Managing Cyber Risk in Relationships with Law Firms
Protecting Financial Institution Data Outside the Enterprise Perimeter
Protecting client information and sustaining critical services across sectors
Financial institutions and organizations across sectors routinely entrust outside counsel with highly sensitive information. That information may be stored across a law firm's document management systems, shared with e-discovery providers, or retained long after a matter concludes. Law firms are responsible for safeguarding the information entrusted to them, while client organizations must understand and manage the risks associated with placing their data in another organization's care.
Recent attacks by Silent Ransom Group (SRG) demonstrate the consequences of that exposure. The FBI has reported that SRG has targeted US law firms since spring 2023, using IT impersonation and other social engineering techniques.
Recently, researchers have reported related activity affecting dozens of organizations across professional, legal, and financial services. LS-ISAO analysts reported a surge in activity during August and early September, with SRG publicly listing more than 29 law firms as claimed victims in 2026. In these cases, attackers persuaded employees to establish remote sessions using legitimate support software, then searched the systems and document repositories that those employees could already access.
Offering detailed direction and actionable strategies, particularly for engagements involving highly sensitive information, this advisory provides cross-sector guidance on how to safeguard data by building on existing information governance and security practices.