Navigating Ransomware Data Dumps

Backups defeat encryption. They do nothing against the threat to publish.

Law Firm Cybersecurity · Chapter 13~8 min read

Modern ransomware isn't just about encrypting and holding your data hostage anymore. The newer and more dangerous model is simpler: the attackers quietly copy your data, and then threaten to publish it unless you pay. Some groups skip the encryption entirely — no locked files, no dramatic ransom screen — just a quiet exfiltration followed by a demand.

For most businesses, good backups defeat encryption. They do nothing against the threat to publish. And a law firm is exactly the kind of victim these groups target.

Double extortion and the leak site

The mechanism has a name: double extortion. Steal the data, encrypt (or don't), and pressure the victim with a public "leak site" where the stolen files get posted if the demand isn't met. The FBI issued a specific warning in 2025 about a group running this playbook against law firms — pure data-extortion, driven by social engineering rather than malware, with victim firms named on a public leak site when they don't pay.1 Security researchers tracking the space counted well over a hundred ransomware incidents against the legal sector across 2025 and into 2026, and noted clusters of firms appearing together — a signature of the vendor-supply-chain problem from Chapter 9.2

Why law firms draw this fire is not mysterious: they hold highly sensitive material — litigation strategy, transactions, client data — and they operate under intense pressure to keep it confidential, which is precisely what makes the threat to publish effective.3

FIGURE 1 — DOUBLE EXTORTION: THE FORK
Initial access
a bought stealer log (Ch. 5) or vendor compromise (Ch. 9)
Quiet lateral movement
Data exfiltration
backups don't help past this point
(a) encrypt + demand, or (b) just threaten to publish
Leak-site listing → publication if unpaid
The damage is done at exfiltration, not encryption. Prevention has to happen to the left of that.

What actually reduces this risk

Prevention here is mostly the rest of this guide, aimed at the left side of that flow diagram:

1. Close the initial-access routes. Most ransomware starts with a stolen credential (Ch. 2, Ch. 5), a phished staff member (Ch. 7), an exposed service (Ch. 6, Ch. 11), or a compromised vendor (Ch. 9). The prevention was in those chapters.

2. Backups still matter — for the encryption half. Offline, immutable, tested backups defeat the file-locking side and are non-negotiable. Just don't mistake them for protection against publication.

3. Minimize and segment data. The less sensitive data you hold, and the more it's segmented, the less an intruder can exfiltrate in one reach. Data you deleted under a retention policy can't be dumped.

4. Detect the exfiltration, not just the encryption. Because the damage is at exfiltration, monitoring that can flag unusual outbound data movement is what gives you a chance to act before the fork.

5. Have an incident response plan — before. Formal Opinion 483's clearest practical instruction is that the decision to have a plan, and its content, must be made before a breach.4 Who leads, who calls counsel, who contacts the regulator, who notifies clients, how you communicate if email is down. A plan written during an incident is not a plan.

6. Know your notification obligations in advance. Given how much the statutory duties vary, the time to determine what you'd owe, to whom, and how fast is now — with counsel — not while the clock is running.

Incident-readiness starter

An incident-response-plan template and pre-incident readiness checklist — plus, if you'd like, a review of your website and hosting-side recovery posture (backups, restoration, monitoring).

Your firm's ransomware-readiness checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. FBI, Private Industry Notification 20250523-001, Silent Ransom Group Targeting Law Firms (May 23, 2025); see also A Silent Threat, Loud Consequences, DataBreaches.net (Apr. 13, 2026).
  2. INC Ransom Group Mounts Rapid Campaign Against Law Firms, Halcyon (Mar. 11, 2026) (200+ legal-sector incidents tracked 2025–early 2026; victim clustering).
  3. No Encryption, Just Exposure: Silent Ransom Group Targets Law Firms, SuspectFile (Apr. 13, 2026).
  4. ABA Comm. on Ethics & Pro. Resp., Formal Op. 483 (2018).

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer