SilentRansomGroup Claims Breach of Law Firm Greenberg Traurig
The multinational firm confirmed limited data exposure following a ransomware claim and a regulatory filing in Vermont.
Multinational law firm Greenberg Traurig has fallen victim to a cyberattack claimed by the ransomware collective SilentRansomGroup. The breach highlights the ongoing vulnerability of high-stakes legal repositories to targeted extortion attempts.
On September 2, 2026, SilentRansomGroup announced the compromise of the firm, listing Greenberg Traurig on a dark web leak site. The threat actors demanded the initiation of negotiations to prevent the release of sensitive data. Greenberg Traurig has since acknowledged that a limited amount of data was posted to the dark web. According to a regulatory filing submitted to the Vermont Attorney General on September 8, 2026, at least 10 residents of Vermont were affected by the incident.
The High Value of Legal Data
Law firms have become primary targets for ransomware operators because they serve as centralized hubs for highly sensitive information. These firms typically manage a combination of corporate secrets, pending litigation details, and intellectual property that can be leveraged for significant financial gain. This attack on Greenberg Traurig—a leading U.S.-based firm with more than 2,850 attorneys operating across 49 locations—follows a broader industry trend of escalating cyberattacks against professional service firms and critical infrastructure.
Industry Implications
Because of the scale of Greenberg Traurig's operations, a breach of this nature carries substantial risks. The potential exposure of confidential data belonging to high-profile corporate clients and government entities creates severe legal and reputational liabilities. For the legal industry, such incidents underscore the necessity of moving beyond standard encryption toward more robust, zero-trust security architectures to protect attorney-client privilege in a digital environment.
Future Outlook
While the firm has confirmed the leak of limited data, the full scope of the compromise remains unclear. Observers are watching for further disclosures on the dark web and potential class-action litigation following the regulatory filings. It remains to be seen whether other jurisdictions will report affected residents or if the threat actors will release additional tranches of data to pressure the firm into payment.