Lewis Brisbois

Lewis Brisbois Bisgaard & Smith LLP restricted outside access to internal networks after a June 2026 cyberattack and directed remote and hybrid employees to work from offices or use firm-issued computers. The public record does not establish whether attackers successfully entered the network, accessed client or employee data, deployed ransomware, made an extortion demand or caused a client-service outage.
Only external sources publicly identify the event as cyber-related. Credible external sources document the disruption, but the organization does not clearly do so.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
VPN, remote desktop, telework, remote administration, or other remote-access capabilities were unavailable or restricted.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with medium confidence that Lewis Brisbois Bisgaard & Smith LLP experienced malicious cyber activity that prompted the firm to block outside access to internal networks. DysruptionHub’s published report said the firm instructed remote and hybrid employees to work from offices or use firm-issued computers after a cyberattack. Bloomberg Law reported that the firm warned employees on June 5 about criminals calling workers while posing as internal IT personnel and falsifying caller ID, then imposed the remote-access restrictions on June 10.
The public record does not establish whether those social-engineering attempts resulted in successful unauthorized access. Lewis Brisbois did not publicly confirm a network intrusion, malware deployment, data theft or extortion, and did not respond to media requests for comment reflected in the reviewed reporting.
The documented operational effect was disruption to normal remote and hybrid work. Employees who relied on personal-device access to internal systems were directed either to work from an office or take firm-issued computer equipment home. Staff unable to do either were told to request temporary arrangements, and the firm expected to obtain and distribute additional equipment.
The restriction materially changed how some employees could access firm systems, even though no public client-service outage was confirmed. For a nationwide law firm, restricting personal-device access can affect attorney and staff workflows, document access and coordination across offices, but the public evidence does not identify specific legal matters, client services or deadlines that were disrupted.
The incident became public through internal emails reviewed by Bloomberg Law rather than through a formal statement from Lewis Brisbois. The firm’s communications described attempted attacks, remote-access restrictions and employee work requirements, but did not disclose the incident’s technical scope, containment status or investigative findings.
The last direct evidence of operational impact is the June 10 employee directive. Searches through July 26 found no newer report confirming that the temporary equipment shortage, onsite-work requirement or other material disruption continued. With 46 days since that observation, the incident is presumed resolved, but no authoritative restoration notice or investigative all-clear was found. The expected permanent ban on personal-device access is treated as a security-policy change rather than evidence of continuing disruption.
Confidence is medium that malicious cyber activity affected firm operations because internal security warnings and operational restrictions were documented by Bloomberg Law. Confidence is low that attackers successfully infiltrated the network because the reporting explicitly said that point was unclear.
The tactics resembled activity associated with Silent Ransom Group, also known as Luna Moth, Chatty Spider and UNC3753, but neither Lewis Brisbois nor law enforcement attributed this incident to that group. Tactical similarity alone does not support an actor claim for this incident.
The public record does not establish the initial access outcome, affected systems, compromised accounts, malware family, data-access scope, client or employee data exposure, ransom demand, law-enforcement involvement or confirmed restoration date. It also does not establish whether any public-facing or client-facing legal services became unavailable.

DysruptionHub reported that Lewis Brisbois blocked outside access to internal networks and ordered remote and hybrid employees to work from offices or use firm-issued computers. The firm had warned staff about callers impersonating internal IT, while successful intrusion, data exposure, ransomware and client-service impact remained unconfirmed.
The FBI warned that Silent Ransom Group targets U.S. law firms by posing as IT support through calls and phishing emails and seeking access through legitimate remote-access tools. The alert provides tactical context but does not attribute the Lewis Brisbois incident.
Bloomberg Law reported that Lewis Brisbois warned employees on June 5 about criminals impersonating internal IT staff and, on June 10, required remote and hybrid workers to work onsite or take firm-issued equipment home after outside access to internal networks was blocked.
Signed-in members can report an error, update, or missing source.