Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

June 8, 2026, 8:53 a.m.

Description

From January through May 2026, a financially motivated data theft extortion campaign executed by threat cluster UNC3753 targeted dozens of organizations across professional, legal, and financial services in the United States. The threat actors leverage voice phishing and social engineering techniques, posing as IT support to convince targets to host screen-sharing sessions and download remote monitoring and management utilities. Once inside environments, they conduct searches to locate and exfiltrate highly sensitive data including proprietary legal agreements, personally identifiable information, and financial records for subsequent extortion demands. The entire attack sequence often occurs within a single business day, with recent incidents showing data theft initiated in under an hour. Notably, threat actors have also accessed victims' systems in person, with individuals posing as IT technicians entering corporate offices to attempt direct exfiltration using USB storage media.

Date

  • Created: June 5, 2026, 6:07 p.m.
  • Published: June 5, 2026, 6:07 p.m.
  • Modified: June 8, 2026, 8:53 a.m.

Indicators

  • 193.141.60.212
  • 64.94.84.97
  • 174.169.162.62

Attack Patterns

  • BAZARLOADER
  • Ursnif - S0386
  • LOCKBIT.BLACK
  • TrickBot - S0266
  • SILENTNIGHT
  • Totbrick
  • PE_URSNIF
  • UNC3753

Additional Informations

  • Finance
  • Government
  • itdesk.com
  • business-data-leaks.com
  • lockbit.black
  • United States of America