Big Law hackers pocket $50m in ransoms this year as fresh breaches emerge

Published:
August 10, 2026 5:00 PM
Need to know

HSF Kramer is the latest law firm to experience a cyber incident involving sensitive personal information.

WilmerHale and Goodwin reportedly paid ransoms of at least $18 million and around $10 million respectively, according to The Insurer.

HSF Kramer is the latest victim of a Big Law cyber incident, adding to a series of attacks raising the stakes for major law firms.

US state regulatory filings show social security numbers and health records were involved in the incident.

This comes as WilmerHale and Goodwin reportedly paid eight-figure ransoms to Luna Moth, a cyber extortion group known for targeting law firms.

New reports

HSF Kramer told Non-Billable: "We experienced an incident earlier this year in a part of our US IT environment which was investigated and contained. The small number of people affected have been notified."

Last week, Luna Moth claimed that Mayer Brown was a victim of a leak. The firm told Non-Billable that “one of its personnel mistakenly sent a small number of documents to an unauthorised third party who had misrepresented their identity”.

Mayer Brown said it had launched an investigation, which confirmed that it was “an isolated incident and that the third party did not access our systems”.

Steep ransoms

The incidents come amid a wider run of cyberattacks against major law firms, with the financial consequences increasingly running into eight figures.

WilmerHale paid at least $18 million to Luna Moth following a recent breach, according to The Insurer, while Goodwin reportedly paid around $10 million to the same group.

A Goodwin spokesperson told Non-Billable: "The incident [this spring] occurred when a single Goodwin employee was deceived into turning over their credentials to an unauthorised party.”

Advertisement

Goodwin said it notified the "limited number" of clients whose data was involved, as well as affected individuals, and was offering complimentary credit monitoring and identity theft protection. The firm did not address the reported $10 million ransom payment.

WilmerHale did not respond to a request for comment by the time of publication.

Weil also reportedly paid between $18 million and $20 million following another attack earlier this year, while Jones Day reportedly declined to pay a $13 million demand before stolen files were published.

Big Law's cyber bill

Law firms are particularly attractive targets because of the sensitive information they hold, from deal documents to financial records and personal data.

The Goodwin and Mayer Brown incidents also highlight the role of social engineering in attacks on law firms, where a single set of compromised employee credentials can potentially provide access to sensitive client data.

For firms, the financial exposure extends well beyond any ransom payment. Forensic investigations, cybersecurity specialists, regulatory notifications, remediation and potential litigation can all add to the cost.

The attacks are also putting pressure on cyber insurance costs for law firms. At least one insurer has stopped taking on new law firm clients while seeking renewal increases of 10% to 20%, according to The Insurer, with other carriers also reportedly pulling back from new law firm business.

Advertisement
No items found.