Skip to content

Greenberg Traurig Data Breach: SilentRansomGroup Targets Big Law

Darkwebdecoded September 12, 2026

Greenberg Traurig confirmed a data breach to Vermont’s Attorney General on September 8, 2026. A ransomware group called SilentRansomGroup had already posted the firm’s data on its dark web leak site on September 2, roughly six days before the regulatory filing. The confirmed exposure includes Social Security numbers. Greenberg Traurig has not disclosed a total number of affected individuals. This breach is part of a sustained campaign by SilentRansomGroup specifically targeting US law firms throughout August and September 2026.

That’s the headline. But the headline is the least interesting part of what’s happening here.

Greenberg Traurig is not a one-off incident. It’s the sixth confirmed or claimed law firm breach in the last three weeks, all connected to the same ransomware group. And that group has been quietly evolving its tactics from phone calls to something far more brazen: sending physical operators into law firm offices, posing as IT support, and walking out with data on a storage device.

What Greenberg Traurig Has Confirmed

The firm’s regulatory filing with the Vermont Attorney General is currently the only public, verified record of confirmed exposure. It identifies Social Security numbers as the exposed data type and names 10 Vermont residents as affected individuals.

Here’s something worth noticing: Greenberg Traurig has no office in Vermont. When a firm with no physical presence in a state shows up with a confirmed breach filing there, it means employees, clients, or third parties connected to legal matters, people with no reason to expect their data sits in any Vermont-linked context, may be affected. The Vermont filing is not a ceiling on the scope. It’s a regulatory floor: the minimum the firm was legally required to disclose to one jurisdiction. Total affected individuals have not been published.

Separately, Greenberg Traurig confirmed to Reuters that “limited data” had been posted to the dark web. The firm did not confirm SilentRansomGroup by name, did not specify what was taken, and described the situation as ongoing. Its statement was carefully narrow, using language that acknowledged the posting without affirming the full extent of what the group claims to hold.

That gap between what a ransomware group claims and what a victim firm confirms is deliberate on both sides. GalaxyWarden, a breach tracking service monitoring the dark web listing, described the situation accurately: “the only thing you can treat as established today is the existence of the listing itself.” Ransomware groups routinely list firms as a pressure tactic before any payment discussion, and what they publish doesn’t always match what they have.

The SilentRansomGroup: Who They Are and Why Law Firms

SilentRansomGroup operates under several names in cybersecurity research: Luna Moth, UNC3753, and Chatty Spider have all been used to track the same underlying operation. They emerged in March 2022 after the collapse of the Conti ransomware syndicate, which means their origins sit squarely in the post-Conti Russian-speaking criminal ecosystem. They are financially motivated. Law firms are their specialty.

The reason law firms make attractive targets is different from why banks or hospitals get hit, and it’s worth explaining clearly because it affects who is actually at risk here.

A law firm breach is a three-layer problem. The first layer is the firm’s own operational data, employee records, payroll, HR files. The second layer is client data, the names, financials, identities, and communications of the companies and individuals that hired the firm. The third layer is third-party data: the class members in a class action lawsuit, the counterparties in a transaction, the witnesses named in litigation, the targets of an investigation. These are people who have no direct relationship with Greenberg Traurig and no reason to expect their information is held there at all.

All three layers carry attorney-client privilege, which is the extortion angle. A ransomware group threatening to publish privileged legal documents isn’t just threatening one company’s embarrassment. It’s threatening the confidentiality of every client matter touched. That makes the reputational pressure uniquely severe, and the willingness to pay, or at least to engage, correspondingly higher. SilentRansomGroup reportedly extracted a $20 million ransom from a law firm in May 2026 alone.

Understanding the economics of why law firms keep getting targeted is the same logic we’ve covered in the broader ransomware ecosystem, as we detailed in the AudiA6 crypto laundering takedown , ransomware operations are structurally rational businesses that follow the money, and right now the money is in legal sector data.

Six Law Firms in Three Weeks: The Full Timeline

Greenberg Traurig didn’t appear in isolation. Here is every confirmed or claimed SilentRansomGroup law firm incident from the last four weeks of August through the first week of September 2026, in chronological order.

August 12, 2026: Riker Danzig Scherer Hyland & Perretti. A New Jersey firm founded in 1882, listed on the SilentRansomGroup leak site. No public regulatory filing has emerged at the time of writing.

August 12, 2026: WilmerHale (Wilmer Cutler Pickering Hale and Dorr). A separate incident disclosed to Delaware regulators on August 12. This is the largest single filing in the current wave: more than 911,000 affected individuals. The WilmerHale breach predates most of the SilentRansomGroup listings but sits within the same compressed window of law firm targeting.

August 13, 2026: Reminger Attorneys at Law. An Ohio-based firm with a Kentucky and Indiana presence, listed on the group’s leak site.

August 18, 2026: Troutman Pepper Locke (second attack). This is the most alarming entry on the list. SilentRansomGroup’s own leak post described it as the second attack against the same firm within a year. The first was carried out through physical intrusion, an operator who entered the firm’s office in person. DataBreaches.net independently reviewed the leaked material and found it included files marked “privileged and confidential,” mediation records, and spreadsheets containing the names, addresses, and full Social Security numbers of more than 64,000 individuals who are class members in various class action lawsuits. The firm declined to negotiate this time. The data was published.

September 1, 2026: Holland & Knight. A major US firm headquartered in Tampa, listed on the group’s site.

September 2, 2026: Greenberg Traurig. Listed six days before the Vermont regulatory filing, putting the firm in the same campaign as every name above.

This is not a scattered series of opportunistic attacks. This is a deliberate, sustained campaign against a single sector by a single group with 144 listed victims across its total history and an escalating targeting pattern focused on legal services.

The Tactic Nobody Is Talking

The most important detail SilentRansomGroup is not the dark web listing or the regulatory filing. It’s how they’re getting in.

The group started with callback phishing, fake IT support calls that talked employees into installing remote access software. That worked well from 2022 to early 2025. They upgraded to direct vishing (voice phishing calls) starting in March 2025, calling employees directly to extract credentials without software. Both tactics exploited the same gap: employees who trusted a caller claiming to be from IT.

Then in late 2025, the group did something that looks almost absurd until you realize it worked: they started sending operators physically into law firm offices, impersonating IT support personnel, and manually planting storage devices to exfiltrate data directly from the network. The FBI formally confirmed this physical intrusion tactic in May 2026. Halcyon AI’s research describes it as exploiting “the gap between cybersecurity and physical security programs, which are often not integrated and lack coordinated defenses.”

This is what SilentRansomGroup’s own post Troutman Pepper Locke meant when it said “first time through physical intrusion.” They’re documenting their own escalation. The first breach of that firm was carried out by someone who walked through the front door.

For context, most corporate security frameworks treat digital access and physical access as separate domains. Your network has a firewall. Your office has a reception desk. SilentRansomGroup is betting that nobody coordinates between the two, and their track record suggests that bet is frequently correct.

This connects to the same systemic vulnerability we covered in the supply chain and dark web warning signs analysis : the most effective attacks don’t target the hardest part of a system. They target the gap between systems.

What This Means If You’re a Greenberg Traurig Client

Here’s the part no breach announcement explains clearly enough. If you’ve been involved in legal matters that Greenberg Traurig handled, as a client, as a counterparty, as a class member in litigation, as an employee of a client company, your information may sit in files the firm held, even if you never signed anything with them directly.

That’s different from having a password leaked. It’s different from a retailer losing your credit card number. A law firm’s files can contain your legal strategy, your financial disclosures made in confidence, your communications a dispute, and your identity documents submitted during representation.

This kind of data has a long tail. It doesn’t lose value quickly. Someone with your name, your Social Security number, and contextual information your involvement in a legal matter has a ready-made social engineering script. They know what case you were part of. They know who the other parties were. A call from someone who accurately describes your legal history is far more convincing than a generic phishing attempt.

The safest immediate steps for anyone who has been a Greenberg Traurig client, or who worked with any company that was a Greenberg Traurig client on a matter that involved you, are the same practical ones that apply to any serious identity exposure. Our guide on what to do when your personal data is on the dark web walks through the full sequence, credit freezes, fraud alerts, account monitoring, in the order that actually matters.

Credit freezes at all three bureaus (Equifax, Experian, and TransUnion) remain the single most effective defensive step because they block new credit accounts regardless of how convincing an impersonator might be. They cost nothing and don’t affect your existing credit. If Social Security numbers were confirmed exposed, which Vermont’s filing establishes, this step moves from “good idea” to “do it today.”

Report any attempted fraud to the FTC at IdentityTheft.gov or to the FBI’s IC3 at ic3.gov . Both accept reports from individuals affected by data breaches and identity-based fraud.

The Breach Notification Question

One detail the SERP coverage mostly skips over is the timing gap between the dark web listing and the regulatory filing.

SilentRansomGroup listed Greenberg Traurig on its leak site on September 2. Vermont’s regulatory filing arrived September 8. That’s a six-day window. The question worth asking,for any breach involving sensitive legal data, is when the firm first knew the intrusion itself, not just when the dark web listing became public.

Most state breach notification laws require disclosure “without unreasonable delay” after discovery, with specific deadlines varying by state. Vermont law sets a 45-day notification window. The existence of a six-day gap between the dark web post and the regulatory filing doesn’t itself suggest non-compliance, the firm may have been working to scope the incident before filing. But it’s the same structural question that came up in the Substack breach , where a four-month gap between intrusion and discovery turned out to be the most significant failure in the incident.

Greenberg Traurig has not disclosed when it first detected the intrusion, and the investigation is described as ongoing. Those questions will likely surface in class action litigation, which two plaintiff’s law firms had already announced investigating as of September 9, 2026.

Why Removing Data from the Dark Web Won’t Solve This

When the Greenberg Traurig story broke, some coverage implied the firm was working to “address” the dark web posting. That framing deserves clarification.

A ransomware group’s leak site is not like a public website that can be asked to take something down. It’s hosted on the Tor network. The operator controls it. The threat group publishes what they choose to publish, and data they release spreads across forums, Telegram channels, and other leak aggregators within hours.

Even if the listing itself disappeared tomorrow, which SilentRansomGroup has no incentive to enable, anything already downloaded from it is already circulating. The data from the Troutman Pepper Locke case, for example, was posted and then pulled by the group, but the window in which it was accessible was sufficient for it to be copied. As we covered in the guide on whether your data can be removed from the dark web , removal of the original posting doesn’t recover the copies. It just removes one door. The data remains.

Frequently Asked Questions

What happened at Greenberg Traurig?

A ransomware group called SilentRansomGroup claimed to have breached the firm on September 2, 2026, and threatened to publish stolen data unless negotiations began. Greenberg Traurig confirmed “limited data” was posted to the dark web and filed a breach notice with the Vermont Attorney General on September 8, disclosing Social Security number exposure for at least 10 Vermont residents.

How many people were affected?

A total number has not been disclosed. Vermont’s filing confirms 10 residents, but the firm has no Vermont office, suggesting the affected population extends significantly beyond that state.

Who is SilentRansomGroup?

A financially motivated ransomware-as-a-service operation also tracked as Luna Moth and UNC3753. Originally emerged in 2022 after the Conti collapse. Specializes in targeting US law firms. Has evolved from callback phishing to vishing to in-person physical intrusion to gain access to law firm networks.

Is Greenberg Traurig the only law firm hit?

No. SilentRansomGroup has hit at least five other law firms in the same August-September 2026 window, including WilmerHale (911,000 affected individuals disclosed to Delaware), Troutman Pepper Locke (second attack, 64,000+ class action members’ SSNs leaked), Holland & Knight, Reminger, and Riker Danzig Scherer Hyland & Perretti.

What should I do if I was a Greenberg Traurig client?

Freeze your credit at all three bureaus. Set up fraud alerts. Watch for phishing calls that reference your legal matter details. Report any fraud attempts to IdentityTheft.gov or ic3.gov.

Can my data be removed from the dark web?

No. Once data is published on a dark web leak site, it spreads to multiple channels and cannot be recalled. The correct response is to make the exposed data as difficult to misuse as possible, not to attempt removal.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

Infostealer Logs – The Breach That Rarely Gets Reported

Infostealer logs: In the first half of 2025, over 1.8 billion credentials containing saved passwords, usernames, phone numbers,…

Inside India’s New Darknet Crypto Cell – What It Does and Why It Exists

India has established a special unit for tracking drug money on the dark web. On September 6, 2026,…

Carders Now Vet Their Suppliers Like Amazon Reviews. Here’s How the Stolen Card Economy Actually Works.

There’s a document circulating on underground forums right now with a title that sounds like a post…

Substack Data Breach: 663,000 Accounts Were Exposed for Four Months Before Anyone Noticed

In October 2025, someone got into Substack’s systems and quietly pulled out data on hundreds of thousands of…

ValueFirst Appeared in a Dark Web Alert. Here’s Why That’s Worth Paying Attention To.

On September 7, 2026, at around 6:16 PM, a dark web intelligence monitoring account called @DailyDarkWeb posted a…

Google Killed Its Dark Web Report – What to Use Instead

Starting from the 16th of February 2026, Google dark web report shut down its operation completely. This comes…