Custom IT Solutions for All Types of Industries

Data Collaboration Services empowers industry-specific transformation through secure, scalable, and intelligent data solutions.

Cloud Solutions

Finance

Financial institutions in New York are not only bound by national regulations like PCI-DSS, SOX, and GDPR, but also face local regulatory demands, such as those set by the NYDFS.
Data Backup & Recovery

Healthcare

Healthcare providers today face the dual challenge of improving patient care while navigating complex technological and regulatory requirements.

The Most Powerful Law Firm in America Was Breached by a Phone Call.

Jones Day, one of America’s leading law firms, confirmed a cyber breach involving no malware or ransomware. Attackers used a fake invoice email and impersonated IT support by phone, accessing files tied to 10 clients. The Silent Ransom Group claimed responsibility, prompting an FBI warning to law firms.

Published

What Happened

No malware. Just a convincing lie.

Earlier this year, Jones Day a firm routinely ranked among the most powerful in the world confirmed that an unauthorized third party had accessed a limited number of dated files belonging to 10 of its clients. The firm notified those affected and stated the access was contained to a specific, narrow set of records.

What makes this breach worth your attention isn’t the size. It’s the method. The attackers didn’t break a firewall or deploy ransomware. They used social engineering: an invoice-themed phishing email sent from an ordinary consumer email account no malicious link, no attachment, nothing for a spam filter to catch. The email simply set the stage for a follow-up phone call from someone impersonating corporate IT support, talking an employee into granting access.

Responsibility was claimed by the Silent Ransom Group (also tracked as Luna Moth, UNC3753, and Chatty Spider), which added Jones Day to its dark-web leak site. This is the same playbook the group has run against dozens of organizations across the legal, financial, and professional-services sectors and it is the reason the FBI issued a FLASH advisory warning U.S. law firms specifically.

By the Numbers

A small breach with a loud warning

10
Jones Day clients whose files attackers accessed
0
Pieces of malware or encryption used pure social engineering
4th
Legal sector’s rank among industries most targeted by ransomware in early 2026
20
Law firms & legal orgs the INC Ransom group alone claimed in 2026
Dozens
Organizations Silent Ransom Group hit Jan–May 2026 across legal & finance
~2x
Increase in reported law-firm incidents over the prior year
Key Facts

How the Silent Ransom Group operates

The anatomy of a no-malware extortion attack

  • Step 1 The bait: An invoice-themed email from a free consumer account, with no link or attachment, so nothing trips a security filter
  • Step 2 The call: A follow-up phone call from an attacker posing as internal IT support, pressuring staff to grant remote access
  • Step 3 The hunt: Once inside, they search document-management platforms and cloud storage for contracts, tax records, Social Security numbers, and M&A files
  • Step 4 The exfiltration: Data is quietly copied out using legitimate tools like WinSCP and Rclone not malware
  • Step 5 The squeeze: No files are encrypted; instead the victim is named on a leak site and extorted to keep the data private
  • The group has even sent operators to law firms’ physical offices in person, impersonating IT staff to gain network access

Notice what’s missing from that list: anything your antivirus would flag. There’s no virus to detect, no encrypted drive to recover. The “exploit” is a trusting human being doing what they thought was their job. That’s exactly why these attacks are so effective against firms that have invested heavily in technical defenses but not in their people.

The Cascade

Why law firms are the soft target with the hardest data

Attackers love law firms for a simple reason: you hold everyone else’s secrets. A single firm’s systems can contain merger plans, litigation strategy, settlement figures, tax filings, and the personal data of thousands of clients and their customers. Breach one firm and you’ve effectively breached every client it represents.

The Silent Ransom Group has industrialized this. The same email-then-call routine that snared Jones Day is being aimed at firms of every size and smaller firms are arguably easier marks, because the receptionist or paralegal who takes the “IT support” call may have no script for what to do and no second person to verify with. The attackers are betting on politeness and urgency, and both are abundant in a busy practice.

There’s also a reputational multiplier unique to legal work. A breach doesn’t just expose data it can puncture attorney-client privilege, the foundation of the client relationship. That’s precisely the leverage the extortionists are counting on: the fear that confidential files going public will cost you clients you can never win back.

Legal & Regulatory Fallout

A “limited” breach still triggers a full obligation

Even a contained incident affecting a handful of clients carries real consequences. Jones Day was required to notify the affected clients, and any breach involving personal information pulls in a patchwork of state breach-notification laws, each with its own deadlines and penalties. Where client data includes health or financial records, federal frameworks layer on top.

For law firms specifically, there’s a professional dimension consumer businesses don’t face. State bar rules of professional conduct obligate attorneys to take reasonable steps to safeguard client information and, in many jurisdictions, to inform clients when that information may have been compromised. A breach can become an ethics question, not just an IT question.

And the plaintiffs’ bar is paying attention. Data-breach class actions now follow disclosures almost reflexively. A firm that can’t show it took reasonable, documented precautions staff training, verification procedures, access controls is far more exposed when the lawsuits and bar inquiries arrive.

Action Steps

What your firm should do this week

  1. Set a verification rule for “IT support” calls. No one grants remote access or shares credentials based on an inbound call. Require staff to hang up and call back a known internal number every time, no exceptions for “urgent.”
  2. Train your people on this exact attack. Tell your team the Jones Day story. The threat isn’t a mysterious hacker it’s a polite phone call and a fake invoice. Run a short phishing-and-vishing drill so the next call doesn’t catch anyone off guard.
  3. Lock down remote-access tools. Inventory every program that allows remote control of a workstation, restrict who can install or approve them, and require multi-factor authentication on everything that touches client files.
  4. Watch your document platforms for bulk downloads. The data left via WinSCP and Rclone. Enable alerts for large or unusual exports from your document-management and cloud-storage systems so exfiltration is caught in minutes, not weeks.
  5. Have a breach-response and notification plan ready. Know in advance who you call, how you preserve evidence, and how you meet client-notification, state-law, and bar obligations before you need it.
The Bottom Line

Your firewall didn’t fail. Your phone rang.

The lesson of the Jones Day breach is humbling precisely because the firm is so formidable. With resources most practices can only imagine, it was still beaten by the oldest trick there is: a confident stranger asking for access. No technology gap was exploited. A human one was.

That’s the good news and the bad news. Bad, because you can’t buy a box that fixes it. Good, because the defense is within reach of any firm willing to build it: a culture where every request to “verify your account” or “let me in to fix something” is met with a callback to a number your people already trust. If you’re not sure your team would pass that test today, that’s the gap to close now before the call that matters is a real one.

Stay Ahead of Threats

Get weekly insights on the latest vulnerabilities, breach analysis, and defense strategies delivered directly to your inbox.

End-to-end encrypted delivery