On June 10, 2026, Lewis Brisbois, one of the largest law firms in the United States, directed all remote and hybrid employees to either return to its offices or bring firm-issued computers home after blocking outside access to internal networks in response to a cyberattack. The decisive operational pivot reflects the seriousness with which the firm treated the intrusion and the lengths to which modern law firms must go to contain a suspected breach, even at the cost of significant workflow disruption.

Notably, the firm's information security director had warned staff five days earlier about cybercriminals impersonating internal IT personnel through telephone calls featuring falsified caller ID information. This form of social engineering is particularly insidious because it exploits a trusted internal relationship rather than a technical vulnerability, allowing threat actors to bypass many traditional defenses such as firewalls, endpoint protection, and email filters. When an employee believes the caller is a colleague from the help desk, even well-trained personnel may disclose credentials, approve multi-factor authentication prompts, or grant remote access without realizing the request is malicious.

The tactics observed at Lewis Brisbois align with those associated with the Silent Ransom Group, which has previously targeted major firms including Jones Day and Fox Rothschild. The recurrence of this pattern suggests a sustained campaign aimed at the legal industry, which holds concentrated volumes of sensitive client information, privileged communications, and transactional data that adversaries view as exceptionally valuable.

For law firms and their clients, the incident underscores that cyber-hygiene is now a board-level governance priority rather than a purely technical concern. Firms should consider reinforcing verification procedures for any IT-related contact, implementing out-of-band confirmation channels, conducting tailored social engineering training, and reviewing vendor access controls. Clients engaging outside counsel may reasonably inquire about a firm's incident response readiness, identity verification protocols, and segmentation of client data. Proactive measures, combined with transparent communication during incidents, remain the most effective means of preserving trust and minimizing operational and reputational harm when sophisticated threat actors strike.

This article is provided for general informational purposes only and does not constitute legal advice. Clients facing specific cybersecurity or data protection concerns should seek tailored counsel suited to their particular circumstances.