Silent Ransom Group Is Targeting Las Vegas Attorneys With Fake IT Calls
The FBI has issued a specific warning about a criminal group that calls attorneys, pretends to be their IT department, and walks out with the client file.
Published by CMIT Solutions of Las Vegas · Cybersecurity · 6 min read
The Attack That Starts With a Phone Call
Most law firms in Clark County think about cybersecurity the way they think about fire suppression — a compliance box, handled by the building. That assumption is now dangerous. The legal industry is not being caught in the blast radius of attacks aimed at someone else. It is being deliberately and specifically hunted, by a group the FBI has publicly named.
The group is Silent Ransom Group, also tracked as Luna Moth, Chatty Spider, and UNC3753. It has been working US law firms since spring 2023, and it escalated sharply through 2025 and into 2026. The FBI issued a FLASH advisory describing the method in detail, because the method is unusually effective and requires almost no technical sophistication to pull off.
Here is what makes it different: there is often no malware at all. An operator simply telephones an attorney or a paralegal, says they are from the firm’s IT help desk, and asks them to join a remote support session over Microsoft Teams, Zoom, or Quick Assist. The employee, trying to be helpful, clicks yes. The attacker then copies the files and demands payment to not publish them. No encryption, no ransom note on the screen, no obvious moment where anything looked wrong.
Security researchers tracked more than 200 ransomware and extortion incidents against law firms between 2025 and early 2026. Ransom demands against legal and professional services firms have ranged from roughly $500,000 to $21 million, with the average sitting just under $2 million. INC Ransom alone has claimed more than 20 law firms and legal services organizations in 2026.
How the Campaign Actually Works
The FBI advisory and follow-on threat intelligence describe three distinct entry methods. Any firm evaluating IT support for law firms should be asking a prospective provider how they defend against each one specifically:
- Callback phishing. A fake subscription or renewal invoice arrives by email — no malicious link, no attachment, nothing a filter will catch. It lists a phone number to dispute the charge. The victim calls the attacker directly.
- Vishing as internal IT. An operator calls staff claiming to be the firm’s own help desk and talks them into installing a legitimate remote access tool. Because the software is legitimate, endpoint protection stays silent.
- Physical intrusion. In the most aggressive variant, operators walk into the office posing as IT contractors and plug USB storage devices directly into workstations to copy data on site.
- Exfiltration, not encryption. Because nothing gets locked, your backups do not save you. The leverage is the threat of publishing privileged client material.
- Supply chain clustering. Victims have clustered in ways that suggest a shared legal technology vendor was compromised upstream, giving attackers several firms through one door.
What Is Actually at Stake for a Las Vegas Firm
Clark County’s legal market is unusually exposed. Personal injury and construction defect practices hold medical records and settlement figures. Gaming and hospitality counsel hold regulatory filings and employment matters. Family law holds financial disclosures. All of it is material an extortionist can price.
- ⚠ Privileged client communications published on a leak site, permanently and searchably
- ⚠ IOLTA and settlement trust account details exposed, feeding follow-on wire fraud against clients
- ⚠ Nevada NRS 603A breach notification obligations triggered across every affected resident
- ⚠ Bar complaints and malpractice exposure from clients whose confidences were not protected
- ⚠ Opposing counsel gaining access to strategy, valuations, and settlement authority
- ⚠ Referral relationships lost — in a market this tightly networked, reputation damage compounds fast
There is also an ethics dimension that has no equivalent in other industries. ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. ABA Formal Opinion 483 goes further: it establishes an affirmative duty to monitor for breaches, to stop unauthorized access, to restore system integrity, and to notify affected current clients. Critically, the opinion treats incident response planning as part of “reasonable efforts” — meaning the absence of a written plan is not merely a business risk. It is a defensible allegation of a rules violation.
Three Fixes That Actually Stop This Attack
• Establish a verified callback rule for anyone claiming to be IT
The GapAt most small and mid-sized firms, staff have no way to confirm who their IT provider actually is. If a voice on the phone sounds competent and uses the right vocabulary, they get access. That is the entire attack.
The FixPublish one support number and one support email, post them physically at every desk, and make it firm policy that nobody grants a remote session to an inbound call. Staff hang up and dial the posted number. Extend the same rule to anyone who appears in the office claiming to be a technician — badge check, no exceptions, escorted at all times.
• Block unapproved remote access tools at the endpoint
The GapAntivirus will not flag Quick Assist, AnyDesk, or a legitimate Zoom screen share, because none of those are malicious. The tooling the attacker uses is the same tooling your real IT team uses.
The FixApplication allow-listing. Approve exactly one remote support agent and block the rest at the device level, so an employee who is being socially engineered cannot complete the install even if they want to. Pair it with alerting on large outbound data transfers, since exfiltration is the whole point of this campaign.
• Write the incident response plan before you need it
The GapFirms discover their notification obligations during the breach, when the managing partner is trying to determine which clients were affected and no one can answer. Under Opinion 483, that improvisation is itself the problem.
The FixA written plan naming who declares an incident, who contacts the carrier, who drafts client notice, and who talks to the Nevada bar if required. Keep logging turned on and retained long enough to answer “what did they take” — without logs, you must assume everything was taken and notify accordingly.
Las Vegas Businesses: Don’t Wait for the Breach.
A thirty-minute review will tell you whether your firm can survive a phone call from someone pretending to be your IT department.
What Managed IT Services for Law Firms Should Include
If you are evaluating providers, the differentiator is not price per seat. It is whether the provider understands that a law firm’s threat model is confidentiality first. Encryption-based ransomware is survivable with good backups. Silent extortion is not, because the damage happens the moment the data leaves the building.
Meaningful managed IT services for law firms should cover identity and multi-factor authentication that resists help-desk social engineering, endpoint detection tuned to flag unusual data movement rather than just known malware, documented vendor risk review for your practice management and e-discovery platforms, staff training that specifically rehearses the fake-IT-call scenario, and immutable backups kept separate from your production environment. Ask for all five by name. A provider who cannot speak to vendor risk review has not thought about the supply chain clustering that has already hit firms this year.
Defending Las Vegas with CMIT Solutions
CMIT Solutions of Las Vegas works with Clark County professional services firms that carry real confidentiality obligations — legal, healthcare, accounting, and the contractors who serve them. We know the difference between a compliance checkbox and a control that actually stops a determined caller at the moment they ask an employee to click “allow.”
If your firm has never tested what happens when someone phones your office claiming to be IT, that test is going to happen eventually. It is worth choosing whether it happens on your terms or theirs.
• FBI IC3 FLASH Advisory — Silent Ransom Group Impersonating IT Personnel Through Social Engineering
• BleepingComputer — Silent Ransom Group Targets Law Firms With Fake IT Support Calls
• ABA Formal Opinion 483 — Lawyers’ Obligations After an Electronic Data Breach
Protect Your Las Vegas Business Today
Local IT support and cybersecurity built for firms that cannot afford a confidentiality failure. Serving Las Vegas, Henderson, North Las Vegas, and Clark County.
Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com
3111 S. Valley View Blvd., Suite A205, Las Vegas, NV 89102