Skip to main content
Back to overview
Medium

Global law firm Jones Day confirms cyber attack and client data access

Jones Day acknowledged that an “unauthorised third party accessed a limited number of dated files for 10 clients” and that all affected clients have been notified.

Key points

  • Confirmed a "phishing incident" affecting client files.
  • Unauthorized access to dated files for 10 clients.
  • Silent Ransom Group claimed responsibility.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking activity

03

Potential impact

Potential operational disruption

Availability

Published
Apr 7, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Availability

Mentioned entities

JonesdayGlobalJones DayFederal CircuitGreg Castanias. Jones DaySilent Ransom GroupLuna MothChatty SpiderUNC3753According

Quick context

Questions about this signal

What happened in this signal?

Jones Day acknowledged that an “unauthorised third party accessed a limited number of dated files for 10 clients” and that all affected clients have been notified. The attackers claimed they focused on the head of the firm’s Federal Circuit team, supposedly referring to Greg Castanias. Jones Day declined to identify the clients or the specific files involved, displaying the kind of attention to secrecy that could’ve avoided this whole problem to begin with. The attack has been attributed to the Silent Ransom Group , also known as Luna Moth, Chatty Spider, and UNC3753 — all excellent garage band names for anyone in the market. According to an FBI alert last May , SRG has been targeting law firms specifically since 2023. But that was before the federal law enforcement agency embarked on a half-baked loyalty purge and reassigned the remaining agents to rounding up roofers and threatening people for making fun of Trump on Instagram . Today, the FBI exists mostly as a luxury travel agent for Kash Patel to slam beers with hockey players . As a bulwark against cybercrime, the FBI is essentially an offensive lineman who immediately turns around and yells “incoming!” at the quarterback. Filevine’s New Legal AI Platform LOIS Turns AI Into A True Legal Coworker Legal work isn’t slowing down, and the firms that win won’t be the ones working harder — they’ll be the ones working smarter. Jones Day confirms cyber attack after hackers access client files Jones Day has become the latest high-profile law firm to fall victim to a cyber attack, after hackers accessed files linked to a number of client matters. The US firm — which represented Donald Trump in both his 2016 and 2020 presidential campaigns and has placed several of its lawyers into senior White House and Justice Department roles — confirmed it had experienced a “phishing incident” in which “unauthorised third party accessed a limited number of dated files for 10 clients.” All affected clients have been notified, though the firm declined to name either them or the specific files involved. The attack has been linked to the Silent Ransom Group, which has claimed responsibility for the breach. Reuters reports that the group published a file directory and screenshots of purported negotiations with Jones Day representatives, and is said to have specifically targeted Greg Castanias, a senior Washington-based partner who leads the firm’s Federal Circuit practice. Jones Day has found itself in the crosshairs before, and in 2021 the firm was among several major companies caught up in a hack of file transfer software linked to a separate ransomware group. Jones Day is one of a number of major law firms to have been targeted in recent years. Allen & Overy was hit by an attack linked to the LockBit ransomware group in 2023, before its merger with Shearman & Sterling, though the firm was later quietly removed from the group’s website without explanation. Quietly removed from the website suggests that a ransom might have been paid. Solicitor pretended to be police officer to spy on ex at Nando’s City lawyer charged with insider dealing Food company posts eye-catching job ad seeking corporate lawyer with ‘gravitas of a senior partner’ for unpaid role

When was this signal reported?

Shadow Tier lists Apr 7, 2026 as the signal date.

Which organization is connected to this signal?

Jonesday is the organization connected to this public signal.

Explore Jonesday
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents