TL;DR: Double extortion ransomware means criminals steal your data and threaten to publish it, sometimes without encrypting a single file. Backups protect your systems. They do nothing for data that has already left your network. Firms need both.

What is double extortion ransomware?

The FBI’s flash alert on the Silent Ransom Group, also known as Luna Moth, sets out the method clearly. Attackers pose as IT support over the phone or by email to gain access to a victim’s systems. They then exfiltrate data using legitimate remote access tools, and extort the victim by threatening to publish what they have stolen. No encryption is required for this to work.

Some ransomware groups still encrypt files on top of the theft. Luna Moth and groups like it have shown that stealing the data and threatening to release it is often enough on its own.

What happened at Weil Gotshal & Manges

Weil, Gotshal & Manges confirmed in May 2026 that a threat actor uploaded a limited number of client documents to external cloud storage. The firm stated its core network was not accessed and that operations were not disrupted, according to reporting by Law.com. The Insurer reported, citing sources familiar with the matter, that Weil paid between $18 million and $20 million to suppress publication of the data. Weil has not confirmed that figure.

Weil was not the only firm targeted. Jones Day faced a $13 million demand in April 2026 and refused to pay, after which Silent Ransom Group published stolen files on its leak site, per reporting by Aardwolf Security. The Insurer also reported that Mayer Brown had data published on the same leak site after an employee was misled into sending documents to an impersonator. Law.com reported that Fox Rothschild confirmed a separate breach from a May 2026 attack linked to the same group.

The Insurer reported that cybersecurity firm Halcyon tracked more than 200 ransomware incidents against law firms between 2025 and early 2026. These cases involve US firms, and Silent Ransom Group has focused on the US legal market so far. The method itself is not limited to one country, and there is nothing stopping the same tactic being used against a UK firm.

Why is double extortion ransomware increasing?

Arctic Wolf’s 2026 Threat Report tracked a sharp shift in its incident response caseload. Data-only extortion, where attackers steal information without encrypting anything, grew from 2% of cases to 22% in a single year.

Backup and recovery have improved across most sectors, which makes pure encryption a weaker threat than it used to be. A firm that can restore its systems quickly has little reason to pay a ransom for a decryption key. Stealing the data and threatening to publish it gets around that problem entirely.

Why isn’t a backup strategy enough on its own?

Backups protect your ability to keep operating. If your systems are encrypted, a good backup gets you running again without paying anyone.

Backups do not stop data theft. If client files were copied out of your network last week, restoring a clean backup this week changes nothing about what the attacker already has. The two problems need two different answers, and treating backup as cover for both is where firms get caught out.

What protects a law firm against double extortion ransomware?

Backup still matters. It needs to sit alongside other measures rather than carry the whole plan on its own.

Immutable backups

An immutable backup cannot be altered or deleted, even by someone who has gained administrator access to your network. Attackers often try to find and destroy backups before the rest of an attack begins. An immutable backup closes that route off, since even a compromised admin account cannot touch it.

Monitoring for data leaving your network

Most security tools are built to catch encryption in progress. Data theft looks different, and it needs different monitoring: unusual outbound transfers, access to files a user does not normally touch, activity outside working hours. Catching an attacker while they are still copying data is the difference between a contained incident and a seven-figure demand.

An incident response plan built for data theft, not just downtime

A response plan focused only on getting systems back online misses half the problem. It also needs to cover what happens once data has already left your network: who gets notified, what your obligations are under data protection law, and how you communicate with clients before the attacker does it for you.

What should your firm do next?

What should your firm do next?

Ask your IT provider one direct question: if an attacker copied client files out of your network tomorrow without touching a single system, would you know before they told you? If the answer is no, that is the gap Luna Moth and groups like it are built to find.

Labyrinth Technology works with UK law firms on exactly this gap. Our cyber security services start with an audit of your current setup, so you know where data could leave your network unnoticed before an attacker finds out for you. From there, we build monitoring that watches for data leaving and an incident response plan that covers theft as well as downtime.

On the backup side, our backup and disaster recovery service includes immutable backups as standard, so a compromised admin account cannot touch your recovery point even if an attacker gets that far. We also test your backups on a schedule, rather than leaving that discovery for the day you actually need them.

If you cannot answer the question above with confidence, get in touch and we will find out together where that gap sits in your firm.

Newsletter

Stay informed with practical IT insights

Get useful updates, security advice, and technology guidance from the Labyrinth Technology team.