Summary:
INC ransomware group claimed attacks against ten law firms and legal services organizations on their dark web leak site within a recent 48-hour period. The volume, sector specificity, and timing of these postings suggest the possibility of a coordinated campaign or a shared upstream compromise, such as a supply chain event affecting a common legal technology provider or managed services vendor. Organizations in the legal services industry should treat this cluster of activity as an elevated threat signal and take immediate steps to assess their exposure, review third-party dependencies, and validate backup and incident response readiness. Halcyon observed increased targeting against the legal services sector, with groups such as Silent (also known as LeakedData) targeting it almost exclusively in 2025. Halcyon continues to monitor this activity and will update this alert as new evidence emerges.
Background:
Between 2025 and early 2026, Halcyon tracked 200+ ransomware incidents affecting the Law Firms & Legal Services sector, underscoring that legal organizations have become a persistent target across multiple ransomware operations. Law firms are an attractive target due to the sensitivity of client data, regulatory pressure to resolve incidents quickly, and a perceived willingness to pay ransoms to protect attorney-client privilege and confidential case materials.
The INC ransomware group emerged as a ransomware-as-a-service (RaaS) operation first observed in mid-2023, known for double-extortion tactics involving data exfiltration and encryption. The group operates a dark web leak site where victim organizations are publicly listed if ransom demands are not met, as is common with many ransomware threat actors. INC has historically targeted a broad range of sectors, but recent activity reflects a pronounced concentration on law firms and legal services organizations.
The Silent ransom group, which emerged in March 2022 following the Conti ransomware syndicate collapse, has also been targeting on firms in the legal sector. Unlike INC, Silent operates as a pure data extortion group without deploying encryption and has intensified targeting of US law firms since spring 2023 using custom phishing and vishing campaigns. While there is no confirmed operational link between INC Ransom and Silent, the parallel targeting of the legal sector by multiple threat actors suggests ransomware gangs view law firms as attractive targets for extortion and attack.
Details:
- Concentrated Law Firm Targeting: Ten law firms and legal services organizations have appeared on the INC Ransom leak site within a 48-hour window, representing an unusual clustering of victims from a single sector. This volume and speed are atypical even for prolific RaaS operations and raises the possibility that these incidents are connected. In total, INC Ransom has claimed 20 law firms and legal services organizations in 2026. Silent has claimed 24 organizations providing legal services in 2025 and 1 in 2026.
- Possible Supply Chain Event: The concentration of law firm victims in a compressed timeframe is consistent with a potential supply chain compromise. This could be a shared legal practice management platform, document management system, e-discovery tool, or managed IT services provider used across multiple firms. A single upstream breach could provide an attacker with access to numerous downstream legal organizations simultaneously. There is currently no confirmed evidence of a specific supply chain vector, but the pattern warrants investigation by affected firms and their technology vendors.
- 2025-2026 Legal Sector Trend: Halcyon attack tracking data reflects a sustained increase in ransomware incidents affecting law firms and legal services throughout 2025 and into early 2026.
- Tactics, Techniques, and Procedures: INC Ransomware typically leverages known vulnerabilities in Citrix, Fortinet and SimpleHelp RMM that allow remote code execution for initial access. While Silent uses social engineering, callback phishing, and IT Help Desk scams. Both use common legitimate tooling to include WinSCP, RClone, and MegaSync for lateral movement and data exfiltration.
Mitigation:
- Supply Chain Risk Assessment: Law firms should immediately inventory third-party technology providers, managed service providers, and shared platforms. Review vendor security postures [M1016], assess whether any common provider has disclosed a breach, and monitor for indicators of compromise associated with upstream vendors [M1019]. Prioritize segmenting access from third-party tools to core systems and sensitive client data [M1030].
- Legal Sector-Specific Threat Awareness: Given the elevated targeting of law firms by both INC Ransom and Silent, legal organizations should treat this period as a heightened threat environment. Ensure that incident response plans account for double-extortion scenarios involving both data exfiltration and encryption, and that plans address obligations around attorney-client privilege and regulatory notification [M1025].
- Deploy Dedicated Anti-Ransomware Solution: Deploy dedicated anti-ransomware defenses to block malicious binaries pre-execution [M1038], detect runtime behaviors and data exfiltration attempts [M1040], prevent tampering and network intrusion [M1031], and protect the integrity of backups to reduce extortion leverage [M1053].
- Post-Encryption Response: If systems are encrypted, isolate affected systems to contain impact [M1030], preserve forensic evidence, and determine the scope of compromise using available logs and telemetry [M1047]. Engage experienced ransomware incident response specialists to support investigation, containment, recovery planning, and decision-making. Assess whether other firms sharing common technology providers have also been impacted.
- Backup and Recovery Validation: Verify that offline and immutable backups are current, tested, and isolated from production environments [M1053]. Ensure that backup restoration procedures can support recovery within acceptable timeframes without reliance on attacker-provided decryptors.
References:
Source Summary:
This Alert is based on Halcyon observations, open-source information, and ongoing research. Findings reflect our current understanding of threat actor activity and may be updated as new evidence emerges. Assessments may be revised as additional evidence becomes available.
The Halcyon Ransomware Research Center unites experts, drives smart policies, and delivers actionable intelligence to detect, disrupt, and defeat ransomware. Explore the Center’s latest reports, analysis, and resources here.
Click Here For The Original Source.
