CSIDB logo
Incident

Lewis Brisbois Bisgaard & Smith LLP

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-10 04:17

Linked entities

Victim
Lewis Brisbois Bisgaard & Smith LLP
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Lewis Brisbois Bisgaard & Smith LLP experienced a cyberattack in which threat actors posed as internal IT staff via phone calls with falsified caller IDs to trick employees into granting remote access. The campaign, consistent with tactics used by the Silent Ransom Group (also known as Luna Moth), targeted remote and hybrid workers using personal devices to connect to the firm’s network. In response, the firm blocked external access from personal devices, instructed remote and hybrid staff to work onsite or use firm‑issued equipment, and began distributing additional hardware to support the change. While investigators have not confirmed whether the attackers breached the network, the incident prompted a review of security controls and highlighted the growing reliance on social engineering against large law firms.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 5 2026 Curtis Hendzell, the director of information at Lewis Brisbois Bisgaard & Smith LLP, sent a firm‑wide email warning employees that the company was receiving reports of cyber criminals calling staff on cellphones, posing as internal IT department personnel, falsifying caller IDs and requesting urgent action to secure accounts, urging recipients to hang up on and report such calls. The email noted that several support staff members worked remotely or on hybrid schedules, signing into the firm’s computer network from personal devices, a configuration that cybersecurity professionals said made the firm vulnerable to threat actors seeking remote control of a device already accessing the virtual network. On June 10 2026 the firm issued another email, viewed by Bloomberg Law, stating that an “event” had taken place earlier that month and that, as a result, Lewis Brisbois was shutting off access to its internal network from employees’ personal devices. The June 10 message, authored by office administrator Elijah Bernal, instructed all remote and hybrid employees to either work from the firm’s offices or bring their firm‑issued computer setups home, pending the purchase and distribution of additional equipment. Bernal wrote that, until additional equipment could be obtained, those on remote or hybrid schedules would need to work onsite or bring their current office setup home, and he noted that bringing office equipment home might present challenges with Wi‑Fi connectivity, asking employees who were absolutely unable to work in the office to request a temporary work solution. The firm indicated that it expected to permanently ban employees from accessing systems through personal devices once the transition was complete.

The tactics described in the June 5 and June 10 emails matched the pattern of a social engineering campaign in which attackers cold‑called employees, pretended to be IT support, and used psychological pressure to persuade targets to divulge credentials or grant remote access, a method that the FBI had highlighted in a May 2026 bulletin warning that the Silent Ransom Group—also known as Luna Moth—was targeting law firms through such techniques, including phone calls, emails and in‑person visits. The bulletin noted that the group sought to bypass two‑factor authentication and other security measures, and that large law firms remained attractive targets because they maintained large volumes of sensitive information, making them a one‑stop shop for threat actors. Silent Ransom was described as known for sophisticated social engineering schemes that aimed to extort firms by threatening to release stolen data unless a ransom was paid, with some groups reportedly looking for cyber insurance policies and requesting policy limits as the ransom amount; a Clark Hill partner cited an unnamed law firm that had allegedly paid $10 million to avoid the release of hacked data. The group had been linked to recent hacks of Orrick Herrington & Sutcliffe and Fox Rothschild, according to lawsuits filed against those firms.

In the case of Fox Rothschild, the firm’s chief artificial intelligence and information security officer, Mark McCreary, stated in an email that a lawyer had become the victim of a sophisticated social engineering attempt, but that the incident was limited to a single device associated with the user involved, there was no broader access to the firm’s systems or network, the activity was quickly mitigated and contained, and the firm was conducting a thorough review of the involved data and would provide notice as required by law. Orrick Herrington & Sutcliffe declined to comment on its breach, noting that a related lawsuit against the firm had been quickly withdrawn. Lewis Brisbois representatives did not respond to requests for comment regarding whether the attackers had successfully infiltrated the firm’s network, and it remained unclear from the available sources if any data had been exfiltrated or if any ransom demand had been made.

The firm’s response to the perceived threat included a rapid shift in work‑from‑home policy, a push to procure additional firm‑issued hardware, and a directive to restrict network access to devices controlled by the company. Chris Loehr, executive vice president and co‑founder of threat detector Cyrenity Cyber, commented that restricting access to the virtual network to firm‑controlled devices added a layer of security, making it easier to pinpoint suspicious IP addresses during an incident response, and noted that if a VPN had been part of the attack vector, requiring employees to work onsite or use firm‑issued equipment was a typical step to cut off that vector. Loehr added that he was surprised a firm of Lewis Brisbois’s size had not already restricted access for personal devices, observing that many law firms operated successfully without allowing employees to use personal equipment for work.

Lewis Brisbois, founded in Los Angeles, reported having more than 1,600 attorneys nationwide at the time of the incident. The firm’s managing partner, Greg Katz, had assumed leadership after a tumultuous period in 2023 during which more than 100 lawyers departed, and he had subsequently installed new chiefs of technology and information as part of efforts to upgrade the firm’s technology infrastructure. The June 10 email from Bernal indicated that the firm was scrambling to obtain additional computers and devices to accommodate employees who were required to bring their office setups home or work onsite. The narrative of the incident, as reflected in the source material, consists of the initial warning about fraudulent IT‑support phone calls, the subsequent decision to block personal‑device network access, the mandate for remote staff to return to the office or use firm‑issued hardware, the firm’s public statements about the attack’s similarity to known Silent Ransom tactics, the lack of confirmed infiltration or data loss, and the organizational changes undertaken by leadership in the aftermath. No further details about the attack’s technical specifics, the exact number of employees affected, or any eventual legal or financial consequences were provided in the available sources.

Sources

Sources available to members: 2 sources.

CSIDB