LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › FBI Warns of Silent Ransom Group's In-Person Law Firm Attacks

HIGH severityUnverified claimHow we verify

FBI Warns of Silent Ransom Group's In-Person Law Firm Attacks: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 27, 2026
FBI Warns of Silent Ransom Group's In-Person Law Firm Attacks

Reported May 27, 2026.

HIGH
Severity
3
Data types exposed
May 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

FBI Warns of Silent Ransom Group's In-Person Law Firm Attacks was disclosed on May 27, 2026. The breach exposed client data, legal documents, and sensitive case files at law firms; if you or your organization may have been affected, review any notices from the impacted firms and take protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

The FBI issued an advisory on May 27, 2026, describing activity by Silent Ransom Group, also referred to as Luna Moth, against U.S. law firms. The warning states that the group has sought client data, legal documents, and sensitive case files through social engineering since 2023, including impersonation of IT staff by telephone or email and, in some instances, physical presence at firm offices. No victim count or list of affected organizations was included in the advisory.

Inside the incident

The advisory provides no specific dates for individual incidents beyond the group's reported activity since 2023. It notes that the group has obtained data for extortion without deploying encryption-based ransomware. The number of people or organizations affected remains undisclosed, and the FBI did not publish details on the volume or contents of any files removed.

How a breach like this happens

Incidents involving social engineering of this type typically begin with reconnaissance of an organization's staff and vendors. Attackers then contact employees by phone or email while posing as internal technical support or trusted third parties, seeking credentials or physical access. When successful, they locate and copy targeted files rather than encrypting systems. The absence of ransomware distinguishes these events from many other extortion operations and can delay detection.

Who is FBI Warns of Silent Ransom Group's In-Person Law Firm Attacks?

Law firms maintain large volumes of client records, contracts, litigation materials, and regulatory filings. These organizations operate under professional confidentiality obligations and often store information that is not publicly available. An advisory directed at this sector highlights the potential reach of the described activity across multiple clients and matters handled by any single firm.

What data was at risk

The advisory names client data, legal documents, and sensitive case files as the categories of information sought. No further inventory of exposed records has been released. Organizations of this kind routinely hold personal identifiers, financial details, medical information, and privileged communications; whether any of those specific elements were accessed in the reported incidents is unconfirmed.

What's at stake

Exposure of client and case materials can affect ongoing legal matters, settlement negotiations, and regulatory compliance for the individuals and entities involved. Law firms may face questions about their handling of confidential information even when the method of access lies outside their direct control. Clients whose records were copied have limited immediate visibility into how the material might be used.

What to do if you're exposed

Individuals who believe their information may have been held by an affected firm should contact that firm directly for any notifications issued. They can also request an explanation of what records were involved and what steps the firm is taking. Running a free exposure scan of their email address against known breach data provides one way to check for prior appearances of their information in public listings.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

Swiss Utility Energie Netze Bern Hit by Payload RansomwareJune 22, 2026ShinyHunters Claims 3.1TB NAIC Insurance Data BreachJune 18, 2026Virginia Museum of History & Culture Breached by TheGentlemenJuly 6, 2026SBI Software Hit by Genesis Data LeakJuly 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the FBI Warns of Silent Ransom Group's In-Person Law Firm Attacks →

Source: Dark Reading

Publicly posted — pending verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram