Jones Day confirms limited breach after phishing attack by Silent Ransom Group
DataBreaches.netArchived Apr 07, 2026✓ Full text saved
One of the top-ranked law firms in the country confirmed today that it has suffered a data breach. Jones Day disclosed the breach after hackers known as Silent Ransom Group (SRG) posted the data to their dark web leak site on March 30. A spokesperson for the firm said that limited files for 10 clients... Source
Full text archived locally
✦ AI Summary· Claude Sonnet
One of the top-ranked law firms in the country confirmed today that it has suffered a data breach. Jones Day disclosed the breach after hackers known as Silent Ransom Group (SRG) posted the data to their dark web leak site on March 30. A spokesperson for the firm said that limited files for 10 clients were obtained, and that all affected clients were notified. The Silent Ransom Group , also known as Luna Moth , Chatty Spider , and UNC3753 , has been targeting law firms since early 2023, “likely due to the highly sensitive nature of legal industry data,” the FBI said in a private industry notification it issued last year. As part of the leak, SRG included a file tree and a screenshot showing part of what appears to be a negotiation chat between the threat actors and representatives of Jones Day from March 20 to March 28. Jones Day has not confirmed that the screenshot is accurate or that the full interactions are accurate, but if it is, it appears that SRG demanded $13,000,000.00, presumably to delete the data and keep quiet about the attack. There is nothing in the screenshot suggesting that Jones Day ever made a counteroffer for that amount. As days went by without resolution, SRG’s negotiator, who identified themselves as “Ammiel Olsen” for negotiations, resorted to the type of threats we have often seen in unsuccessful negotiations. The final communication in the screenshot, dated March 28, warned Jones Day: In case by Monday 12pm Central time there won’t be any response, We will publish all your data, contact every employee of your firm and all your clients to notify them about the data leak. Our attacks will resume to your firm and more of your data will be possessed and published. Our attack was conducted on the head of your firm’s Federal Circuit team, a key member of your firm, your name will Glow on news and journalists, your competitors and enemies will be glad to find that out, especially after being exposed in the Epstein files about your ties with child predators. The data leak will only worsen your situation, you will face significant financial, reputational and legal difficulties and We will make sure all of the above happens. Reuters reports that the hackers were referring to Greg Castanias, who leads the Jones Day team handling cases before the U.S. Court of Appeals for the Federal Circuit. Castanias reportedly declined to comment. There has been no indication that SRG has resumed attacking Jones Day, successfully re-attacked them, or acquired more data. Because SRG does not provide contact information on their leak site, DataBreaches was unable to contact them to request any update. This was not Jones Day’s first data breach. The firm was one of many companies affected by Clop threat actors exploiting a vulnerability in the Accellion file transfer program used by many firms. Category: Breach Incidents Business Sector Hack Phishing