Your Vendor's Breach Is Your Breach: INC Ransom's Law Firm Cluster
- Jun 25
- 6 min read

By Yonatan Hoorizadeh — CISSP, CISM, CRISC, AAISM
Published by Purple Shield Security
INC Ransom posted 10 law firms to its leak site in a 48-hour window in March 2026, part of 20 legal organizations it has claimed this year — a clustering Halcyon says points to a possible breach of a shared legal-technology vendor. The lesson for small firms: a breach of your practice-management, document, or IT provider is functionally your breach, and your client data is on the line.
What happened with INC Ransom and the law firms?
The INC Ransom ransomware group listed ten law firms and legal-services organizations on its dark web leak site inside a single 48-hour window. According to a March 11, 2026 alert from the Halcyon Ransomware Research Center, that pace is unusual even for a busy ransomware-as-a-service operation, and it brings INC's 2026 legal-sector total to 20 organizations.
INC Ransom first surfaced in mid-2023 as a ransomware-as-a-service (RaaS) operation — a model where the core group rents its tooling to affiliates who carry out attacks. Halcyon describes INC as a double-extortion actor: it both steals data and encrypts systems, then threatens to publish the stolen files if the victim refuses to pay. The leak site is the public pressure lever.
Law firms have become a steady target. Halcyon tracked more than 200 ransomware incidents against the Law Firms & Legal Services sector between 2025 and early 2026. The firm attributes the appeal plainly: legal organizations hold concentrated, sensitive client data, face regulatory pressure to resolve incidents quickly, and are seen as willing to pay to protect attorney-client privilege.
Why does a cluster of victims point to a shared vendor?
Ten firms surfacing in 48 hours is the kind of pattern that rarely comes from ten separate, unrelated break-ins. Halcyon's assessment is that the clustering is consistent with a single upstream compromise — a breach of one technology provider that multiple firms all rely on, giving an attacker simultaneous access to everyone downstream.
The candidate vendors Halcyon names are the ones small and mid-sized firms lean on every day: a shared legal practice-management platform, a document-management system, an e-discovery tool, or a managed IT services provider. Compromise one of those, and you don't breach one firm — you breach every client on the platform at once.
Important caveat: Halcyon is clear that there is no confirmed evidence yet of a specific supply-chain vector. The supply-chain theory is the most likely explanation for the pattern, not a proven root cause. That distinction matters — but it doesn't change what a firm should do, because the exposure is the same whether the cluster turns out to be one shared vendor or several.
Why is a vendor's breach your breach?
Because the obligations don't transfer with the data. When you hand client files to a practice-management platform or an outsourced IT provider, you are still the entity that owes those clients a duty of confidentiality. If that vendor gets breached, you are the one explaining it to clients, to your malpractice carrier, and potentially to a regulator — not the vendor.
This is the part of third-party risk that smaller firms consistently underweight. The mental model is usually “we hired a reputable vendor, so security is handled.” In a supply-chain event, the vendor's incident becomes your disclosure, your client-notification obligation, and your reputational hit. The attacker never has to touch your network for your name to end up on a leak site.
There's also a leverage problem the news coverage tends to skip. In a double-extortion case, the data is already gone before encryption ever happens. Paying — or your vendor paying — doesn't un-steal attorney-client material. For a litigation practice, the nightmare isn't downtime; it's privileged strategy or an opposing party's discovery landing in the wrong hands. That risk can't be restored from a backup, which is exactly why a third-party risk assessment has to look at where data lives, not just whether systems can be recovered.
How does INC Ransom actually get in?
Through known, patchable vulnerabilities — not exotic zero-days. Halcyon reports that INC Ransom typically exploits known flaws in Citrix, Fortinet, and SimpleHelp RMM (remote monitoring and management) software to gain initial access and remote code execution. Once inside, INC and the related Silent group use legitimate tools — WinSCP, RClone, and MegaSync — to move laterally and quietly exfiltrate data.
Two things follow from that. First, the entry points are things a firm or its IT vendor is supposed to be patching already; this is a maintenance failure as much as an attacker breakthrough. Second, because the exfiltration uses normal file-transfer utilities, it doesn't look obviously malicious to a tool watching for malware. That's why so many of these intrusions are invisible until the extortion email arrives.
What should a small firm do this week?
Start with the one question this cluster is really asking: do you know every outside provider that can touch your client data? Most small firms can't answer that in 30 seconds, and that inventory gap is the actual exposure here.
Build a real vendor inventory. List every provider that stores, processes, or can remotely access client data — practice management, document management, e-discovery, cloud storage, and your outsourced IT/MSP. You can't assess risk you haven't named.
Ask each critical vendor two direct questions: have you disclosed a breach in the last 12 months, and how is your access to our data segmented from your other clients? Vague answers are an answer.
Confirm where the breach-notification duty sits. Read the data-protection and incident-notification clauses in your vendor contracts now, not during an incident — know who notifies clients and who carries the cost.
Pressure-test your assumption about your IT provider's patching. The Citrix, Fortinet, and SimpleHelp flaws INC uses are known and fixable; ask your provider, in writing, when those systems were last patched.
Make sure your incident response plan covers a vendor-side breach — including the attorney-client privilege and regulatory-notification angles Halcyon specifically flags — not just an attack on your own servers.
None of this requires an enterprise security budget. It requires someone whose job is to think about it. For a 10-to-50-person firm, that's exactly the gap a fractional CISO and vCISO fills — senior security leadership that maps your vendor exposure and your obligations without a full-time hire.
Frequently asked questions
Does this only matter if I'm a law firm?
No. Law firms are the sector in the headline, but the mechanism — a shared vendor breach exposing every customer at once — applies to any small business that outsources data to a common platform. Accounting practices, medical clinics, and small financial firms all share the same exposure to their practice-management and IT vendors.
I'm a 12-person firm. Can I really vet my vendors' security?
You don't need to audit their code. You need a named inventory of who holds your data and a few direct questions per vendor: recent breach history, how your data is segmented from other clients, and what they commit to in their contract. That's a one-afternoon exercise that closes most of the gap, and it's the part smaller firms skip.
If my vendor gets breached, am I the one who has to notify clients?
In most cases, yes. The duty of confidentiality to your clients stays with you regardless of where the data was breached. The exact notification obligations depend on your state and the data involved, but you should assume you are the notifying party — and confirm exactly that in your vendor contracts before an incident, not during one.
Does cyber insurance cover a breach that started at my vendor?
Sometimes, but don't assume it. Coverage for third-party and supply-chain incidents varies widely by policy, and some require specific vendor-management controls to be in place for a claim to pay. Read your policy's third-party and dependent-business-interruption language now, and treat any required controls as a to-do list rather than fine print. Purple Shield is not an insurance advisor; verify specifics with your broker.
INC Ransom's law firm cluster is a reminder that your security perimeter now includes every vendor that touches your client data. If you're not sure which of your providers could put your name on a leak site, that's the conversation to have. Purple Shield Security helps small and mid-market firms map their third-party exposure and build incident response readiness without an enterprise budget — talk to us before a vendor's bad week becomes yours.



