Skip to content
Flash Briefing high Legal & ProfessionalFinance

RansomHub Affiliates Targeting UK Law Firms During Active M&A Mandates

Somewhere between exchange and completion, a UK mid-market law firm gets the call. Not from the client. From the attacker, who has been sitting in the file server for three weeks and wants to talk about payment terms.

RansomHub affiliates have figured out something the rest of the ransomware ecosystem is catching up to: law firms don’t just hold money, they hold leverage. Strike during an active M&A mandate and you’re not just encrypting files; you’re threatening a deal. The client doesn’t know. The counterparty’s lawyers don’t know. And the firm now has 72 hours before regulators need to.

The timing isn’t luck. In multiple confirmed incidents, encryption events tracked closely to known deal calendars, timelines the actor appears to have obtained during reconnaissance or through prior data access. This is deliberate targeting, not opportunism.

Why Law Firms Are Structurally Ideal Targets

Every victim has some version of this calculus: pay the ransom, or absorb the cost of disclosure and recovery. Law firms are unusual because disclosure during an active transaction isn’t just an embarrassment. It can collapse the deal, trigger client termination, and create a reputational wound in a sector where discretion is the product.

A firm managing a significant acquisition has a client whose deal timeline is not their own. The counterparty doesn’t know there’s an incident. Telling the client means telling their client. The cost of paying can look rational against all of that, which is exactly what RansomHub affiliates are counting on.

Regulatory pressure compounds this. The ICO 72-hour clock starts when a fee earner becomes aware of the breach, not when IT confirms the scope. The SRA has its own notification requirements. Firms gambling on containment without disclosure are adding a regulatory liability to an already deteriorating situation.

What Gets Stolen Before Encryption

At the more capable end, these are not smash-and-encrypt operations. Actors are spending weeks in the environment before any ransom note appears.

Transaction data is the crown jewel. Draft agreements, board packs, due diligence reports, and valuation analysis have a brief but extraordinary intelligence value window before a deal closes. Anyone holding those terms before a public announcement has insider-equivalent market intelligence. That has a market beyond the ransom payment itself.

Client personal data is almost universally present. Corporate work generates employment records, individual shareholder information, and director details at volume, all of it in scope for ICO notification obligations.

Privileged communications between solicitor and client create a separate legal dimension when exposed. Post-incident litigation involving those communications has extended the consequences of breaches well beyond the immediate recovery.

Counterparty strategy in contested matters or live litigation is visible in the file. Actors with any relationship to opposing parties have uses for this material that have nothing to do with extortion.

Who’s Getting Hit

Not the Magic Circle. Mid-market firms (roughly £20–200m revenue, regional UK presence, transactional practice focus) make up the bulk of confirmed cases. The logic is consistent: larger firms have made real security investments over the last five years, and RansomHub affiliates are rational actors who evaluate effort against return.

Corporate and real estate practices handling high-value transactions are the primary targets. Litigation practices running significant commercial disputes are close behind: the counterparty intelligence angle makes them worth the effort even outside transaction timing.

What the 72-Hour Clock Actually Means

The ICO notification threshold is triggered by awareness, not by certainty. A fee earner who discovers encrypted files on a matter server has, in that moment, started the clock, regardless of whether the IT team has confirmed anything. Firms that discover a breach on a Friday afternoon and decide to “assess the situation over the weekend” before notifying are making an unlicensed decision about ICO compliance.

The SRA obligation runs parallel. Firms that have been through an incident under-notified and faced regulatory scrutiny afterwards describe the dual exposure as more damaging than the incident itself.

Before the Next Mandate Lands

A few things worth doing now, not during an incident:

Segment transaction data. Live M&A matter files should sit in access-controlled environments separated from general firm infrastructure, with access restricted to the working team and all document access logged. This isn’t complex. Most firms just haven’t done it.

Test whether your backups actually survive an encryption event. RansomHub affiliates specifically target and delete backup infrastructure during reconnaissance. If your backups are online and domain-joined, assume they’re gone. Verify that critical matter data can be recovered from something encryption can’t reach.

Run a tabletop for a mid-deal scenario, not a generic ransomware exercise, but specifically: active deal, client who doesn’t know, 72-hour ICO clock. The decision tree is different and leadership needs to have walked through it before it’s real.

Have an IR retainer in place before you need it. The difference between calling an IR firm you already have a relationship with and cold-calling at 11pm is typically measured in days of response time, and in who controls the narrative.