The growing outbreak of ransomware attacks on law firms prompted the UK's National Cyber Security Centre to publish an advisory report last week, advising the legal sector that their clients' deepest, darkest and most sensitive secrets are being targeted by some of the most prolific ransomware operators on the scene – and it's time to get serious about securing legal sector networks.
See also: MCMC warns about the malware mobile app “Pink WhatsApp”

See also: Mallox ransomware attacks IT industries with new attack pattern
Just a few days ago, food group Mondelez, behind brands such as Ritz and Oreo, announced that the personal data of 51,000 of its current and former employees had been compromised in a cyberattack on the law firm Bryan Cave Leighton Paisner. However, so far, calls for improved cybersecurity have not been taken seriously by legal organizations.
Threat actors targeting the legal sector range from small-time cybercriminals using ransomware tools from the dark web to state-run actors backed by China, Iran, North Korea and Russia, according to the recent UK Legal Sector Cyber Threat Report published by the NCSC. The report states that almost 75% of the UK’s top 100 law firms have been hit by cyberattacks.
In addition to the sensitive data they hold and the potential harm that exposure could cause, licensed attorneys have an ethical obligation to protect their clients' secrets, according to Gallo, which adds personal and professional reputation to the list of potential losses.
See also: MOVEit: Hackers steal data of 45,000 New York students

Ransomware targets law firms around the world
In the first two months of 2023 alone, 10 cyberattacks were launched against six different law firms, according to findings from eSentire's threat response team.
In addition to Mondelez , Genova Burns LLC, a law firm in Newark, New Jersey, confirmed it was breached in April, resulting in the personal data of an unknown number of Uber drivers being compromised . Australia’s largest law firm, which represents hundreds of clients and government agencies, HWL Ebsworth, was also breached by Russian ALPHV / Blackcat in the spring.
However, in the face of the growing risk of ransomware cyberattacks, according to PriceWaterHouseCoopers’ annual law firm survey, which is cited by UK cybersecurity regulators, the top 100 law firms spent less than 1% (just 0.46%) of their fee revenue on cybersecurity.
Sixty-four percent of legal IT leaders surveyed by BlackBerry's survey said they were discouraged by the amount of work required to build their own internal security functions, and eighty percent said a program would be too expensive, Gadsby explains in Dark Reading.
Source of information: darkreading.com
