It seems often that not a day goes by that some new breach affects the world in which we live. By breach, of course, I refer to a cyber-attack. When we hear of these happening, we should pay attention to many of the facets involved. There are lessons to be learned as each breach develops and information is released and it would be negligent not to pay attention to them.

The large law firm of Lewis Brisbois is one of the most recent attacks. As part of the ongoing incident the firm recalled its remote workers back to their offices, after they had blocked external access to their internal networks. This is a fairly large step, for reasons that will become clear as we will see.
This order came 5 days AFTER the firm’s information security director issued an email warning employees about the ongoing attack. “We are receiving reports from across the firm of cyber criminals calling employees, including on cellphones, posing as internal IT department personnel and falsifying caller ID, asking for urgent action to secure accounts,” which was written in an email back on June 5h.
Stop here and start taking notes. The email acknowledges an ongoing incident, which seems to be primarily focused on social engineering type attacks. Phone calls, imitation of internal IT personnel and even switching caller ID to hide their identities. This seems to be a well-orchestrated and prepared attack. Now it is not uncommon for attackers to utilize these techniques, at all. I even use them in penetration tests to target individuals within a company. But the thing to note here is that this attack had precursors. Probably not noticeable to cyber security personnel but present, nonetheless. Every company has information spread all over the Internet and all it takes is a little bit of digging to uncover very useful information. In the world of hacking this is known as reconnaissance.
An article in Bloomberg stated that these techniques are often used by a threat group called Silent Ransom, but that should not be set in stone. Many groups use these exact same techniques, and they have been around for years. Also of note, the FBI issued a bulletin back in May of 2025, warning law firms in particular that Silent Ransom was targeting their organizations. So, prior warning was already made, my questions would be the following:
- Did the legal firms take notice of this warning? Did they even know it was posted over a year ago and took preemptive action? Such warnings are common, but also commonly overlooked by future victims!
- Threat intelligence is vital to any cyber-security program. Warnings, bulletins and knowledge of ongoing attacks are vital to preparing for such incidents.
But, moving on. Lewis Brisbois, making a move such as requiring all employees to work from the office is amazing. What stood out to me is that the Bloomberg Law article said that the firm “expects to permanently ban employees from accessing systems through personal devices.” Wait, what? Do companies still allow employees to use personal systems to connect to the business network? How is that even managed and monitored? Or is it?
That creates a major problem. Working from home is not new, it was even around before the Covid era. Acceptable Use Policies are a necessity in the corporate world today. The amount of data, sensitive in many ways, that employees have access to is amazing, and neglecting to properly protect that data in the modern era of remote work is negligent to say the least! To top this action off, Lewis Brisbois reported that they are struggling to even find the equipment necessary to issue to employees.
If you remember the major Sony hack, they also struggled with equipment loss. Their incident was different, but they lost access to many systems, including cell phones! They had to go to a storage closet and get old phones back into service to be able to continue their business. This should be covered in the Disaster Recovery Plan, as well as the Incident Response Plan of any company. Sadly, these are often overlooked. But equipment can be lost to environmental factors, to malware, or to several other issues and every organization should have a plan in place to provide substitutes for their employees.
As with any public incident or breach, we should take advantage of learning the lessons presented. Even if we do not know the full details of what occurred, we can begin early to take steps to enhance our own protective posture!
Carpe Diem!
Leave a Reply