The FBI put out an advisory this year about a crew that has been working U.S. law firms since 2023. They don't break in. They call your front desk pretending to be IT, or they walk into the office in person, and they ask someone to hand over remote access.
Then they copy files and threaten to publish them.
Notice what's missing: no encryption, no locked screens, no ransom note on the server. Nothing looks broken. The firm finds out when the extortion email arrives, and by then the client files are already sitting on someone else's drive.
Backups don't save you here. You still have your data. So does the attacker.
What helps is making the documents themselves useless once they leave. Sensitivity labels in Microsoft 365 wrap encryption around the file itself, not the folder it sits in. A labeled settlement agreement copied to a personal cloud drive is a file nobody can open. That same document emailed to the wrong recipient stays unreadable.
Most firms already own this. Manual labeling is included in Microsoft 365 Business Premium, and almost nobody has switched it on. Automatic labeling needs a bigger license, but hand-labeling your three most sensitive document types is an afternoon of work.
Worth a look before your next cyber renewal. The question isn't whether you can restore the files. It's what those files can do once they're out of your hands.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email