Insura
Ransomware Attacks on Law Firms Are Surging: 2026 Coverage Guide

Ransomware Attacks on Law Firms Are Surging: 2026 Coverage Guide

John Abbott
7/10/2026

Quick Answer

Does cyber insurance cover ransomware attacks on law firms?

Yes — a well-built Cyber policy covers the ransom or extortion payment, forensic investigation, data restoration, business interruption while systems are down, and client notification. Law firms are prime ransomware targets: privileged client files give attackers double-extortion leverage, and ABA Rule 1.6 makes a leak an ethics problem, not just an IT one. Mid-market firms typically pay $1,500–$15,000 a year, and most pair Cyber with legal-malpractice E&O — carriers like Chubb, Cowbell and Hiscox discount the bundle.

Why Ransomware Groups Are Targeting Law Firms in 2026

Ransomware operators have figured out something uncomfortable: law firms are close to the perfect victim. Carrier claims desks are seeing it in real time — Chubb, the largest cyber insurer in the U.S., reports its lawyers-segment Cyber book growing fast, driven specifically by ransomware activity against firms of every size. Healthcare practices, financial firms, banks, and manufacturers round out the target list, but law firms sit at the top for three structural reasons.

1. Client files are double-extortion gold

Modern ransomware isn't just encryption anymore. Attackers exfiltrate data first, then encrypt — two levers: pay to get your systems back, and pay again to keep client files off a leak site. For most businesses, leaked data is embarrassing. For a law firm, it's privileged communications, M&A deal terms, litigation strategy, and trust-account details — data your clients assumed was untouchable. Attackers know a firm facing that exposure is far more likely to pay, and to pay quickly.

2. ABA Rule 1.6 turns a breach into an ethics problem

ABA Model Rule 1.6(c) requires lawyers to make "reasonable efforts" to prevent unauthorized disclosure of client information, and Formal Opinions 483 and 498 spell out breach-notification duties to clients. A ransomware event at a law firm isn't just an IT incident — it can trigger bar complaints, client notification obligations, and malpractice claims layered on top of the operational damage. Attackers exploit that pressure: a firm worried about its licenses negotiates differently than a retailer worried about downtime.

3. Deadlines and trust accounts don't wait

Courts don't pause filing deadlines because your document management system is encrypted. Real estate closings and settlement disbursements run through IOLTA and trust accounts that attackers actively hunt for. When a firm's calendar, case files, and billing all go dark at once, every day of downtime compounds — which is exactly the pressure ransomware pricing is built around.

The result: the ABA's most recent TechReport data shows roughly 3 in 10 firms have experienced a security incident, and ransomware demands against small and mid-size firms now routinely land in six figures. Firms under 50 attorneys are now the primary target pool — the same quality of data as BigLaw, with a fraction of the security budget.

The FBI Warning: Silent Ransom Group Is Hunting Law Firms

In May, the FBI released a Private Industry Notification on the Silent Ransom Group — also tracked as Luna Moth, Chatty Spider, and UNC3753 — warning that the group is actively targeting U.S. law firms using IT-themed social-engineering phone calls and callback phishing emails to get remote access to firm devices and steal client data for extortion. SRG has operated since 2022, but in spring 2023 it shifted focus almost exclusively to law firms because of how sensitive legal-industry data is. And per the FBI, the group has escalated again in 2026: when the remote-access play fails, SRG has begun sending a person to the victim firm's office, posing as IT support, to plug a storage device directly into a computer.

What makes SRG hard to catch is that there's no malware and no encryption. The group uses legitimate remote-access tools — Zoho Assist, AnyDesk, Splashtop, Atera — then pulls data out through WinSCP or renamed copies of Rclone. Traditional antivirus rarely flags any of it, and the intrusion leaves few artifacts. Once they have your files, SRG sends a ransom email threatening to sell or publish them — then follows up with phone calls to your employees and even your clients to raise the pressure. DataBreaches.net has reported roughly 38 law firms on SRG's leak site (the ones that refused to pay); the group claims most victims quietly do pay, which would put the real number of compromised firms well above 76.

And SRG is only the most law-firm-focused actor in a crowded field. Claims data shared with our brokerage by specialty cyber underwriters shows Akira as the single most active group in the legal segment (roughly 20% of law-firm incidents), with SRG, Qilin, Rhysida, DragonForce, BianLian, RansomHub, Black Basta, and INC all appearing as well. This is not one coordinated campaign — law firms are being targeted across the board. The same claims data quantifies why: law firms pay ransoms at nearly three times the rate of the rest of insurers' books, ransom/extortion events are about a third of law-firm cyber claims by count but roughly three-quarters of total losses, average payments land in the low-to-mid six figures, and the 90th-percentile law-firm loss runs about nine times the severity of the broader book. Underwriters have noticed. That's exactly why getting coverage terms right — before renewal, not after a claim — matters more for firms than for almost any other buyer.

The insurance takeaway from the SRG playbook is specific: because these attacks steal data without encrypting anything, a backup strategy alone does not address the risk. Backups restore availability; they do nothing when the attacker's leverage is publication. Your cyber extortion coverage needs to respond to threats to publish or sell stolen data — not just to encryption events — and your incident response plan needs a data-exfiltration-only scenario in it.

What Cyber Insurance Actually Covers in a Ransomware Event

A well-built Cyber policy is effectively a pre-paid incident-response team plus a balance-sheet backstop. Here's what the coverage grid looks like when ransomware hits a firm:

Ransom and extortion payments

Cyber extortion coverage reimburses the ransom payment itself (where payment is legal — OFAC-sanctioned threat actors are the exception), plus the cost of the specialists who negotiate with the attackers. Carriers like Chubb and Cowbell maintain panels of experienced ransomware negotiators who frequently cut demands by half or more before anything is paid. Read the insuring agreement's trigger closely: it should respond to threats to publish, sell, or expose stolen data, not only to encryption — data-exfiltration-only crews like SRG and MeowLeaks never encrypt anything, because the data itself is the leverage.

Digital forensics and incident response

The first 72 hours are forensic work: how did they get in, what did they take, are they still inside? Policies cover the breach counsel and forensics firms that answer those questions. This matters doubly for law firms, because determining which clients' data was accessed drives your Rule 1.6 notification analysis. It matters triply in an SRG-style intrusion, where the attacker used legitimate tools and left almost nothing behind for forensics to find.

Business interruption and lost billables

If your practice management, document management, and email are encrypted, you aren't billing. Business interruption coverage replaces lost revenue during the outage — for a firm billing $2M–$10M a year, even a two-week disruption is a six-figure loss. Look for "contingent" or "dependent" business interruption too, which responds when the attack hits a vendor you depend on (your cloud practice-management platform, for example).

Data restoration

The cost of rebuilding systems, restoring from backups, and re-creating corrupted matter files. If backups were encrypted along with production systems — common in law-firm attacks, where intruders dwell for weeks first — this line item gets expensive fast.

Notification, credit monitoring, and PR

State breach-notification statutes apply to law firms just like anyone else, layered on top of the ethical duties. Coverage pays for notification mailings, call centers, credit monitoring for affected individuals, and crisis PR — which for a firm whose brand is confidentiality is not a nice-to-have. With SRG in particular, crisis communication is not hypothetical: the group calls the victim firm's clients directly to pressure payment, so client-facing messaging has to be ready early.

What ransomware coverage does NOT include

Three gaps matter most. First, sublimits: some policies cap ransomware or social-engineering losses well below the headline limit — a $1M policy with a $250K ransomware sublimit is a very different product. Second, client and escrow funds: cyber crime and funds-transfer-fraud agreements on some forms cover only the firm's own money. Law firms hold other people's money — IOLTA, settlement, and closing accounts — so confirm the Cyber Crime insuring agreement explicitly applies to third-party funds and funds held in escrow. Wholesale cyber specialists now flag this as the single most important coverage check for law-firm placements. Third, the malpractice claim that follows: if a client sues alleging the breach damaged their case or deal, that's a professional-liability claim, and it lands on your E&O policy, not your Cyber policy. Which brings us to the bundle.

The Real Package: Cyber + Legal Malpractice (E&O)

For law firms, standalone Cyber is half a solution. A serious ransomware event at a firm almost always produces two kinds of loss:

  1. First-party and breach costs — ransom, forensics, downtime, notification. That's Cyber.
  2. Client claims — "the leak of my deal terms cost me the transaction," "the missed filing deadline during your outage damaged my case." That's legal malpractice / E&O.

Neither policy covers the other's territory. Legal-malpractice policies broadly exclude breach-response costs, and Cyber policies exclude claims arising from professional services. Firms that carry both — ideally from carriers that coordinate the two lines — avoid the coverage-gap finger-pointing that turns a bad month into a bad year.

There's also a pricing reason to buy them together: carriers like Chubb, Hiscox, and Cowbell underwrite both lines for law firms and typically discount a bundled Cyber + E&O placement 10–25% versus buying the pieces separately. For a deeper dive on the pairing, see our guide to the Cyber + E&O bundle for law firms.

What Law Firms Pay for Cyber Insurance in 2026

Premium realism, based on what mid-market professional-services firms actually pay:

Firm profile Typical annual Cyber premium
Solo / 2–5 attorneys, basic controls $1,500–$3,500
5–20 attorneys, $1M–$5M revenue $3,000–$7,500
20–75 attorneys, litigation/transactional mix $7,500–$15,000+

Ransomware is the loss driver behind these numbers, so ransomware readiness is what moves your quote. Underwriters at every major carrier now ask about the same short list:

  • Phishing-resistant MFA everywhere — email, VPN, remote access, and admin accounts. Missing MFA is the single most common reason a law firm gets a declination or a ransomware sublimit, and the FBI specifically recommends the phishing-resistant variety (hardware keys or platform passkeys, not SMS codes).
  • Tested, offline (or immutable) backups — backups the attacker can't encrypt are what turn a ransom negotiation into a restoration project. (Against data-theft-only actors like SRG, backups don't remove the leverage — pair them with the data-retention point below.)
  • Endpoint detection and response (EDR) on all machines.
  • IT-verification and callback procedures — straight from the FBI's SRG guidance: verify the credentials of anyone claiming to be IT support, whether on the phone or standing in your office; set a written policy for how your real IT staff authenticate themselves to employees; and train staff to treat unsolicited "IT" calls and remote-session requests as hostile until verified.
  • Email filtering and wire-verification procedures — because ransomware crews and wire-fraud crews use the same phishing door. (Related reading: social engineering and wire fraud coverage for law firms.)
  • Security awareness training with phishing simulation, updated for callback phishing — the email that asks you to phone them.
  • Data-retention discipline — the less closed-matter client data sitting in accessible systems, the less leverage a thief walks away with.

A firm with those controls documented will price at the low end of its band — and more importantly, will have carrier options rather than a single reluctant quote.

How the Major Carriers Approach Law-Firm Ransomware

  • Chubb — the largest U.S. cyber insurer (A++ AM Best), with a fast-growing lawyers-segment Cyber book and deep claims experience in exactly this scenario. Strong incident-response panel, meaningful extortion limits, and the ability to pair Cyber with other professional lines for a coordinated program. For small and mid-size firms, Chubb quotes are frequently both the broadest and the most competitive.
  • Hiscox — a professional-liability specialist with strong appetite for small firms; its Cyber form pairs naturally with its professional liability products, making it a clean bundle option for firms under ~$5M revenue.
  • The Hartford — competitive for small-firm packages, especially where a firm wants Cyber alongside its broader business insurance program with one carrier relationship.
  • Cowbell — a cyber-focused MGA whose continuous risk-rating model can reward firms with good security hygiene; often aggressive on pricing for well-controlled small firms and quick to quote.

Appetite for law firms also shifts constantly — carriers enter and exit this class as their claims experience develops, and wholesale markets with A and A+ ratings have stepped in to write firms competitively as some retail markets pulled back. That churn is one more reason to compare carriers on identical specs at every renewal rather than auto-renewing: the market that declined you two years ago may want you now, and vice versa.

A Ransomware Timeline: How Coverage Responds Hour by Hour

Hour 0: Staff can't open matter files; a ransom note demands $450,000. You call the carrier's 24/7 breach hotline — this call is the trigger for everything the policy does.

Hours 1–24: Breach counsel engages (covered). Forensics firm deploys (covered). Ransom negotiators open contact with the threat actor (covered).

Days 1–7: Forensics maps the intrusion and the data taken. Negotiators work the demand down. If backups are intact, restoration begins and the ransom may never be paid; if not, the carrier consents to and reimburses a negotiated payment (covered, subject to limits and OFAC screening). Lost billables accrue under business interruption (covered, after the waiting period — typically 8–12 hours).

Weeks 2–6: Rule 1.6 analysis determines which clients must be notified; notification, call center, and credit monitoring run through the policy (covered). Crisis PR manages client communication (covered).

Months 2–12: A client alleges the leaked deal data damaged them. Your legal-malpractice E&O policy responds to the claim — this is the piece a Cyber-only program leaves bare. Firms without coverage absorb every line above out of pocket, at vendor rates negotiated mid-crisis.

How to Buy This Coverage Without Overpaying

  1. Fix MFA and backups first — two weeks of IT work routinely saves 20–30% on premium and unlocks better carriers.
  2. Quote Cyber and E&O together — bundle pricing plus no coverage-gap disputes. Our law firm Cyber insurance guide and legal malpractice insurance guide break down each line in detail.
  3. Check the ransomware sublimit, not just the headline limit — insist on extortion coverage at or near full policy limits, triggered by publication threats as well as encryption.
  4. Verify social engineering coverage — and the escrow question — wire-fraud losses are the sibling risk, and sublimits of $100K–$250K are common defaults that can often be negotiated up. While you're in the crime section, confirm the coverage applies to third-party funds and funds held in escrow, not just the firm's own operating account.
  5. Compare at least three carriers — appetite for law firms varies widely; the spread between the best and worst quote on identical specs is routinely 40%+.

Insura.ai compares law-firm Cyber + E&O quotes from Chubb, Hiscox, The Hartford, and Cowbell in one pass — start a quote comparison and see real bundled pricing for your firm in minutes.

FAQ

Q: What is the Silent Ransom Group, and why does the FBI keep mentioning law firms?
A: Silent Ransom Group (also called Luna Moth, Chatty Spider, or UNC3753) is an extortion crew that has targeted U.S. law firms almost exclusively since 2023. The FBI's notification describes their method: phone calls and callback-phishing emails impersonating IT support, legitimate remote-access tools instead of malware, quiet data theft, then a ransom demand backed by calls to your employees and clients — and, most recently, in-person visits posing as IT staff. Because they never encrypt anything, backup-centric defenses and encryption-triggered coverage language both miss the risk.

Q: Will my Cyber policy actually pay the ransom?
A: Yes, cyber extortion coverage reimburses ransom payments made with carrier consent, along with negotiation costs — unless the threat actor is OFAC-sanctioned, in which case payment is illegal for anyone. In practice, carriers' negotiators and restoration teams resolve many events without paying at all.

Q: We have solid backups. Doesn't that protect us?
A: Against encryption, yes — backups turn a ransom negotiation into a restoration project. Against data-theft extortion, no: when the attacker's leverage is publishing your clients' files, restoring systems changes nothing. That's why underwriters now look for data-retention discipline and exfiltration-aware incident response plans alongside backups, and why your extortion coverage must be triggered by publication threats, not just encryption.

Q: Doesn't my legal malpractice policy already cover a data breach?
A: No. Legal-malpractice (E&O) policies cover claims arising from your professional services — not breach response, ransom payments, forensics, or downtime. Conversely, Cyber policies exclude malpractice claims. A ransomware event at a law firm usually implicates both, which is why the Cyber + E&O bundle is the standard recommendation.

Q: My firm has 8 attorneys. Are we really a target?
A: Yes — small and mid-size firms are now the primary target pool. You hold the same privileged data as a large firm (deal terms, litigation strategy, client PII, trust accounts) with a smaller security budget, and attackers automate their targeting. Carrier claims data shows firms under 50 attorneys driving much of the growth in legal-sector ransomware claims — and law firms as a segment paying ransoms at roughly three times the rate of other industries.

Q: If we pay the ransom, is the incident over?
A: No. You still owe clients notification under ABA Rule 1.6 guidance and state breach laws, forensics still has to prove what was taken, and leaked-data claims can arrive months later. That long tail is what the notification, regulatory, and E&O pieces of a bundled program absorb.

Compare cyber insurance quotes from top-rated carriers — in minutes, not days.

Recommended Articles

What would cyber coverage cost your business? Answer 3 questions for personalized quotes. Get Cyber Quotes →