
Holland & Knight, Greenberg Traurig and Katten have confirmed separate cyber incidents in which attackers obtained files, including some containing client information.
The attacks come amid a wider wave targeting Big Law, with the FBI warning in May that Silent Ransom Group has been using social engineering tactics to target law firms.
Three major US law firms have confirmed separate cyber incidents, extending a wave of attacks targeting Big Law in recent months.
Holland & Knight, Greenberg Traurig and Katten all said that attackers obtained a limited number of files, although the firms said their wider systems remained operational or were not breached.
The incidents were first flagged by cyber intelligence websites, which attributed the attacks to Silent Ransom Group, a cyber extortion group that has increasingly targeted law firms and other professional services businesses.
Social engineering attacks
Holland & Knight said an attacker used social engineering techniques to gain unauthorised remote access to a firm computer.
The firm said the incident involved the same group that has targeted other law firms using similar tactics. It said a “small number of files” were involved, affecting 14 clients, who have been notified. Holland & Knight said its systems remained fully operational and there was no disruption to client services.
Katten also said its incident involved social engineering. The firm said attackers did not gain access to its systems or network but obtained a “limited number of files”, including “a very small number” containing client information.
Greenberg Traurig said an unauthorised actor accessed a limited number of documents. The firm said: “We are aware that the threat actor responsible for this incident has posted these documents on the dark web. We have directly notified the small number of affected clients.” It added that its systems had not been compromised and it was continuing to serve clients without disruption.
All three firms said they had contacted law enforcement.
The incidents come amid growing concern over Silent Ransom Group, which the FBI warned in May was actively targeting US law firms.
The group’s methods can be surprisingly simple. According to the FBI, attackers pose as IT support to gain access to victims’ computers remotely before quickly stealing sensitive data and threatening to publish or sell it unless a ransom is paid.
Big Law in the crosshairs
The latest incidents follow attacks involving several other major law firms, including Jones Day, Weil, HSF Kramer and Mayer Brown.
Silent Ransom Group has been targeting US law firms since at least 2023, according to the FBI.
The financial stakes can be significant. WilmerHale and Goodwin paid eight-figure ransoms following attacks this year, according to The Insurer, while Weil reportedly paid as much as $20 million after it was targeted.
Join 10,000+ City law professionals who start their day with our newsletter.
The essential read for commercially aware lawyers.


