WilmerHale and Goodwin Procter Paid Millions After a Ransomware Gang Just Called Reception

by Rebecca Sutton

Two of America’s most prominent law firms have quietly paid millions of dollars in the latest law firm ransomware attacks to make headlines. Neither breach involved a single line of malicious code. WilmerHale paid at least $18 million. Goodwin Procter paid roughly $10 million. Both handed the money to a group called Luna Moth. It talked its way past their defences using phone calls, not exploits.

The pair are the latest disclosed payments reported by insurance trade press. They form part of a wider run of similar cases. Each one shows how little a criminal now needs to walk away with a seven-figure payout.

An employee on a phone call at a laptop, the kind of vishing call behind recent law firm ransomware attacks

No malware, no encryption, just a convincing phone call

Insurance trade publication The Insurer reported the two payments on 7 August. Its reporting was sourced from confidential claims data. WilmerHale’s insurer CNA covered a $10 million primary layer of the payment. Goodwin Procter’s cover came through Brit. Neither firm has publicly confirmed the exact figures.

But the pattern is already on the record elsewhere. Weil Gotshal reportedly paid between $18 million and $20 million to the same group in May. Jones Day faced a $13 million demand in April and appears to have refused it.

Luna Moth, also tracked as the Silent Ransom Group or Chatty Spider, does not encrypt files. It relies on data-theft extortion instead. The group steals files, then threatens to publish them unless paid. So the usual ransomware defences, such as backups and endpoint detection, only cover part of the risk. Luna Moth formed in 2022 out of the old BazarCall phone-scam crew, and it has stuck to social engineering ever since.

Its playbook has escalated steadily. Through early 2025, targets received fake subscription-renewal invoices by email. Each invoice carried a phone number to call and dispute the charge. That call put the victim on the line with an operator posing as IT support. The operator talked them into installing a remote-access tool.

From March 2025, the group skipped the invoice step. It began calling employees directly and claiming to be internal IT, a shift to direct vishing. When that failed, the FBI says operators started sending someone in person. A fake IT contractor walks into the building and gets access to a workstation. Then they plant a USB storage device to pull the data out.

Why law firm ransomware attacks keep working

The FBI and IC3 have issued two advisories tracking this shift. The first, in May 2025, covered the vishing calls. A follow-up in May 2026 confirmed the physical intrusions had continued. Security firm Halcyon recorded 134 ransomware incidents against legal services firms in the first quarter of 2026 alone. Luna Moth itself claims responsibility for more than 100 attacks since it started operating.

One case shows how little access the group needs. Mayer Brown said its own systems were never touched, even after some of its data turned up on Luna Moth’s leak site. That is a sign the group can grab files without ever touching a firm’s core network.

Law firms are attractive targets for an obvious reason. Client files are confidential by definition, so a threat to publish them carries real weight. The professional duty to protect that data makes a quiet payment feel like the safer option. Insurers have been willing to cover the bill rather than gamble on a public leak.

Ransom demands have grown accordingly. BleepingComputer reported that early Luna Moth demands typically ran from $1 million to $8 million. The sums now reported in these law firm ransomware attacks show that ceiling has moved much higher for firms with the deepest pockets.

What this means beyond the legal sector

None of Luna Moth’s tricks need a software flaw. They exploit trust in a phone call and trust in a visitor badge. So any firm with a help desk and a front door is a fair target, not just law firms. A pen test that only checks external systems will miss this. There is nothing on the perimeter to find.

UK organisations have already seen a similar approach succeed. The pair convicted over the 2024 TfL breach also relied on low-tech impersonation rather than a technical exploit. That lesson travels well beyond the legal sector, and well beyond the United States, in these law firm ransomware attacks.

The practical test is simple. Could someone claiming to be “IT” talk an employee into granting remote access? Could a stranger with a lanyard get past reception and up to a desk? If the honest answer is “probably,” that is the gap Luna Moth has been exploiting for four years running. Closing it costs a fraction of an $18 million ransom.

A scoped social engineering assessment, phone calls and an on-site visit included, will show you honestly where that gap sits. That beats leaving it to guesswork, and it is far cheaper than the bill for the next round of law firm ransomware attacks.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like