Aon | Professional Services Practice
When Trust Becomes the Attack Surface: Why Law Firms Are the Warning Sign for Every Industry
Release Date: October 2026The Luna Moth cyber campaigns point towards a future where cyber extortion increasingly exploits something very difficult to secure: trust.
Key Takeaways
- Law firms are prime targets because they hold highly sensitive client and matter data.
- Trust is being exploited through impersonation, social engineering, and remote access abuse.
- These methods are templates for attacks on other professional service firms and on other industry sectors. For all organizations, cyber resilience is no longer solely a technology challenge.
For years, law firm cyber risk discussions have centered on ransomware, email compromise, and exploitation of software vulnerabilities.
But the recent surge of attacks attributed to the threat group Luna Moth, also tracked as Silent Ransom Group (SRG), Chatty Spider, and UNC3753, demonstrates that many firms may be defending against yesterday's threats while adversaries are increasingly exploiting something far more difficult to secure: trust.
Unlike traditional ransomware operators, Luna Moth generally does not rely on encrypting systems or deploying destructive malware.
Instead, the group specializes in social engineering, impersonation, and extortion. Their objective is straightforward: gain access to sensitive information, exfiltrate high-value data, and pressure victims into paying to prevent disclosure.
Law firms represent an especially attractive target, routinely maintaining highly sensitive information involving mergers and acquisitions, litigation strategy, intellectual property, internal investigations, privileged communications, regulatory matters, and personally identifiable information.
Exposure of this sensitive data creates significant reputational, operational, regulatory, and client relationship consequences.
For threat actors focused on extortion rather than encryption, few sectors present a more appealing target.
A Different Kind of Adversary
The rise of Luna Moth highlights an important shift in cybercrime.
Historically, organizations invested heavily in technologies capable of detecting malware, blocking malicious executables, and identifying ransomware encryption activity. Luna Moth intentionally avoids many of these indicators.
According to public reporting from the FBI and Mandiant, the group's campaigns often leverage legitimate business communications, phone calls, remote administration tools, and human manipulation rather than sophisticated malware. In many cases, victims are persuaded to voluntarily grant access to systems or assist attackers in performing actions that facilitate data theft.
This attack pathway matters because traditional security controls may have limited effectiveness when an employee genuinely believes they are interacting with internal IT personnel or a legitimate service provider and therefore willingly grants access to a trusted device.
In several publicly reported incidents, attackers allegedly impersonated help desk personnel, technology support staff, or service providers. More recent reporting has also described incidents involving individuals physically appearing at office locations posing as IT personnel.
The implication of these attacks is significant. The attack surface no longer exists solely within networks, endpoints, and cloud environments. It also exists within business processes, employee trust relationships, and physical office operations.
How an Attack Typically Unfolds
While individual intrusions vary, public reporting reveals a common pattern.
The attack often begins with an innocuous communication. Victims may receive an email related to an invoice, technology issue, migration activity, or service request. The communication frequently contains little or no malicious content. Instead, it serves as a pretext to initiate further engagement.
The next phase typically involves direct interaction with a targeted employee. Attackers may impersonate technology support personnel on calls and direct the employee to a fake support portal. During these conversations, attackers leverage urgency, credibility, and authority to build trust.
Once trust is established, the employee is encouraged to participate in a screen-sharing session, visit a fraudulent website, install remote management software, or otherwise grant access for what appears to be a technology support request. Public reporting indicates that commonly referenced tools include legitimate remote monitoring and management solutions frequently used by IT departments.
After obtaining access, the attackers move quickly.
While ransomware groups may spend weeks conducting reconnaissance, Mandiant has reported that in these attacks data identification, staging, theft, and extortion can occur within hours of initial compromise. Sensitive legal documents, financial records, client information, and other confidential materials are exfiltrated rapidly.
After the data has been removed, the objective becomes clear.
Victims receive extortion demands threatening publication or disclosure of stolen information often within thirty minutes. Because operations frequently continue without encryption-related disruption, some organizations may initially underestimate the severity of the incident until the full extent of data loss is established.
Why Every Industry Should Pay Attention
Although public reporting has primarily focused on attacks against law firms, there is little about the Luna Moth playbook that could not be used elsewhere.
The group's success stems from its ability to exploit people, processes, and trust relationships rather than industry-specific technology vulnerabilities.
Public reporting from the FBI and Mandiant indicates that Luna Moth has targeted organizations across professional services, financial services, and other sectors, using the same core methodology of impersonation, social engineering, remote access abuse, and data theft.
Law firms may be particularly attractive because of the volume of confidential client information they maintain, but the underlying attack model is highly transferable.
Any organization that houses sensitive information, intellectual property, financial data, regulated personal information, or strategic business records could become a viable target.
And in many respects, the tactics employed by Luna Moth align with broader trends across the threat landscape.
Cybercriminals increasingly recognize that gaining access through an employee can be faster, cheaper, and more reliable than identifying and exploiting technical vulnerabilities.
As organizations continue to strengthen endpoint protection, patch management, and network defenses, human trust is becoming a preferred attack vector.
Those likely to face similar campaigns include:
- Accounting and advisory firms, which maintain sensitive financial records, tax information, and confidential client communications.
- Management consulting firms, which often possess strategic plans, merger activity, market intelligence, and proprietary research.
- Healthcare organizations, where patient information and operational disruption concerns can create significant extortion leverage.
- Financial institutions, which maintain valuable financial data and extensive client relationships built on trust.
- Insurance organizations, brokers, and third-party administrators that routinely hold sensitive commercial, financial, and personal information.
- Technology and software providers, particularly those with access to customer environments or intellectual property.
Many of these sectors share characteristics that make law firms attractive targets: large volumes of sensitive information, relationship-based business models, extensive use of external vendors, and employees accustomed to servicing clients and responding quickly to requests.
The emergence of reported in-person impersonation efforts should further elevate concerns across industries.
Traditional cyber defenses are often designed to identify malicious emails, malware, or unauthorized network activity. They are generally less effective when an attacker arrives as a seemingly legitimate contractor, technician, or support representative.
Public reporting indicates that some Luna Moth-linked operations have incorporated physical-world deception into their campaigns, further blurring the distinction between physical and cyber security risks.
Luna Moth, therefore, should not merely be viewed as a threat actor targeting law firms, but as an example of a broader evolution in cybercrime. The techniques being refined today against law firms could easily become tomorrow's standard operating procedure against a much wider range of organizations.
The Strategic Takeaway
The most important lesson from the Luna Moth campaigns is that cyber resilience is no longer solely a technology challenge.
The most resilient organizations will be those that recognize a fundamental reality – the next generation of cyber extortion campaigns may not begin with malware or software vulnerabilities. They may begin with a persuasive voice on the phone, a convincing email, a trusted-looking website, or an individual standing in the lobby claiming to be there to help.
As organizations grabble with defending against such tactics, it should be assumed that trusted devices will get compromised. Limiting the blast radius requires a combination of technical controls, governance, awareness, and preparedness. Identity verification procedures, remote access governance, privileged access management, data protection strategies, modern awareness training, and extortion-focused incident response planning should all form part of a comprehensive defense strategy.
The organizations that will emerge strongest in this evolving threat landscape will be those that recognize a fundamental shift in cyber risk. The next breach may not begin with a compromised system, but with a successfully exploited act of trust.
Contact
The Professional Services Practice at Aon values your feedback. To discuss any of the topics raised in this article, please contact Brian Gillin.
Brian Gillin
National Product Leader, Head of Cyber, North America
New York
About Aon
Aon (NYSE: AON) exists to shape decisions for the better — to protect and enrich the lives of people around the world. Through actionable analytic insight, globally integrated Risk Capital and Human Capital expertise, and locally relevant solutions, our colleagues provide clients in over 120 countries with the clarity and confidence to make better risk and people decisions that help protect and grow their businesses.
Follow Aon on LinkedIn, X, Facebook and Instagram. Stay up-to-date by visiting Aon’s newsroom and sign up for news alerts here.
©2026 Aon plc. All rights reserved.
Aon is not a law firm or accounting firm and does not provide legal, financial or tax advice. Any commentary provided is based solely on Aon’s experience as insurance practitioners. We recommend that you consult with your own legal, financial and/or insurance advisors on any commentary provided herein. All descriptions, summaries or highlights of coverage described herein are for general informational purposes only and do not amend, alter or modify the actual terms and conditions of any relevant policy. Coverage is governed only by the terms and conditions of such policy. Insurance coverage in any particular case will depend upon the type of policy in effect, the terms, conditions and exclusions in any such policy, and the facts of each unique situation. No representation is made that any specific insurance coverage would apply in the circumstances outlined herein. Please refer to the individual policy forms for specific coverage details.
The information contained in this document and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity.
This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.
Insurance products and services offered by Aon Risk Insurance Services West, Inc., Aon Risk Services Central, Inc., Aon Risk Services Northeast, Inc., Aon Risk Services Southwest, Inc., and Aon Risk Services, Inc. of Florida and their licensed affiliates.
