CSIDB logo
Incident

Jones Day

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-09 01:47

Linked entities

Victim
Jones Day
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2026
Discovered
Undetermined
Disclosed
May 2026
Resolved
Pending

Summary

Jones Day was targeted by the Silent Ransom Group, which posted data belonging to ten of the firm’s clients. The incident underscores why law firms are attractive targets due to the volume and sensitivity of their client information and has prompted discussion of ethical duties, breach‑notice obligations, and the potential for class‑action litigation following such exposures.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Law firms are especially attractive targets for data breaches given the volume and sensitivity of their data. In April, Jones Day became the latest victim of the "Silent Ransom Group," a hacking ring that posted data from 10 of the firm’s clients. The Silent Ransom Group is known for exfiltrating and publishing client information from compromised law firms. The exposure of client data from Jones Day triggered concerns about confidentiality and potential misuse of the disclosed information. The incident highlights the ongoing threat posed by ransomware‑oriented actors to legal practices.

Under ABA Formal Opinions 477R and 483, lawyers must use reasonable efforts to safeguard client information, detect and respond to incidents, and communicate with affected clients when a breach occurs. Notice requirements compel firms to promptly evaluate obligations when they know or reasonably should know that a data breach has occurred. Firms must notify current clients if the breach involves or has likely involved material client information or impairs their ability to perform legal services. Notice should disclose the breach and known extent of affected information and be shared without unreasonable delay. State breach‑notification laws, in effect as of January 1, 2026, set deadlines ranging from 30 to 60 days or require notice “without unreasonable delay” depending on the jurisdiction. Federal statutes such as HIPAA, the GLBA, and SEC rules may impose additional reporting duties when law firms handle protected health information, financial data, or securities‑related information. Affected individuals may pursue class‑action claims alleging negligence, breach of implied contract, breach of fiduciary duty, and violations of state or federal statutes that provide a private right of action.

Sources

Sources available to members: 1 source.

CSIDB