The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Law Practice/Law Firms
Breach intelligence, attack campaigns, and threat reports targeting the Law Practice/Law Firms sector.
Explore Other Sectors
Law Practice/Law Firms Threat Reports
BambooToken Malware Exploits MQTT Protocol for Stealthy Enterprise Attacks
BambooToken, a sophisticated malware framework active since 2023, has evolved to use the MQTT protocol for command-and-control communications across Windows and Linux systems. The malware compromises enterprise servers supporting mobile applications, financial services, and software development firms primarily across Asia and South America. By leveraging MQTT's publish-subscribe architecture, BambooToken creates resilient command channels that avoid direct connections to attacker infrastructure, significantly improving evasion capabilities while maintaining persistent access to infected systems. This incident highlights the growing trend of threat actors adopting unconventional protocols like MQTT to bypass traditional security controls, reflecting the increasing sophistication of modern cyber campaigns targeting critical business infrastructure.
1 week ago
Kill Chain
U.S. Lawmakers Push for Sanctions Against Indian Hack-for-Hire Networks
Bipartisan lawmakers have urged the U.S. Treasury Department to sanction three India-based hack-for-hire groups - Sunkissed Organic Farms (formerly Appin), BellTroX, and CyberRoot - that have conducted over 15 years of targeted espionage against American citizens, businesses, and legal representatives. These cyber mercenary operations have reportedly stolen data from thousands of Americans while operating on behalf of foreign governments including Qatar, targeting critics of Qatar's World Cup bid and even family members of former House Intelligence Chairman Mike Rogers. The groups have also engaged in aggressive legal campaigns to censor media reporting on their activities, effectively allowing foreign entities to suppress information about cyber threats targeting U.S. interests. This incident highlights the growing threat of nation-state sponsored cyber mercenary operations that blur the lines between criminal hacking groups and state-sponsored espionage. As geopolitical tensions increase and digital espionage becomes more commercialized, these hybrid threat actors represent a significant challenge to traditional cybersecurity defenses and diplomatic responses.
2 weeks ago
Kill Chain
FBI Warns of Sophisticated OAuth Consent Phishing Campaign Targeting Prominent Figures
The FBI issued a public alert in late 2025 regarding a sophisticated OAuth consent phishing campaign targeting high-profile individuals, their family members, and associates through commercial messaging applications. Attackers impersonate government officials, journalists, and public personalities to trick victims into granting access to legitimate cloud services like Microsoft or Google under the pretense of reviewing documents. Once OAuth permissions are granted, attackers gain persistent access to emails, files, and sensitive data that cannot be revoked simply by changing passwords, requiring victims to manually invalidate tokens in application security settings. This campaign highlights the growing trend of identity-centric attacks that bypass traditional security measures including multi-factor authentication, representing a significant evolution in social engineering tactics that exploit trusted authentication protocols against prominent targets.
3 weeks ago
Kill Chain
Legal Filing Prompt Injection Attack: When AI Security Meets the Courtroom
In August 2026, a novel attack vector emerged where an individual embedded hidden AI instructions within a legal court filing, attempting to manipulate AI systems that might process the document to rule in their favor. This prompt injection attack represents a sophisticated evolution of adversarial AI techniques, moving beyond traditional digital platforms into legal and governmental processes. The incident demonstrates how threat actors are adapting prompt injection methods to exploit AI systems in critical decision-making contexts, potentially compromising judicial integrity and administrative processes. This incident highlights the growing urgency around AI security as organizations increasingly deploy AI systems for document processing, legal research, and decision support. With the rapid adoption of AI in government, healthcare, and enterprise environments, similar prompt injection attacks could target any AI-powered system that processes external documents or user inputs.
3 weeks ago
Kill Chain
Apollo Global Management Hit by BlackFile Social Engineering Attack: $1 Trillion Firm Discloses Data Breach
Apollo Global Management disclosed a data breach occurring between July 6-10, 2024, where attackers used social engineering tactics to gain unauthorized access to cloud platforms. The attack was attributed to BlackFile, a threat group affiliated with The Com collective, which has been targeting financial institutions, law firms, and medical technology companies. Personal data including names, Social Security numbers, dates of birth, and contact information were compromised, though Apollo found no evidence of data being posted online or used for identity theft. This incident exemplifies the growing threat of sophisticated social engineering campaigns targeting the financial sector, particularly as cybercriminals increasingly focus on high-value private equity firms and leverage voice-phishing techniques to bypass traditional security controls.
1 month ago
Kill Chain
Ransom Busters' Secondary Extortion Tactics Target Ransomware Victims
In August 2026, a ransomware affiliate known as 'Ransom Busters' initiated a deceptive campaign targeting organizations previously victimized by ransomware attacks. The group claimed to have infiltrated ransomware groups' servers, offering to delete stolen data in exchange for payments ranging from $20,000 to $60,000. This approach involved direct communication with victim organizations, asserting unauthorized access to threat actors' infrastructure and proposing data recovery services for a fee. The legitimacy of these claims is highly questionable, as such actions would constitute violations of the U.S. Computer Fraud and Abuse Act. This incident underscores the evolving tactics within the ransomware ecosystem, where affiliates may exploit victims through secondary extortion schemes. Organizations are advised to exercise caution and skepticism toward unsolicited offers of assistance from unverified entities, as engaging with such actors may lead to further financial loss without any assurance of data recovery.
1 month ago
Kill Chain
BlackFile's 2026 Vishing Attacks on Financial Institutions
In early 2026, the cybercrime group BlackFile, also known as UNC6671 and linked to 'The Com,' initiated a series of sophisticated voice-phishing (vishing) attacks targeting major financial institutions, including private equity firms, law firms, and financial rating agencies. By impersonating IT support personnel, they deceived employees into divulging credentials, enabling unauthorized access to sensitive data. The group then exfiltrated this data and issued extortion demands, often starting around $3 million, with payments typically negotiated down to less than $1 million. Notably, BlackFile has expanded its operations under multiple brands—Redact, Pink, Helix, and Falcon—using shared infrastructure to target an average of 1.5 new victims daily. This incident underscores the persistent and evolving threat posed by cybercriminal groups employing social engineering tactics. The financial sector's susceptibility to such attacks highlights the critical need for enhanced employee training, robust authentication mechanisms, and vigilant monitoring to mitigate the risks associated with vishing and data extortion schemes.
1 month ago
Kill Chain
Apple's August 2026 Mercenary Spyware Threat Notifications: What You Need to Know
In August 2026, Apple issued threat notifications to users in 110 countries, alerting them to potential mercenary spyware attacks targeting their devices. These sophisticated attacks are typically aimed at individuals based on their profession or activities, such as journalists, activists, politicians, and diplomats. Apple emphasized the severity of these threats and recommended that affected users enable Lockdown Mode and keep their devices updated to mitigate risks. The issuance of these notifications underscores the persistent and evolving nature of mercenary spyware threats. As these attacks become more sophisticated and widespread, it is crucial for individuals and organizations to remain vigilant and adopt comprehensive security measures to protect sensitive information and maintain privacy.
1 month ago
Kill Chain
Scottish Government Data Breach: Lessons in Third-Party Security
In August 2026, Scotland's Crown Office and Procurator Fiscal Service (COPFS) disclosed a data breach involving an external supplier managing an online data maturity assessment. The breach exposed personal information of approximately 300 employees, including names, roles, and work email addresses. The incident was detected on August 5, 2026, when the third-party noticed suspicious activity on its network. While COPFS's case-related data remained unaffected, the breach raises concerns about the security of third-party vendors handling sensitive government information. This incident underscores the growing risks associated with third-party service providers in the public sector. As government agencies increasingly rely on external vendors for data management and assessments, ensuring robust security measures and continuous monitoring of these partners becomes imperative to prevent unauthorized access and data breaches.
1 month ago
Kill Chain
Ransom Cartel Leader Sentenced to 16 Years for Ransomware Attacks
Between 2021 and 2023, the Ransom Cartel ransomware group, led by Belarusian national Maksim Silnikau, targeted at least 18 organizations across various sectors, including law firms, medical technology startups, educational institutions, and multinational corporations in the United States. Silnikau orchestrated these attacks by recruiting participants from cybercrime forums, providing them with stolen credentials and encryption tools, and managing operations through a dedicated control site. The group's activities resulted in attempted extortions totaling approximately $5.2 million, causing significant operational disruptions for several victims.In August 2023, Silnikau was apprehended in Poland while attempting to return to Belarus and was subsequently extradited to the United States. In July 2026, he pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft, leading to a 16-year prison sentence. This case underscores the persistent threat posed by ransomware groups and highlights the importance of international cooperation in combating cybercrime.
1 month ago
Kill Chain
UNC6671's 2026 Cyberattacks on Hedge Funds: A Wake-Up Call
In August 2026, a series of cyberattacks targeted prominent hedge funds and private-equity firms, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers, identified as UNC6671 and associated with the BlackFile group, employed sophisticated voice phishing (vishing) techniques to impersonate corporate IT helpdesks. By directing employees to fraudulent login pages, they captured credentials and session cookies, enabling unauthorized access to corporate systems. This breach led to significant data exfiltration and subsequent extortion attempts, with ransom demands reaching up to $3 million, though settlements often averaged around $750,000. This incident underscores a concerning trend in cyber threats, where attackers leverage social engineering to bypass traditional security measures. The financial sector's increasing reliance on cloud-based services and single sign-on (SSO) platforms presents new vulnerabilities, emphasizing the need for enhanced employee training and robust security protocols to mitigate such risks.
1 month ago
Kill Chain
Ransom Cartel Ransomware Creator Sentenced to 16 Years
In August 2026, Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for orchestrating attacks against at least 18 companies worldwide. Operating between 2021 and 2023, Ransom Cartel employed double extortion tactics, encrypting victims' data and threatening to leak it unless ransoms were paid. The group attempted to extort at least $5.2 million, causing over $6.7 million in losses. Notably, their operations disrupted a medical technology startup for two months and caused significant downtime for multiple law firms. This sentencing underscores the persistent threat posed by ransomware-as-a-service operations and highlights the critical need for robust cybersecurity measures. Organizations must remain vigilant against evolving ransomware tactics, as threat actors continue to adapt and exploit vulnerabilities across various sectors.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports