CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 309

As cited

Copy frozen at (site build).

threat intel

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

UNC3753, a financially motivated threat group, conducted a data theft extortion campaign from January through May 2026 targeting US law firms and professional services organizations. The group used voice phishing and social engineering to trick employees into downloading remote access tools, then either searched systems directly or manipulated victims into stealing sensitive data like legal agreements and financial records for extortion. In some cases, actors physically entered corporate offices posing as IT technicians to extract data via USB media.

Why it matters: Legal and financial services practitioners need immediate awareness of this multi-vector attack pattern since UNC3753 has demonstrated the ability to compromise networks within hours and scale operations across dozens of organizations, requiring urgent review of voice phishing defenses, remote access policies, physical security controls, and employee verification procedures.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

UNC3753, a financially motivated threat group, conducted a data theft extortion campaign from January through May 2026 targeting US law firms and professional services organizations. The group used voice phishing and social engineering to trick employees into downloading remote access tools, then either searched systems directly or manipulated victims into stealing sensitive data like legal agreements and financial records for extortion. In some cases, actors physically entered corporate offices posing as IT technicians to extract data via USB media.

Why it matters: Legal and financial services practitioners need immediate awareness of this multi-vector attack pattern since UNC3753 has demonstrated the ability to compromise networks within hours and scale operations across dozens of organizations, requiring urgent review of voice phishing defenses, remote access policies, physical security controls, and employee verification procedures.

VendorsMicrosoftGoogleZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary