Reinsurance
Explore our offerings
Explore our Mid-Market offerings
Jeanelle Dawes-Ghee, Senior Claims Specialist, Cyber, AXA XL

By

Senior Claims Specialist, Cyber, AXA XL

Law firms are sitting on a goldmine. And cybercriminals know it.

In a May 26 bulletin, the FBI warned that the Silent Ransom Group (also known as Luna Moth, Chatty Spider, and UNC3753) is increasingly targeting U.S. law firms by using fake IT support calls and even in person visits to gain access to highly confidential legal data and extort victims.

Few professions collect and centralize sensitive information the way lawyers do. Client files, deal documents, medical records, trade secrets, intellectual property portfolios, litigation strategies, personal financial data, confidential settlements, internal investigations, compliance reports. The modern law firm’s database is a comprehensive bank of information on the most sensitive aspects of individual and corporate life.

That concentration of high value data makes lawyers one of the most attractive targets in the cybercrime ecosystem. Getting the data is the first step. Using the data to extort firms and their clients is the real plan of attack.

Why lawyers are uniquely attractive targets
From a cybercriminal’s perspective, the ideal victim has three traits: access to very sensitive data, a strong need to keep that data secret, and weaker security than the data’s value would warrant.

Many law firms fit this profile. They hold unusually concentrated, wide ranging sensitive information. While most organizations store data about their own operations, law firms store data about many companies and individuals at once. A single firm might handle M&A documents with non public financials and strategy, regulatory filings and enforcement correspondence, HR investigations, IP portfolios and licensing deals, criminal defense files with highly personal details, family law matters involving assets and health, and internal compliance reports on potential misconduct. Breaching one firm isn’t just a single incident. It can be hundreds of smaller breaches across industries, jurisdictions, and personal lives.

Boards and regulators scrutinize third party risk, including law firms. Security posture is now a competitive differentiator: clients expect evidence of controls, certifications, and audits, and firms that demonstrate real cyber resilience can turn it into an advantage rather than just a cost.

Also, for law firms, confidentiality is mission critical. A leak can undermine legal strategies, hurt clients in disputes or negotiations, trigger regulatory scrutiny, and damage the trust that underpins the client lawyer relationship. Attackers know this makes firms more likely to pay to prevent disclosure.

Unfortunately, not all firms have a strong cybersecurity posture. While some global firms have robust defenses, the sector also includes boutiques handling high stakes matters with minimal IT support, small and mid size firms relying on consumer grade tools, and solo practitioners without dedicated security expertise.

Databases as prime extortion fodder
Today’s ransomware and data theft campaigns often use “double” or “triple” extortion. Social engineering plays a large part in that, as criminals often trick attorneys and staff into revealing passwords, clicking malicious links, or approving fraudulent access requests that look like routine IT or client communications. They may impersonate partners, clients, vendors, or even court personnel to build trust and bypass normal security checks, giving them a direct path into email accounts, document repositories, and case systems.

Once inside, they quietly map the firm’s environment and exfiltrate data before launching the visible attack. They steal sensitive files and threaten to leak them, contact clients, or alert regulators if the firm doesn’t pay. In more aggressive cases, they go further and directly extort the firm’s clients, using the stolen data as a launchpad for multiple extortion schemes.

Even with good backups to restore systems, the threat that confidential client information could be exposed, used against them in disputes, or leveraged to pressure individual clients is potentially devastating for both the firm and everyone it represents.

Information tailored for maximum pressure
Not all leaked data has equal extortion value. Law firm databases hold information that creates maximum leverage:

  • Pending deals and IPOs: Premature disclosure or rumors can derail transactions or damage valuations.
  • Litigation strategies and settlements: Exposing negotiation positions, amounts, or terms can disrupt ongoing disputes.
  • Internal investigations and compliance reports: Often involve potential violations or misconduct that organizations urgently need to manage discreetly and legally.
  • Personal and family information: High-net-worth clients and executives share sensitive financial and personal details whose exposure risks both reputational harm and physical security.

Attackers don’t need legal expertise, only the ability to spot, “If this goes public, someone loses.” That loss drives their extortion.

Paying to prevent exposure can seem like the quickest way to protect clients, but it’s dangerous: attackers may still leak or sell data, and payments can raise law enforcement, sanctions, and anti–money laundering issues while leaving core security flaws untouched.

This collides with lawyers’ ethical duties. Firms must juggle confidentiality, regulatory reporting, client notification, and reputation under intense time pressure, especially when criminals time attacks before key hearings, filings, or deals.

Plus, client expectations are rising. Boards and regulators scrutinize third party risk, including law firms. Security posture is now a competitive differentiator: clients expect evidence of controls, certifications, and audits, and firms that demonstrate real cyber resilience can turn it into an advantage rather than just a cost.

From a cyber claims specialist perspective
We’re seeing a clear claims trend: law firms are being hit more often, and the fallout is more severe. After a breach, the number of firms targeted by class actions continues to grow. Even with strong incident response, exposure can still be significant, and settlements often exceed those in comparable data security cases, driven by reputational harm, impact on client relationships, and heightened regulatory scrutiny.

After more than a decade handling cyber claims and incident response across industries, one pattern is clear: firms that treat cybersecurity as a core professional duty -- not just an IT issue -- consistently fare better.

Three considerations consistently make the difference:

  • Preparation pays off. Firms with tested incident response plans, employee training, reliable backups, and clear governance resolve incidents faster, often avoid or reduce ransom payments, and communicate more credibly with clients and regulators. When the groundwork is in place, incidents are more likely to stay contained; when it isn’t, they tend to spiral into crises that reshape the firm’s relationships and reputation.
  • Insurance is a safety net, not a strategy. Cyber insurance can fund forensics, legal support, notifications, and business interruption. But insurers now closely scrutinize security controls. The firms that handle breaches best have a strong relationship with a skilled broker and cyber insurer, know exactly what their policy covers, and have aligned their security and governance to that coverage.
  • The best “negotiation” happens before a breach. Strong controls, documented practices, and a mature response posture give firms leverage with insurers, regulators, and even attackers. They reduce both the likelihood and the impact of extortion.

Looking ahead, the profession’s challenge is moving from “high-value target” to “resilient partner” by investing in cybersecurity in line with the value of the data they hold. This shift also requires collaborating across the sector by sharing threat intelligence, joining collective defense initiatives, and adopting common minimum standards to raise the baseline and stave off easy attacks.

Law firm databases are both the profession’s greatest asset and its greatest weakness. Criminals view them as prime extortion material; lawyers should treat them as a clear call to modernize. Firms that weave cybersecurity into their duty of care, their governance, and their client service won’t eliminate risk, but they can shift from easy targets to resilient, trusted partners.

 

To contact the author of this story, please complete the below form

First Name is required
Last Name is required
Country is required
Invalid email Email is required
 
Invalid Captcha
Subscribe

More Articles

Subscribe to Fast Fast Forward

Global Asset Protection Services, LLC, and its affiliates (“AXA XL Risk Consulting”) provides risk assessment reports and other loss prevention services, as requested. In this respect, our property loss prevention publications, services, and surveys do not address life safety or third party liability issues. This document shall not be construed as indicating the existence or availability under any policy of coverage for any particular type of loss or damage. The provision of any service does not imply that every possible hazard has been identified at a facility or that no other hazards exist. AXA XL Risk Consulting does not assume, and shall have no liability for the control, correction, continuation or modification of any existing conditions or operations. We specifically disclaim any warranty or representation that compliance with any advice or recommendation in any document or other communication will make a facility or operation safe or healthful, or put it in compliance with any standard, code, law, rule or regulation. Save where expressly agreed in writing, AXA XL Risk Consulting and its related and affiliated companies disclaim all liability for loss or damage suffered by any party arising out of or in connection with our services, including indirect or consequential loss or damage, howsoever arising. Any party who chooses to rely in any way on the contents of this document does so at their own risk.

US- and Canada-Issued Insurance Policies

In the US, the AXA XL insurance companies are: Catlin Insurance Company, Inc., Greenwich Insurance Company, Indian Harbor Insurance Company, XL Insurance America, Inc., XL Specialty Insurance Company and T.H.E. Insurance Company. In Canada, coverages are underwritten by XL Specialty Insurance Company - Canadian Branch and AXA Insurance Company - Canadian branch. Coverages may also be underwritten by Lloyd’s Syndicate #2003. Coverages underwritten by Lloyd’s Syndicate #2003 are placed on behalf of the member of Syndicate #2003 by Catlin Canada Inc. Lloyd’s ratings are independent of AXA XL.
US domiciled insurance policies can be written by the following AXA XL surplus lines insurers: XL Catlin Insurance Company UK Limited, Syndicates managed by Catlin Underwriting Agencies Limited and Indian Harbor Insurance Company. Enquires from US residents should be directed to a local insurance agent or broker permitted to write business in the relevant state.