GoFirm
Back to Blog
Case Studies·4 min read

Luna Moth never touched WilmerHale's network. It still walked away with eighteen million dollars.

By GoFirm

On 8 May 2026, an employee at Wilmer Cutler Pickering Hale and Dorr LLP (WilmerHale), the Washington DC-headquartered law firm that counts some of the world's largest companies among its clients, handed sensitive information to a caller who had misrepresented their identity. WilmerHale did not discover what had happened until 25 June 2026, seven weeks later, and notification letters to affected clients and employees only began going out on 10 July. The party behind the deception was Silent Ransom Group, also tracked as Luna Moth, a financially motivated extortion crew that has spent the past year working almost exclusively through US law firms.

Luna Moth's method does not involve malware or exploited software. Since March 2025, the group has posed directly as a target organisation's internal IT support, calling employees and talking them through actions that hand over credentials, remote access, or, as at WilmerHale, the information itself. The FBI confirmed in May 2026 that the group has escalated the tactic further, sending operators to corporate offices in person, posing as IT technicians, to plant storage devices for data exfiltration when a phone call alone does not work. WilmerHale has stated that the third party did not directly access the firm's systems or network. The employee who was deceived gave up the data willingly, believing the person on the other end had the authority to ask for it.

What left the firm included names and Social Security numbers belonging to clients and employees. State filings confirm at least 436 Texas residents, 42 Massachusetts residents, 35 New Hampshire residents and 11 Vermont residents affected so far, with further disclosures still emerging state by state. A Nevada resident whose Social Security number was exposed filed a proposed class action against WilmerHale in federal court in Washington in July, alleging the firm failed to adequately protect the data entrusted to it.

WilmerHale reportedly paid at least eighteen million dollars in ransom and suppression payments to keep the stolen data from being published, according to insurance industry reporting that surfaced on 7 August 2026. CNA covered the ten million dollar primary layer of the claim, with Aon brokering the firm's cyber insurance programme. WilmerHale is not an isolated case. The same week, Goodwin Procter reportedly paid around ten million dollars to the same group, Weil Gotshal paid a double-digit million sum in a suppression payment, and Mayer Brown had client data published after stating its own systems were never accessed. Luna Moth has now extracted eight figure sums from some of the most well-resourced law firms in the United States, using nothing more sophisticated than a phone call.

The defences that failed here were not weak by conventional standards. WilmerHale is a firm with the scale and budget to run a mature security programme, and its own account of the incident confirms that no server was breached, no password was cracked, and no firewall was bypassed. The single point of failure was a moment when an employee, faced with a caller claiming the standing authority to request sensitive information, complied. No technical control sat at that moment to ask whether the request was genuine.

Handing over client or employee personal data, particularly Social Security numbers, to an external party is an execution event. Before an employee at a firm protected by GoFirm can release that data, a confirmation request goes to the named authority responsible for that data, the firm's data custodian or CISO, on their registered device, requiring a biometric confirmation delivered over a separate channel from the one the request arrived on. If that confirmation does not arrive, the release does not happen, regardless of how convincingly the caller has argued their case, how urgent the request sounds, or which internal department they claim to represent.

A caller who has misrepresented their identity, however convincing the performance, cannot produce a biometric confirmation on the real authority's registered device via a separate channel. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References


1. The Insurer. 2026. Exclusive: WilmerHale paid at least $18 million ransom to Luna Moth as CNA covered primary. The Insurer, 7 August 2026.
2. The Insurer. 2026. Exclusive: Goodwin Procter paid around $10 million ransom to Luna Moth with Brit lead. The Insurer, 7 August 2026.
3. DataBreaches.Net. 2026. WilmerHale Sued Over Client Personal Information Data Breach. DataBreaches.Net, 15 July 2026.
4. Federal Bureau of Investigation. 2026. Silent Ransom Group Impersonating IT Personnel through Social Engineering. FBI/IC3 Flash Report, 26 May 2026.

Share this article