US Law Firms Face Surge in Cyber Extortion and Data Breaches
On March 3, 2026, the ransomware group Kairos claimed theft of about 700 GB of files from Katz, Kantor, Stonestreet & Buckner PLLC, a West Virginia personal‑injury law firm. The stolen data included Social Security numbers, driver’s licenses, medical records and sensitive case details. The firm detected suspicious network activity on February 6, secured its systems and notified clients, but the breach highlighted the vulnerability of law firms that handle highly confidential information.
Separately, the FBI issued a warning that the Silent Ransom Group – a successor to the Conti ransomware syndicate – is increasingly targeting U.S. law firms. The group uses phishing emails, fake IT‑support calls and even in‑person visits to gain remote or physical access to computers, then exfiltrates data for extortion. Stolen files are often transferred via legitimate cloud services such as Google Drive or OneDrive. Both incidents underscore the need for law firms to adopt comprehensive cybersecurity measures, including regular risk assessments, encryption, staff training, and integrated detection and response platforms.