Navigating Ransomware Data Dumps
Backups defeat encryption. They do nothing against the threat to publish.
Modern ransomware isn't just about encrypting and holding your data hostage anymore. The newer and more dangerous model is simpler: the attackers quietly copy your data, and then threaten to publish it unless you pay. Some groups skip the encryption entirely — no locked files, no dramatic ransom screen — just a quiet exfiltration followed by a demand.
For most businesses, good backups defeat encryption. They do nothing against the threat to publish. And a law firm is exactly the kind of victim these groups target.
Double extortion and the leak site
The mechanism has a name: double extortion. Steal the data, encrypt (or don't), and pressure the victim with a public "leak site" where the stolen files get posted if the demand isn't met. The FBI issued a specific warning in 2025 about a group running this playbook against law firms — pure data-extortion, driven by social engineering rather than malware, with victim firms named on a public leak site when they don't pay.1 Security researchers tracking the space counted well over a hundred ransomware incidents against the legal sector across 2025 and into 2026, and noted clusters of firms appearing together — a signature of the vendor-supply-chain problem from Chapter 9.2
Why law firms draw this fire is not mysterious: they hold highly sensitive material — litigation strategy, transactions, client data — and they operate under intense pressure to keep it confidential, which is precisely what makes the threat to publish effective.3
a bought stealer log (Ch. 5) or vendor compromise (Ch. 9)
backups don't help past this point
What actually reduces this risk
Prevention here is mostly the rest of this guide, aimed at the left side of that flow diagram:
1. Close the initial-access routes. Most ransomware starts with a stolen credential (Ch. 2, Ch. 5), a phished staff member (Ch. 7), an exposed service (Ch. 6, Ch. 11), or a compromised vendor (Ch. 9). The prevention was in those chapters.
2. Backups still matter — for the encryption half. Offline, immutable, tested backups defeat the file-locking side and are non-negotiable. Just don't mistake them for protection against publication.
3. Minimize and segment data. The less sensitive data you hold, and the more it's segmented, the less an intruder can exfiltrate in one reach. Data you deleted under a retention policy can't be dumped.
4. Detect the exfiltration, not just the encryption. Because the damage is at exfiltration, monitoring that can flag unusual outbound data movement is what gives you a chance to act before the fork.
5. Have an incident response plan — before. Formal Opinion 483's clearest practical instruction is that the decision to have a plan, and its content, must be made before a breach.4 Who leads, who calls counsel, who contacts the regulator, who notifies clients, how you communicate if email is down. A plan written during an incident is not a plan.
6. Know your notification obligations in advance. Given how much the statutory duties vary, the time to determine what you'd owe, to whom, and how fast is now — with counsel — not while the clock is running.
An incident-response-plan template and pre-incident readiness checklist — plus, if you'd like, a review of your website and hosting-side recovery posture (backups, restoration, monitoring).
Your firm's ransomware-readiness checklist

Footnotes
- FBI, Private Industry Notification 20250523-001, Silent Ransom Group Targeting Law Firms (May 23, 2025); see also A Silent Threat, Loud Consequences, DataBreaches.net (Apr. 13, 2026). ↩
- INC Ransom Group Mounts Rapid Campaign Against Law Firms, Halcyon (Mar. 11, 2026) (200+ legal-sector incidents tracked 2025–early 2026; victim clustering). ↩
- No Encryption, Just Exposure: Silent Ransom Group Targets Law Firms, SuspectFile (Apr. 13, 2026). ↩
- ABA Comm. on Ethics & Pro. Resp., Formal Op. 483 (2018). ↩