Silent Ransom Group Breaches Global Law Firm Greenberg Traurig
The attack underscores a growing trend of high-touch social engineering targeting the legal sector's most sensitive data.
The international law firm Greenberg Traurig was targeted by the Silent Ransom Group (SRG) in September 2026, exposing the vulnerability of high-value legal data to sophisticated human-centric attacks. The breach marks another significant hit to the legal industry by a threat actor known for bypassing traditional software defenses.
On September 2, 2026, the Silent Ransom Group claimed responsibility for the compromise, posting stolen data to their dark web leak site. Following the public claim, Greenberg Traurig filed an official security-breach notice with the Vermont Attorney General on September 8, 2026, confirming that sensitive data had been exposed.
The Evolution of Legal Targeting
The Silent Ransom Group, also associated with the threat actor UNC3753 (known as Luna Moth), spent 2025 and 2026 aggressively targeting U.S. law firms. Unlike many ransomware collectives that rely on automated phishing or software exploits, SRG employs a "high-touch" methodology. This approach prioritizes social engineering and physical access to breach secure environments.
According to cybersecurity analysis, UNC3753 utilizes vishing—impersonating IT support staff via phone calls—to deceive employees into granting access. In some instances, the group has gone as far as physical intrusion into corporate offices to plant USB devices directly into internal networks, effectively leaping over perimeter firewalls.
Systemic Risks to Privilege
This breach is particularly consequential because it targets a top-ten global law firm, where the stakes involve not just corporate secrets but attorney-client privilege. When threat actors move beyond software vulnerabilities to exploit human psychology and physical security, traditional cybersecurity stacks become less effective.
The incident highlights a systemic risk across the legal sector. Law firms hold an immense concentration of sensitive intellectual property, merger and acquisition data, and litigation strategies, making them primary targets for espionage and extortion. The shift toward physical and social engineering suggests that the "human firewall" is currently the weakest link in protecting privileged legal communications.
Future Outlook
As the legal industry grapples with these tactics, the focus is expected to shift toward more rigorous physical security protocols and advanced employee training to counter vishing. While the breach has been confirmed via regulatory filings, the full scope of the stolen data and the specific nature of the compromised client files remain under scrutiny. Industry observers will be watching for whether other global firms report similar intrusions using the Luna Moth playbook.