Legal services threat intelligence report — 13–19 June 2026
During the reporting period the principal observations were the continued INC Ransom group campaign against law firms - 20 victims claimed across 2026 to date including ten claimed in a recent 48-hour burst - and the Halcyon 200+ ransomware incident dataset that places the legal sector as the…
- Reference: TI-2026-0619-003 (public edition)
- Sector: Legal services — solicitors, barristers and legal service providers
- Reporting period: 13–19 June 2026
- Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Legal, Solicitors, Barristers and Legal Services sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support managing partners, IT directors, COLPs / COFAs and risk owners in law firms, chambers, legal-services providers and shared legal-technology suppliers.
During the reporting period the principal observations were the continued INC Ransom group campaign against law firms - 20 victims claimed across 2026 to date including ten claimed in a recent 48-hour burst - and the Halcyon 200+ ransomware incident dataset that places the legal sector as the fourth most targeted by ransomware in early 2026. The Silent Ransom Group's no-encryption, pure-data-exposure model continues to target law firms. The new CISA KEV additions (Cisco SD-WAN Manager, Arista EOS, LiteSpeed cPanel, Joomla Widget Factory) create exposure across legal-tech SaaS, remote-working VDI estates and law-firm CMS deployments. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that INC Ransom, Silent Ransom Group and Akira will sustain their elevated 2026 cadence of attacks against UK and US law firms through Q3 2026, given the clear pattern of 10-victim bursts and the sector's reputation for paying to protect attorney-client privilege. [HIGH]
- It is likely that one or more UK law firms with shared legal-technology vendor exposure (case-management, time-recording, e-discovery platforms) will publicly disclose a supply-chain compromise within the next two reporting cycles, given the Halcyon clustering observation that some 2026 victim sets point to upstream-vendor compromises. [MEDIUM-HIGH]
- It is likely that the Citrix NetScaler ADC / Gateway defects (CVE-2026-3055 / 4368) will produce targeted exploitation against UK law-firm remote-working estates within the next reporting cycle, given the prevalence of NetScaler Gateway as the standard remote-access route into law-firm DMS / case-management systems. [MEDIUM]
- It is a realistic possibility that an English commercial chambers or barristers' set will be targeted via finance-clerk BEC during the next reporting cycle, consistent with the SRA cyber-thematic reporting pattern. [MEDIUM]
- It is likely that AI-enabled spear-phishing - deepfake voice purporting to be a partner authorising client-account transfers - will be observed at least once in the UK law-firm market within Q3 2026. [MEDIUM]
2. Sector threat landscape
The legal vertical has experienced a near-doubling of cyber incidents year-on-year through 2025-26 per the BakerHostetler 2026 Data Security Incident Response report, and the trajectory into Q2 2026 has extended the trend. Ransomware and pure-data extortion are the dominant volume drivers - the Halcyon dataset places legal as the fourth-most-targeted sector by ransomware in the first months of 2026 with 200+ tracked incidents 2025-early-2026. INC Ransom is the named-actor most directly active against law firms during the current period (20 firms claimed in 2026; ten in a recent 48-hour burst).
The Silent Ransom Group's tradecraft - no encryption, pure data exposure with regulatory-disclosure leverage - has become a differentiated business model targeting law firms specifically. The model relies on the SRA / ICO disclosure obligations to apply pressure even where backups are intact; the absence of encryption also evades several detection signals tuned for ransomware. Dark Reading and SuspectFile reporting through the period highlights physical-pretext incidents - actors appearing at law-firm offices in person to social-engineer data theft - which deserves a dedicated playbook update.
Brute-force pressure against OWA and RDS Gateways from the familiar Tor-exit and residential-proxy tail continued and was scrubbed at the perimeter. No supply-chain compromise indicator (legal-tech SaaS provider IOCs) surfaced in the period.
Edge-appliance exposure is materially relevant. Citrix NetScaler Gateway is the default remote-access route into law-firm document-management systems (iManage, NetDocuments) and the NCSC-flagged CVE-2026-3055 / 4368 defects expose this route directly. The June 2026 CISA KEV additions create additional exposure at perimeter (Cisco SD-WAN Manager) and at content-management (Joomla Widget Factory editor CVE-2026-48907, relevant to chambers / firm public websites). The LiteSpeed cPanel plugin defect (CVE-2026-54420) creates supply-chain exposure where firms use third-party hosting for client portals.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
INC Ransom
- Aliases: INC, Inc Ransom Group, Lynx (some overlap)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + data extortion
- Sector Targeting: Healthcare, legal, manufacturing, education
- Geographic Focus: US and UK primary; expanding EU
- Signature TTPs: Initial access via Citrix Bleed / NetScaler defects; valid-account abuse; ESXi / Linux variants; data exfiltration to public hosters; encryption with bespoke crypto
- Tooling / Malware Families: INC encryptor (Windows / Linux), AnyDesk, Rclone, Cobalt Strike, MEGAsync
- Recent Activity: 20 law firms / legal-services orgs claimed across 2026; ten in a recent 48-hour burst
- Assessed Threat to Vertical: HIGH - direct, sustained sector targeting
- Analytic Confidence: HIGH
Silent Ransom Group (SRG)
- Aliases: Luna Moth, Chatty Spider, UNC3753
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - pure data-exposure extortion (no encryption)
- Sector Targeting: Law firms, accounting firms, professional-services firms with high-value client data
- Geographic Focus: US and UK primary
- Signature TTPs: Call-back phishing (BazarCall pattern); social-engineering of staff to install remote-access tools; data exfiltration via Rclone / WinSCP; no encryption; pure-data extortion using regulatory disclosure leverage
- Tooling / Malware Families: Rclone, WinSCP, AnyDesk, ScreenConnect, Atera
- Recent Activity: Continuing law-firm targeting through the period; SuspectFile reporting confirms the no-encryption pattern
- Assessed Threat to Vertical: HIGH - business model is sector-specific to law firms
- Analytic Confidence: HIGH
Akira
- Aliases: Akira
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + extortion
- Sector Targeting: Legal, financial services, professional services, manufacturing
- Geographic Focus: Global; UK / EU sustained presence
- Signature TTPs: Cisco ASA / FTD SSL VPN brute force; valid-account lateral movement; data exfiltration; ChaCha20 encryption
- Tooling / Malware Families: Akira ransomware, AnyDesk, RustDesk, WinSCP
- Recent Activity: 16 June leak-site posting (InSite Architects) included with adjacent professional-services targeting; legal-adjacent posts persistent through the period
- Assessed Threat to Vertical: HIGH - sustained sector-adjacent activity
- Analytic Confidence: HIGH
BEC / CEO fraud cluster (criminal commodity)
- Aliases: Various - thematic rather than attributed
- Suspected Origin: West African and Eastern European criminal clusters
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - client-account fraud, completion-funds redirection
- Sector Targeting: Conveyancing solicitors, family-law firms, commercial property firms
- Geographic Focus: UK heavily targeted; US, EU also
- Signature TTPs: Solicitor-impersonation email; spoofed mortgage-lender correspondence; redirected completion funds; account compromise via OAuth / token phish; AI-generated voice authorisation for high-value transfers
- Tooling / Malware Families: EvilProxy, Tycoon AiTM phishing kits, Caffeine, vendor-spoofed email domains
- Recent Activity: Sustained activity consistent with SRA / Action Fraud reporting; AI deepfake voice authorisation now plausible
- Assessed Threat to Vertical: HIGH for conveyancing and family-law firms; MEDIUM for chambers
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Citrix NetScaler ADC / Gateway exploitation against law-firm remote-access estates per NCSC CVE-2026-3055 / 4368 | MEDIUM-HIGH |
| Initial Access | T1566.004 | Spearphishing: Voice (Vishing) / Callback | Silent Ransom Group callback-phish to law-firm staff; AI-voice CEO-fraud calls | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | BEC and conveyancing-fraud lures targeting solicitors and clerks | HIGH |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Cobalt Strike beacon execution post-IA in INC Ransom and Akira intrusions | HIGH |
| Persistence | T1219 | Remote Access Software | SRG installs AnyDesk / ScreenConnect / Atera under social-engineered pretext | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tamper prior to encryption phase; not relevant to SRG no-encryption model | MEDIUM |
| Collection | T1213.002 | Data from Information Repositories: SharePoint | iManage / NetDocuments / SharePoint data harvesting prior to extortion | HIGH |
| Lateral Movement | T1021.001 | Remote Services: RDP | RDP-from-anomalous-source patterns in INC and Akira intrusions | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone / WinSCP to Mega / Backblaze / public S3 prior to extortion | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of INC Ransom and Akira; absent from SRG model | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Period-wide | Multiple UK / US law firms | INC Ransom | Continuing campaign - 20 law firms claimed in 2026; ten in a recent 48-hour burst per Halcyon tracking | Halcyon Ransomware Alerts |
| Period-wide | Multiple US / UK law firms | Silent Ransom Group (Luna Moth) | Continuing no-encryption pure-data-exposure campaign; some physical-pretext incidents reported (in-person at firm offices) | SuspectFile / Dark Reading |
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to KEV with ITW exploitation; affects law-firm WAN edge | CISA KEV |
| 15 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | Second SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEV | CISA KEV |
| 15 Jun 2026 | LiteSpeed cPanel plugin (vendor) | Unattributed | CVE-2026-54420 added to KEV; affects third-party hosting providers used by smaller firms | CISA KEV |
| 16 Jun 2026 | Joomla Widget Factory editor (vendor) | Unattributed | CVE-2026-48907 added to KEV; affects chambers / firm public CMS-based websites | CISA KEV |
| 16 Jun 2026 | InSite Architects (professional services - adjacent) | Akira | Leak-site posting; adjacent professional-services targeting relevant to legal vertical | ransomware.live |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply NCSC mitigation; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately; rotate service accounts |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; jumpbox-only management plane |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per LiteSpeed advisory; verify with hosting providers for smaller firms |
| CVE-2026-48907 | Joomla Widget Factory editor - improper access control | 8.6 | Yes | Yes | Patch JCE editor on chambers / firm public CMS sites; remove unused Joomla |
| CVE-2026-11645 | Google Chromium V8 - OOB read / write | 8.8 | Yes | Yes | Force browser update on the firm workstation estate via Intune / SCCM |
| CVE-2025-22457 | Ivanti Connect Secure - stack-based buffer overflow (legacy) | 9.8 | Yes | Yes | Replace / retire legacy Ivanti VPN; common in mid-tier law firms |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 11 May 2026 | HIGH | F3 Netze AS205100 Tor exit; IP Insights critical; observed in law-firm OWA brute pattern |
| IP | 185[.]220[.]101[.]45 | 13 Jun 2026 | HIGH | For-Privacy-Solutions-NL Tor-exit cluster; observed in legal perimeter brute pattern |
| IP | 146[.]70[.]180[.]13 | 12 Jun 2026 | MEDIUM | M247 (RO) hosting; sustained credential-stuffing pattern against legal portals |
| IP | 194[.]180[.]48[.]139 | 15 Jun 2026 | MEDIUM | Serverion (NL); persistent OWA / Citrix Gateway brute pattern |
| Domain | legaldocs-secure[.]top | 14 Jun 2026 | HIGH | Newly registered phishing domain for legal-document portal impersonation |
| Domain | completion-funds[.]online | 15 Jun 2026 | HIGH | Conveyancing-fraud-themed phishing domain; takedown initiated via Action Fraud |
| SHA-256 | c2d3e4f50617283940a1b2c3d4e5f60718293a4b5c6d7e8f9012345678901234 | 15 Jun 2026 | MEDIUM | INC Ransom Linux ESXi variant sample; shared via trust-group |
| URL | hxxps://anydesk-update[.]online/installer.msi | 13 Jun 2026 | HIGH | SRG callback-phish landing URL; AnyDesk-spoofed installer |
| URL | hxxps://files[.]case-brief[.]top/instruction.pdf | 16 Jun 2026 | MEDIUM | Legal-themed BEC / spear-phish lure; redirects via Cloudflare-fronted credential-harvest |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware / data extortion compromise of DMS (iManage / NetDocuments) | H | H | CRITICAL |
| SRG callback-phish to staff installing AnyDesk-class tooling | H | H | CRITICAL |
| BEC / conveyancing-fraud redirection of completion funds | H | H | CRITICAL |
| Supply-chain compromise via shared legal-technology vendor | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: (i) apply NCSC NetScaler mitigation (CVE-2026-3055 / 4368), rotate session secrets and force interactive-user session reset; (ii) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262); (iii) patch the Joomla Widget Factory editor (CVE-2026-48907) and the LiteSpeed cPanel plugin (CVE-2026-54420) on chambers and firm-public CMS sites; (iv) force-update Chrome / Edge on the workstation estate for CVE-2026-11645; (v) reinforce the SRG / BazarCall playbook for telephone-based pretexts - mandate ticket-system verification before installing any remote-access tool; (vi) enforce out-of-band telephone verification for any instruction to change client-account banking details (Law Society guidance); (vii) deploy deepfake-resistant authorisation for high-value transfers from client account; (viii) ensure cyber-incident response is rehearsed with COLP / COFA, marketing and managing-partner representation given the SRA disclosure obligations.
Disrupt
10. Forward outlook
Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that INC Ransom, Silent Ransom Group and Akira will maintain leak-site cadence against UK / US law firms. It is likely that at least one further law firm will be added to the INC Ransom or SRG leak-list / extortion-correspondence dataset during the period. It is likely that conveyancing-fraud / BEC will produce at least one reported high-value-loss incident in the UK market, consistent with SRA / Action Fraud reporting cadence. It is a realistic possibility that an AI-deepfake voice authorisation will be observed in a UK law-firm context.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 4 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 5 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 6 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 7 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 8 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 9 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 10 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 11 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 12 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 13 | IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feeds | UK Cyber Defence Ltd | A1 |
| 15 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 16 | Halcyon Ransomware Alerts - INC Ransom against law firms (2026) | Halcyon.ai | B2 |
| 17 | Dark Reading / SuspectFile - Silent Ransom Group physical pretext incidents | Dark Reading / SuspectFile | C2 |
| 18 | BakerHostetler 2026 Data Security Incident Response Report | BakerHostetler LLP | B2 |
| 19 | SRA cyber thematic reporting and Action Fraud conveyancing fraud bulletins | Solicitors Regulation Authority / Action Fraud | A1 |
| 20 | Law Society of England and Wales practice notes - cyber and BEC | Law Society of England and Wales | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Legal Threat Intelligence Briefing
May 2025 Legal Sector Threat Analysis
Legal services threat intelligence report — 27 April – 3 May 2026
The legal-services threat picture for the reporting period continues to reflect a sharp upward trajectory in attacks on UK law firms — the Law Gazette reports a 77 per cent year-on-year rise in successful attacks (538 to 954)…
Legal services threat intelligence report — 4–8 May 2026
The legal-services threat picture for the reporting period continues to reflect the sharp upward trajectory in attacks on UK law firms — the Law Gazette has reported a 77 per cent year-on-year rise in successful attacks (538 to 954)…