CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats Apr 07, 2026

Jones Day confirms limited breach after phishing attack by Silent Ransom Group

DataBreaches.net Archived Apr 07, 2026 ✓ Full text saved

One of the top-ranked law firms in the country confirmed today that it has suffered a data breach. Jones Day disclosed the breach after hackers known as Silent Ransom Group (SRG) posted the data ​to their dark web leak site on March 30. A spokesperson for the firm said that limited files for 10 clients... Source

Full text archived locally
✦ AI Summary · Claude Sonnet


    One of the top-ranked law firms in the country confirmed today that it has suffered a data breach. Jones Day disclosed the breach after hackers known as Silent Ransom Group (SRG) posted the data ​to their dark web leak site on March 30. A spokesperson for the firm said that limited files for 10 clients were obtained, and that all affected clients were notified. The Silent Ransom Group , also known as Luna Moth , Chatty Spider , and UNC3753 , has been targeting law firms since early 2023, “likely due to the highly sensitive ‌nature ⁠of legal industry data,” the FBI said in a private industry notification it issued last year. As part of the leak, SRG included a file tree and a screenshot showing part of what appears to be a negotiation chat between the threat actors and representatives of Jones Day from March 20 to March 28. Jones Day has not confirmed that the screenshot is accurate or that the full interactions are accurate, but if it is, it appears that SRG demanded $13,000,000.00, presumably to delete the data and keep quiet about the attack. There is nothing in the screenshot suggesting that Jones Day ever made a counteroffer for that amount. As days went by without resolution, SRG’s negotiator, who identified themselves as “Ammiel Olsen” for negotiations, resorted to the type of threats we have often seen in unsuccessful negotiations. The final communication in the screenshot, dated March 28, warned Jones Day: In case by Monday 12pm Central time there won’t be any response, We will publish all your data, contact every employee of your firm and all your clients to notify them about the data leak. Our attacks will resume to your firm and more of your data will be possessed and published. Our attack was conducted on the head of your firm’s Federal Circuit team, a key member of your firm, your name will Glow on news and journalists, your competitors and enemies will be glad to find that out, especially after being exposed in the Epstein files about your ties with child predators. The data leak will only worsen your situation, you will face significant financial, reputational and legal difficulties and We will make sure all of the above happens. Reuters reports that the hackers were referring to Greg Castanias, who leads the Jones Day ​team handling cases before the U.S. Court of Appeals for the Federal Circuit. Castanias reportedly declined to comment. There has been no indication that SRG has resumed attacking Jones Day, successfully re-attacked them, or acquired more data. Because SRG does not provide contact information on their leak site, DataBreaches was unable to contact them to request any update. This was not Jones Day’s first data breach. The firm was one of many companies affected by Clop threat actors exploiting a vulnerability in the Accellion file transfer program used by many firms. Category: Breach Incidents Business Sector Hack Phishing
    💬 Team Notes
    Article Info
    Source
    DataBreaches.net
    Category
    🛡 Active Threats
    Published
    Apr 07, 2026
    Archived
    Apr 07, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗