Skip to content

Lewis Brisbois cyberattack restricted remote work

Summary

Lewis Brisbois Bisgaard & Smith LLP restricted outside access to internal networks after a June 2026 cyberattack and directed remote and hybrid employees to work from offices or use firm-issued computers. The public record does not establish whether attackers successfully entered the network, accessed client or employee data, deployed ransomware, made an extortion demand or caused a client-service outage.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Impacted location

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Incident confidence:
Medium
Ransomware:
Unresolved

DD-CIT classification

XC-XDExternal cyber onlyExternal disruption onlyAbout the DD-CIT methodology

Only external sources publicly identify the event as cyber-related. Credible external sources document the disruption, but the organization does not clearly do so.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Remote access disruption

    VPN, remote desktop, telework, remote administration, or other remote-access capabilities were unavailable or restricted.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with medium confidence that Lewis Brisbois Bisgaard & Smith LLP experienced malicious cyber activity that prompted the firm to block outside access to internal networks. DysruptionHub’s published report said the firm instructed remote and hybrid employees to work from offices or use firm-issued computers after a cyberattack. Bloomberg Law reported that the firm warned employees on June 5 about criminals calling workers while posing as internal IT personnel and falsifying caller ID, then imposed the remote-access restrictions on June 10.

The public record does not establish whether those social-engineering attempts resulted in successful unauthorized access. Lewis Brisbois did not publicly confirm a network intrusion, malware deployment, data theft or extortion, and did not respond to media requests for comment reflected in the reviewed reporting.

Operational significance

The documented operational effect was disruption to normal remote and hybrid work. Employees who relied on personal-device access to internal systems were directed either to work from an office or take firm-issued computer equipment home. Staff unable to do either were told to request temporary arrangements, and the firm expected to obtain and distribute additional equipment.

The restriction materially changed how some employees could access firm systems, even though no public client-service outage was confirmed. For a nationwide law firm, restricting personal-device access can affect attorney and staff workflows, document access and coordination across offices, but the public evidence does not identify specific legal matters, client services or deadlines that were disrupted.

Disclosure posture

The incident became public through internal emails reviewed by Bloomberg Law rather than through a formal statement from Lewis Brisbois. The firm’s communications described attempted attacks, remote-access restrictions and employee work requirements, but did not disclose the incident’s technical scope, containment status or investigative findings.

Current status

The last direct evidence of operational impact is the June 10 employee directive. Searches through July 26 found no newer report confirming that the temporary equipment shortage, onsite-work requirement or other material disruption continued. With 46 days since that observation, the incident is presumed resolved, but no authoritative restoration notice or investigative all-clear was found. The expected permanent ban on personal-device access is treated as a security-policy change rather than evidence of continuing disruption.

Confidence and uncertainty

Confidence is medium that malicious cyber activity affected firm operations because internal security warnings and operational restrictions were documented by Bloomberg Law. Confidence is low that attackers successfully infiltrated the network because the reporting explicitly said that point was unclear.

The tactics resembled activity associated with Silent Ransom Group, also known as Luna Moth, Chatty Spider and UNC3753, but neither Lewis Brisbois nor law enforcement attributed this incident to that group. Tactical similarity alone does not support an actor claim for this incident.

Analytic gaps

The public record does not establish the initial access outcome, affected systems, compromised accounts, malware family, data-access scope, client or employee data exposure, ransom demand, law-enforcement involvement or confirmed restoration date. It also does not establish whether any public-facing or client-facing legal services became unavailable.

Organizations involved

Impacted location

Sources

Lewis Brisbois limits remote work after cyberattack
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that Lewis Brisbois blocked outside access to internal networks and ordered remote and hybrid employees to work from offices or use firm-issued computers. The firm had warned staff about callers impersonating internal IT, while successful intrusion, data exposure, ransomware and client-service impact remained unconfirmed.

Lewis Brisbois Calls Remote Staff to Offices After Cyberattack
Bloomberg LawBy Justin HenryPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Bloomberg Law reported that Lewis Brisbois warned employees on June 5 about criminals impersonating internal IT staff and, on June 10, required remote and hybrid workers to work onsite or take firm-issued equipment home after outside access to internal networks was blocked.

Silent Ransom Group Impersonating IT Personnel through Social Engineering
Federal Bureau of InvestigationPublished: Retrieved:
  • Type: Research Threat Intelligence
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

The FBI warned that Silent Ransom Group targets U.S. law firms by posing as IT support through calls and phishing emails and seeking access through legitimate remote-access tools. The alert provides tactical context but does not attribute the Lewis Brisbois incident.