The FBI has issued updated warnings regarding the Silent Ransom Group (SRG), a threat actor that has consistently targeted U.S. law firms and other professional organizations through sophisticated social-engineering attacks. What makes this alert noteworthy is not simply that cybercriminals continue to target law firms, but that their tactics are evolving.
In prior alerts, SRG primarily relied on phishing emails and phone calls in which attackers impersonated IT support personnel and convinced employees to install legitimate remote-access software such as AnyDesk or TeamViewer. Once access was obtained, the attackers stole confidential information and attempted to extort the victim.
According to an FBI FLASH alert, SRG has expanded its tactics. In some cases, when remote-access attempts fail, individuals have reportedly appeared in person at victim locations claiming to be IT personnel. These individuals may request access to computers, connect external storage devices, or claim they need to create a backup or image a device.
Unlike traditional ransomware groups, SRG’s primary objective is often the theft of sensitive information rather than encryption of systems. For law firms, that may include client communications, litigation strategy, financial records, privileged information, and personally identifiable information.
Why This Matters to Law Firms
Law firms hold highly valuable information. They’re also uniquely vulnerable because lawyers and staff constantly communicate with clients, courts, vendors, and technology providers. Attackers understand that trust and urgency are often part of legal practice. A successful attack on a law firm can lead to a range of serious consequences, from exposure of confidential client information to malpractice claims arising from data breaches or missed deadlines.
Practical Steps Law Firms Should Consider
-
Establish a “No Unscheduled IT Access” Policy
No employee should permit remote access to a computer or network based solely on an incoming phone call, email, or text message. If someone claims to be IT support, employees should independently verify the request using known contact information. The contact information for dedicated IT personnel should be posted and readily available to all staff.
-
Verify All Visitors
Create a written procedure requiring reception staff and employees to verify the identity of any person claiming to be from vendors such as copier, telephone, internet, or IT/technology providers. Unexpected visitors should never be granted access to firm computers or network equipment without verification from firm management.
-
Train Employees to Challenge Unusual Requests
Employees should feel empowered to say they are not authorized to provide access and that the request needs to be verified first. A culture that encourages verification is often more effective than a culture that prioritizes speed.
-
Restrict Remote-Access Software
Many attacks involve legitimate remote-access tools rather than malware. Firms should work with their IT providers to identify which remote-access tools are authorized, and remove or monitor for unauthorized tools. If possible, restrict the download of any unauthorized software or tools.
-
Conduct a “Front Desk Test”
Consider whether your receptionist would know what to do if an unexpected individual arrived claiming to be from your IT company and requested access to a workstation. If you aren’t sure, now is a good time to establish a verification procedure.
-
Routinely Review Incident Response Procedures:
If a cyber incident were to occur, every person in the firm should know:
-
- Who to contact in the firm, and if that person is unavailable, who is next in line for contact
- How systems can be isolated quickly
- Whether the firm has cyber insurance, and who needs to notify the carrier
Final Thought
Cybersecurity threats continue to evolve, but many successful attacks still depend on a simple tactic: convincing a trusted employee to grant access. The latest FBI warning is a reminder that cybersecurity is no longer solely a technology issue; it is also a people, process, and training issue. Law firms should regularly train everyone, from partners to reception staff, on how to verify requests for access. Whether those requests arrive by email, phone, or at the front door, the answer is the same: verify first.


