PROFESSIONAL SERVICESSEPTEMBER 9, 2026By Nate Medeiros, CEO & Founder

Social Engineering Is Coming for Law Firms, Big and Small

Privileged communications, deal files, and client escrow accounts make law firms irresistible targets. The FBI says one criminal group has focused on law firms since 2023, and it goes after the people, not the perimeter.

Key takeaway

Law firms concentrate what attackers want most: privileged communications, deal information, and client escrow funds. The FBI warns that one criminal group has specifically targeted US law firms since 2023, using fake IT support calls and even in-person visits. The defense that matters most is protecting people at the moment they act.

Warning lines converging on a courthouse beneath the scales of justice, flanked by a locked folder of privileged documents and a client escrow vault

Law firms are in the business of holding other people’s secrets.

Litigation strategy. Merger and acquisition terms before they are public. Intellectual property filings. Sealed court records. Medical histories from personal injury cases. Financial disclosures from divorces. And, at many firms, client escrow accounts holding millions of dollars in transit between parties. A single partner’s mailbox can contain the most sensitive information of dozens of clients at once.

Cybercriminals have noticed, and the past few weeks have made that hard to ignore. In September 2026, Reuters reported (https://www.reuters.com/legal/government/data-law-firms-quinn-emanuel-mcdermott-exposed-cyber-breaches-2026-09-03/) that two prominent U.S. firms, Quinn Emanuel and McDermott Will & Emery, had disclosed recent data breaches and notified law enforcement. These are large, sophisticated organizations with real security budgets. They are not outliers: the ABA’s 2024 Legal Technology Survey found that 29 percent of responding firms confirmed they had experienced a breach (https://attorneyarmor.com/blog/data-breach-prevention-law-firms), and another 36 percent could not say whether they had been breached or not.

The pattern behind those numbers should sound familiar to anyone who read our look at social engineering against accounting firms. The way into a law firm is rarely a firewall exploit. It is a person: an associate rushing to answer opposing counsel, a paralegal opening what looks like a court notice, a billing manager processing what appears to be a routine wire request.

Why Are Law Firms Such Attractive Targets?

Law firms concentrate high-value information from many organizations behind a single, often thinner, layer of defense. An attacker who breaches one company gets one company’s secrets. An attacker who breaches a law firm can get the secrets of every client the firm serves, already sorted into matters, already labeled by significance. The same analysis of law firm incidents found that phishing and business email compromise account for roughly 38 percent of law firm breaches (https://attorneyarmor.com/blog/data-breach-prevention-law-firms), the largest single category, ahead of stolen credentials and unpatched systems.

Three things make the legal sector especially appealing:

  • Privilege concentrates value. Privileged communications and deal files are exactly the material extortion groups can credibly threaten to publish, because the damage from exposure is immediate and often irreversible.
  • Trust and escrow accounts hold real money. Real estate and transactional firms are, functionally, banks that practice law. Funds moving through a closing are a one-time window that attackers race to exploit.
  • The culture rewards responsiveness. Lawyers are trained to respond quickly to clients, courts, and opposing counsel. Urgency is not a red flag in a law firm. Urgency is the job.

Confidentiality is also not optional. Under Model Rule 1.6 and ABA Formal Opinion 483, lawyers have an ethical duty to make reasonable efforts to prevent unauthorized disclosure of client information and to notify clients when a breach occurs, obligations the ABA walks through in its cybersecurity guidance for legal professionals (https://www.americanbar.org/groups/law_practice/resources/tech-report/2022/cybersecurity-law-firms/). A firm that loses client data does not just have a security problem. It has a professional responsibility problem.

The Attack Campaign Built Specifically for Law Firms

Attack chain from a fake IT support phone call to an impostor being welcomed into an office and files being copied to a USB drive

Most industries worry about opportunistic attacks. Law firms have earned a dedicated adversary. In May 2025, the FBI issued an alert about the Silent Ransom Group (https://www.fbi.gov/file-repository/cyber-alerts/silent-ransom-group-targeting-law-firms-052325.pdf), also known as Luna Moth, which has consistently targeted U.S. law firms since spring 2023, likely because of how sensitive legal industry data is.

The group’s playbook is social engineering from start to finish. Early campaigns used callback phishing: an email charges a small subscription fee, the victim calls to cancel, and the friendly agent on the line walks them through installing remote access software. By spring 2026 the group had evolved to directly impersonating the victim firm’s own IT department, calling employees or urging them by email to call, then talking them into granting a remote desktop session.

And when the phone call fails, they show up in person. Google’s threat intelligence team and the FBI reported in June 2026 (https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/) that the group had targeted dozens of organizations in the first five months of the year, in some cases sending impostors posing as IT technicians into victims’ offices to copy files onto USB drives. Because the group relies on legitimate remote access and file transfer tools rather than malware, traditional antivirus rarely flags any of it.

Notice what every stage of that attack has in common: no exploit, no malware, no broken firewall. Each step is a person being persuaded to help. It is the same handoff we described in our analysis of attackers calling employees and walking them into the attack: the call builds trust, and the damage happens at the follow-through, the remote session granted, the software installed, the credentials entered.

What Does a Breach Actually Cost a Law Firm?

The invoices from recent legal-sector breaches are public, and they are instructive at every firm size. Orrick, Herrington & Sutcliffe, an AmLaw 100 firm whose practice includes advising clients on data breaches, paid $8 million to settle a class action (https://www.law.com/americanlawyer/2024/11/08/judge-approves-orricks-8m-data-breach-settlement-while-gunster-agrees-to-8-5m/) after a 2023 breach that ultimately affected more than 637,000 people. The same report notes that Gunster, a Florida midsize firm, agreed to pay $8.5 million over a breach that affected fewer than 10,000. The settlement math does not scale down just because the firm is smaller.

For firms that hold client funds, the losses can arrive overnight. In January 2026, attackers gained access to the online banking environment of Rabideau Klein, a two-partner Palm Beach real estate firm, and drained $17.3 million from its client escrow account in 13 unauthorized wire transfers (https://therealdeal.com/miami/2026/06/12/law-firm-sues-first-horizon-over-17-million-cyber-attack/) in a single morning. The firm recovered $10.7 million; roughly $6.5 million remains missing, and the firm is now litigating with its own bank over who absorbs the loss.

Then come the obligations that follow every breach: determining what client information was accessed, notifying affected clients under Formal Opinion 483, state notification filings, and the conversation no managing partner wants to have, explaining to a client why their privileged files are in someone else’s hands. For a business built entirely on confidentiality and trust, that conversation is the real cost.

Small Firms Are Not Flying Under the Radar

It is tempting for a ten-lawyer firm to assume attackers only care about the AmLaw 200. The data says otherwise. The ABA’s most recent survey results show that firms of 10 to 49 attorneys report the highest breach rates (https://petronellatech.com/blog/cybersecurity-law-firms-compliance/) of any size band.

The economics explain why. A small firm handling real estate closings moves the same seven-figure wires as a large one, but often without a security team, without 24/7 monitoring, and with IT handled by whoever is least busy that week. Attackers do not need the biggest target. They need the most favorable ratio of value to resistance, and small and midsize firms sit exactly there. Rabideau Klein had two name partners. It also had a $17 million escrow account.

Why Doesn’t Security Awareness Training Solve This?

Law firms train. Most have annual security awareness modules, phishing reminders in the onboarding packet, and a policy binder that says never wire funds without verification. The problem is not that lawyers skip the training. The problem is that the training is not present when the attack is.

A lawyer’s workday is engineered against caution. Court deadlines do not move. Clients expect responses in minutes. Opposing counsel sends attachments all day, every day, and new-client inquiries arrive from strangers as a matter of course. An attacker does not have to make a lawyer careless. They only have to make one message look like the work the lawyer was already rushing to do.

So the associate who completed training in January still clicks the fake court notice in August, because it referenced a real case number. The billing manager still processes the revised wire instructions, because the email came from the actual client’s compromised mailbox. Knowing what phishing looks like in a slide deck is not the same as recognizing it inside a busy Tuesday. Training that happened months ago cannot help with a decision happening right now.

What Does Protection at the Moment of Decision Look Like?

A shield intercepting a lawyer's risky click on a fake login page, with a short lesson offered after the block

The alternative is to put a layer of protection where the decisive step actually happens. Whether the lure arrives by email, by phone, or through a website contact form, the damage almost always runs through the browser: the fake login page that harvests the credentials, the download that installs the remote access tool, the page collecting the wire details. We made this argument in why phishing protection cannot end at the inbox, and the legal sector may be its clearest illustration, because so many law firm attacks never touch a spam filter at all.

A protection-first approach analyzes actions as they happen. When an employee is about to enter credentials on a suspicious page or grant access to an unfamiliar tool, the system steps in before the action completes. Then, instead of a write-up or a generic reminder, the employee gets a short lesson tied to the exact situation they just experienced: what was detected, why it was dangerous, and what to check next time.

That order matters. Protect first, teach second. The associate is not expected to be a security analyst at 6 p.m. on a filing deadline, and the lesson lands while the close call is still fresh, which is precisely when people actually learn.

Protecting the Firm Means Protecting the Client

Every risky action that gets interrupted is an incident that never happens. For a law firm, one protected click can prevent:

  • credential theft from a partner’s mailbox full of privileged communications
  • fraudulent wire instructions reaching a client trust or escrow account
  • a remote access session that becomes a firm-wide data theft
  • exposure of deal terms, litigation strategy, and sealed records
  • attacks launched at clients from the firm’s own trusted addresses

That last point deserves emphasis. When a firm’s email is compromised, the attacker inherits the trust of every client relationship in it. Clients act on instructions from their lawyer’s real address, which is exactly how closing funds end up in criminal-controlled accounts. Protecting the people inside the firm is how the firm keeps its side of the confidentiality bargain.

Security Should Not Depend on Perfect Lawyers

Attorneys need to practice law. Paralegals need to move matters forward. Billing teams need to move money on schedule. None of them chose a career in threat detection, and a security program that quietly assumes everyone will spot every convincing fake is a program designed to fail. As AI makes those fakes cheaper and more fluent, the assumption only gets worse.

The firms that stay out of the breach notices will be the ones that build for reality: people under deadline pressure will sometimes click, and the security layer should be standing between that click and the consequence. The human layer is now the most targeted part of a law firm. It deserves a defense of its own.

How SavvyShield helps: SavvyShield puts the protection-first model described here into practice for firms of every size. It works where legal professionals actually make decisions, in the browser and email environment, detecting and blocking risky actions like fake login pages and suspicious downloads before they become incidents, then reinforcing each close call with a short, targeted lesson. Over time, realistic simulations and adaptive human risk management find and strengthen the firm’s weakest points automatically, with no campaigns for anyone to run.