Moses & Singer Listed by SilentRansomGroup Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Moses & Singer was listed by the SilentRansomGroup ransomware group on August 02, 2026, after internal files were exfiltrated in a ransomware attack; the date of the actual intrusion has not been established. Anyone who has shared data with the firm should check whether their information was exposed and take appropriate protective steps.
Law firms remain a persistent target in today’s ransomware landscape, where attackers seek not only to encrypt systems but to exfiltrate internal material that can be leveraged for pressure and secondary harm. Professional-services organisations hold concentrated stores of client, transactional, and proprietary information, making them attractive to groups that operate leak sites and double-extortion models.
On August 02, 2026, Moses & Singer was reported as listed by the ransomware group SilentRansomGroup. Public detail is limited: the number of people affected is unknown, and the material described is internal files said to have been exfiltrated in a ransomware attack. The listing itself is a claim by the group and has not been independently confirmed in the available record. For clients, counterparties, and staff, even an unverified claim warrants calm attention to what is known and what practical steps remain useful.
Inside the incident
According to the reported record, Moses & Singer LLP appeared on a listing associated with SilentRansomGroup on August 02, 2026. The organisation is described as a full-service law firm specialising in corporate transactions and intellectual property–related work, among other practice areas. The facts state that internal files were exfiltrated in a ransomware attack. No confirmed figure for individuals affected has been published. Timing of the underlying intrusion, the precise method of initial access, the volume of data, and any ransom demand or negotiation outcome are not disclosed in the available information.
What is on the public record, therefore, is a group claim of compromise and exfiltration rather than a fully documented forensic account. Until the firm or independent investigators provide further verified detail, the scale and exact contents of any exposure remain unconfirmed. Readers should treat the leak-site listing as an assertion by the threat actor, not as established proof of every claimed element.
Who is SilentRansomGroup?
SilentRansomGroup is a ransomware actor known in public reporting for double-extortion tactics: encrypting victim environments while also copying data and threatening to publish or auction it if demands are not met. Groups of this type commonly maintain leak or negotiation sites where they name organisations and, in some cases, sample or dump material to increase pressure. Their operations typically rely on initial access through phishing, compromised credentials, exposed remote services, or other common enterprise entry points, followed by lateral movement, data staging, and deployment of ransomware.
Public documentation of SilentRansomGroup’s broader activity describes a pattern of targeting organisations that hold sensitive commercial or professional data. That general profile does not, by itself, prove every detail of any single listing. In this case, the facts support only that Moses & Singer was listed and that internal files were described as exfiltrated; they do not include verified quotes, file counts, or specific claims the group may have posted beyond that framing. Any assertion on a leak site should be read as the actor’s claim until corroborated.
Moses & Singer and its sector
Moses & Singer LLP is a full-service law firm whose reported focus includes corporate transactions and intellectual property work. Law firms in this segment routinely handle deal documents, contracts, correspondence, billing records, and privileged communications. They may also hold identity and contact details for clients, opposing parties, experts, and employees, as well as matter-related financial and strategic information.
A breach or claimed breach at a law firm is consequential because the data involved is often confidential by design, sometimes subject to privilege or regulatory expectations, and frequently valuable to competitors, litigants, or criminals who specialise in fraud and extortion. Even when the full scope is unknown, the sector’s role as a trusted intermediary means that disruption or data exposure can affect not only the firm but also the clients and counterparties whose matters sit in its systems.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as specific categories of personal data, client lists, or document types—is provided in the available record. The number of people affected is unknown.
Organisations of this kind typically hold matter files, emails, contracts, identity and contact information, billing and trust-accounting related records, and other internal work product. That is a general description of the sector, not a confirmed inventory of what was taken here. Exact contents remain unconfirmed. No assumption should be made that any particular client’s file or any named individual’s data was included unless and until verified notice is issued.
Why it matters
For people who may be connected to the firm—clients, employees, vendors, or others—the practical risks of internal-file exposure in a legal context include targeted phishing that references real matters, social-engineering attempts that misuse names and case details, and longer-term misuse of personal or financial identifiers if such data were present. Privilege and confidentiality concerns can also create professional and reputational consequences for the organisation and for the parties whose information was entrusted to it.
For the firm, a ransomware incident that includes exfiltration claims can mean operational disruption, investigative and recovery costs, notification and regulatory obligations where applicable, and sustained attention from clients who need assurance about how their matters were handled. Because the people-affected count and precise data types beyond “internal files” are undisclosed, the individual residual risk cannot be quantified from public facts alone. The prudent response is still to assume that heightened vigilance is warranted until clearer information emerges.
What to do if you're exposed
If you have a relationship with Moses & Singer or reason to believe your information may have been involved, start with basics: treat unexpected emails, calls, or messages that reference legal matters or the firm with scepticism; verify any request for money, credentials, or documents through a known separate channel; and monitor financial and credit activity for unusual behaviour. If you receive direct notice from the firm, follow the instructions in that notice, including any offer of credit monitoring or identity-protection services. Preserve copies of suspicious communications. Consider updating passwords on important accounts, especially if you reused credentials, and enable multi-factor authentication where available.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets. That check does not confirm or deny involvement in this specific incident, but it can help you prioritise further monitoring and password hygiene while official detail remains limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Fox Rothschild LLP Listed by SilentRansomGroup Ransomware GroupBarclay Damon Listed by SilentRansomGroup Ransomware GroupMarshall Dennehey Listed by SilentRansomGroup Ransomware GroupPorter Wright Listed by SilentRansomGroup Ransomware GroupLatest breaches
Publicly posted by silentransomgroup — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.