Silent Ransom Group Extorted $207 Million from 27 Law Firms Using Phone‑Based Social Engineering
Silent Ransom demanded $207 M from 27 law firms through phone intimidation, bypassing ransomware encryption. The episode highlights gaps in security‑awareness and incident‑response controls that continuous‑monitoring programs must address.
ADTP Breach Watch· October 10, 2026· Security Affairs
SeverityHigh
Type💀 Ransomware
ConfidenceHigh
ReportedOct 10, 2026
Professional ServicesLaw firms and professional‑services organizationsPhishing
What happened
Between April and September 2026, Silent Ransom extracted roughly $207 million from 27 law firms by threatening exposure and using phone‑based social engineering; no malware or file encryption was used. Leaked internal chats and blockchain analysis confirm the scale of the operation.
Why it matters for trust and compliance
The incident underscores the need for documented security‑awareness training and auditable incident‑response playbooks—control objectives that map across NIST CSF, ISO 27001, and other frameworks.
Demonstrates the importance of continuous security‑awareness evidence for audit readiness.
Provides a use‑case for incident‑response evidence collection to satisfy control‑monitoring requirements.
Who is affected
Law firms and professional‑services organizations
Recommended actions
Update social‑engineering response playbooks to include phone‑based extortion scenarios.
Implement regular, role‑based security‑awareness training with simulated calls.
Collect and retain training completion records and incident‑response logs as continuous control evidence.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.