response to disruptions underscores the evolving nature of cyber threats and the importance of robust, adaptive cybersecurity measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
NSO Group's Continued Targeting of WhatsApp Users Despite Legal Prohibitions
Impact· LOW

NSO Group's Continued Targeting of WhatsApp Users Despite Legal Prohibitions

In June 2026, WhatsApp identified and disrupted a spear-phishing campaign linked to the NSO Group, a spyware firm previously barred by a court order from targeting WhatsApp users. The attackers attempted to deceive users into clicking malicious links leading to external websites, aiming to install spyware on their devices. This incident follows a 2019 campaign where NSO exploited a WhatsApp vulnerability to target approximately 1,400 users, leading to a lawsuit and a permanent injunction against NSO. ([techcrunch.com](https://techcrunch.com/2026/06/08/whatsapp-says-it-caught-new-spyware-attacks-linked-to-nso-group-in-violation-of-court-order/?utm_source=openai)) The recurrence of such attacks underscores the persistent threat posed by spyware firms and highlights the challenges in enforcing legal restrictions against them. Organizations must remain vigilant and proactive in defending against sophisticated phishing and spyware campaigns that continue to evolve despite legal deterrents.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Silent Ransom Group's Bold Tactics: A Wake-Up Call for Law Firms
Impact· HIGH

Silent Ransom Group's Bold Tactics: A Wake-Up Call for Law Firms

Between January and May 2026, the Silent Ransom Group (SRG), also known as UNC3753, targeted numerous U.S. law firms through a sophisticated data theft extortion campaign. The attackers employed a combination of voice phishing (vishing), social engineering, and physical office intrusions. Initially, they contacted employees via phone calls or phishing emails, posing as IT support to gain remote access. If these attempts failed, SRG operatives visited offices in person, impersonating IT staff to physically access systems and exfiltrate sensitive data using USB drives or external hard drives. The stolen data included contracts, personal information, and financial records, which were then used to extort victims under the threat of public disclosure. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional social engineering with physical infiltration. The legal sector, handling highly sensitive client information, remains a prime target. Organizations must enhance their security protocols, including employee training on social engineering, stringent verification processes for IT support requests, and robust physical security measures to prevent unauthorized access.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UNC3753's 2026 Data Theft Campaign: A Blend of Vishing and Physical Intrusions
Impact· HIGH

UNC3753's 2026 Data Theft Campaign: A Blend of Vishing and Physical Intrusions

Between January and May 2026, the threat actor UNC3753, also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG), targeted numerous U.S. organizations in the professional, legal, and financial sectors. Utilizing voice phishing (vishing) and social engineering tactics, they impersonated IT support to gain remote access via screen-sharing sessions and remote monitoring tools. In some cases, attackers physically infiltrated offices, posing as IT technicians to exfiltrate data using USB devices. Stolen information included proprietary legal agreements, personally identifiable information (PII), and financial records. The group rapidly demanded ransoms, threatening to publish the stolen data if payments were not made promptly. This incident underscores the evolving tactics of cybercriminals, combining traditional social engineering with physical intrusion methods. The rapid execution of these attacks, often completed within a single business day, highlights the need for organizations to enhance their security awareness training and implement robust verification processes for IT support interactions.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports