Ransomware attacks targeting law firms are becoming more sophisticated, with threat actors shifting their tactics beyond traditional phishing. From compromising backup systems and exploiting third-party vendor vulnerabilities to impersonating IT professionals, removing remote access tools, and using AI-enabled social engineering, today’s attacks are increasingly complex. As these threats evolve, law firms should regularly train employees to recognize warning signs and respond appropriately.
In a recent Massachusetts Lawyers Weekly article, B. Stephanie Siegmann, Chair of the Cybersecurity, Privacy & Data Protection Group and Co-Chair of the Artificial Intelligence Practice, explains why even small law firms are attractive targets and how a single vendor vulnerability can expose multiple organizations. She also shares practical steps firms can take to reduce risk, including disabling thumb drives, restricting unsolicited screen-sharing requests, and carefully evaluating whether paying a ransom is the appropriate response.
Read the full article on Massachusetts Lawyers Weekly‘s website.