Why Ransomware Groups Target Law Firms (and What Happens When They Hit)
Law firms are disproportionately targeted by ransomware. The reasons are specific, the consequences are expensive, and the timing matters if your cyber policy renews this fall.
In July, the Anubis ransomware gang hit Coca-Cola’s dairy subsidiary Fairlife, encrypted their Nutanix systems, and stole a terabyte of data. Coca-Cola refused to pay. The data was published in full on July 27.
That same month, two class action lawsuits moved forward against Blank Rome, a 600-attorney Am Law 100 firm, after attackers impersonated IT support staff and accessed records belonging to 57,000 people.
This is the pattern, not the exception.
Why law firms specifically
Ransomware groups don’t pick targets at random. They evaluate potential victims the same way a burglar evaluates houses: what’s inside, how hard is it to get in, and how likely is the owner to pay.
Law firms score high on all three.
The data is uniquely sensitive. A manufacturing company loses production data. A law firm loses privileged communications, litigation strategy, M&A documents, estate plans, client financial records, and immigration files. The ethical obligations surrounding that data create pressure that doesn’t exist in other industries. A breach means potential bar complaints, malpractice claims, and mandatory client notifications on top of the operational damage.
The payment pressure is real. Attorney-client privilege means that stolen data can’t just be “monitored” after a breach the way a stolen Social Security number can. Once privileged communications are published, the damage is done and it can’t be undone. Ransomware operators know this. They also know that law firms face reputational consequences that make paying a ransom look cheaper than the alternative.
The security investment often lags the risk. Mid-size firms (20 to 100 attorneys) typically don’t have a dedicated CISO or a security operations team. They rely on their IT provider or a small internal team. If that provider hasn’t kept pace with the threat landscape, the firm’s defenses may be years behind what attackers are bringing.
Baker Hostetler’s 2025 incident response report found that cyberattacks targeting law firms doubled year over year. The FBI has publicly stated that groups like Silent Ransom specifically target law firms because of the nature of the data they hold.
What a hit actually looks like
The insurance industry and breach response data paint a consistent picture of what happens when a mid-size firm gets hit.
Operations stop. Document management systems go offline. Email goes dark. Court deadlines get missed. Attorneys can’t access case files, billing records, or client communications. In the Fairlife case, physical production halted for weeks across four facilities. For a law firm, the equivalent is every attorney sitting idle while the firm pays their salaries and the clock runs on client deadlines.
The extortion is layered. Modern ransomware is almost always “double extortion.” They encrypt your systems AND steal data before encrypting. Even if you have good backups and can restore operations, they still hold your data hostage. Pay to decrypt, pay again to prevent publication. Some groups have moved to triple extortion: contacting your clients directly and demanding payment from them.
The costs compound. Forensic investigation, legal counsel, client notification, credit monitoring, regulatory filings, potential bar complaints, business interruption losses, and reputational damage. For a mid-size firm, total breach costs routinely exceed $500,000 even without paying a ransom.
The insurance connection
If your firm’s cyber liability policy renews in Q3 or Q4, this is directly relevant. Underwriters read the same headlines. They know law firms are disproportionately targeted. And their response has been to tighten requirements and scrutinize applications more closely.
Our post on what your cyber insurance carrier expects from your IT covers the specific technical controls underwriters are asking about: MFA everywhere, endpoint detection, isolated and tested backups, documented incident response plans, privileged access management.
The part that catches firms off guard is the attestation. Your application asks whether you have these controls in place. You check “yes.” The policy gets issued. Then you get hit, file a claim, and the carrier’s forensic team discovers that what you attested to wasn’t accurate. The claim gets denied.
This is happening. Carriers are denying claims based on attestation gaps. If your firm checked “yes” on MFA but three partners still log in with just a password, or you attested to tested backups but haven’t actually run a restore in two years, that’s a denial waiting to happen.
What to do before renewal
If your renewal is coming up in the next few months, here’s what’s worth checking now rather than scrambling later.
Verify your MFA coverage is complete. Not just email. Remote access, VPN, administrative accounts, cloud applications. Every partner, every associate, every staff member. No exceptions for the managing partner who doesn’t like the extra step.
Confirm your backups are tested and isolated. Not just running. Tested. Can your IT provider show you a successful test restore from the last 30 days? If they can’t, that’s a conversation to have before your carrier asks.
Document your incident response plan. It doesn’t need to be 50 pages. It needs to exist, it needs names and phone numbers, and the people in it need to know they’re in it.
Run a privileged access audit. Who has administrative access? Why? Is it logged? Ransomware operators look for admin credentials first because they unlock everything. If every user at your firm has local admin rights, you’re making their job easier.
Ask your IT provider what changed since last year. Threats evolve. If your security posture is the same as it was 12 months ago, it’s probably not enough anymore.
The timing matters
Ransomware groups don’t take summers off. Renewal season for many firms falls in Q3 and Q4. The intersection of those two facts means the next few months are when your firm’s security posture will be tested and evaluated, both by attackers looking for targets and by underwriters deciding whether to cover you.
The firms that come through this well are the ones that treat security as an ongoing operational requirement rather than a checkbox they fill out once a year on an insurance application.
If your firm needs help preparing for a renewal or confirming that your controls actually match what you attested to, that’s a conversation worth having before the carrier asks.

