Dental clinics are not the only professional firms getting squeezed. In early September 2026, Greenberg Traurig — one of the country's large law practices — disclosed a cybersecurity incident tied to a ransomware group that has spent late summer hunting U.S. law firms.
According to reporting on the firm's Vermont Attorney General notice (filed around September 8), a group tracked as SilentRansomGroup had already listed the firm on a leak site around September 2. The confirmed filing describes limited data posted and Social Security number exposure for at least some residents in that notice. Separately, security reporting has tied the same actor family to a string of law-firm claims through August and September — including other well-known practices. Those other listings are not all equally confirmed; treat them as a pattern signal, not a scorecard of proven breaches.
If you run a smaller firm in Rome, Northwest Georgia, or Metro Atlanta — law, accounting, insurance, or any office that holds client files and wire instructions — the lesson is not "big law got hit." It is that professional services data is portable, valuable, and often sitting behind the same weak spots: email, remote access, and shared file stores.
Why attackers like professional firms
- Client files travel — Matter folders, discovery sets, tax workpapers, and trust-account details are high-leverage for extortion even when operations stay up.
- Email is the front door — Callback phishing, voicemail lures, and MFA fatigue still work on busy professionals who live in Outlook.
- Deadlines beat lock-downs — Filing dates and closings create the same "we'll secure it Monday" pressure shops and clinics know well.
- Vendor and guest access — Co-counsel, e-discovery hosts, bookkeepers, and IT vendors widen the perimeter the same way billing BAs do in healthcare.
What to tighten this month
- MFA everywhere that reaches mail or files — Microsoft 365, VPN, document portals, and admin accounts. No shared "firm" passwords.
- Separate privileged accounts — Daily work identities should not be global admins. Kill access the day someone leaves.
- Lock down external sharing — Named guests over "anyone with the link" for active matters. Revoke when the engagement ends.
- Backups you have restored — Independent copies of mail and file stores; time a real restore of one matter library or mailbox.
- Wire and payment dual-control — Out-of-band verify any change to banking instructions. Ransomware weeks often overlap with BEC attempts.
- Short incident contacts list — Owner, IT partner, cyber insurer, and counsel. Know who calls whom before the first ransom note.
Takeaway for IT decision-makers
If your firm's value is client trust and deadlines, build security around email, identity, and restore — not around hoping you are too small to matter.
SilentRansomGroup's law-firm focus is a reminder that professional SMBs share the same attack economics as larger practices: sensitive files, rushed humans, and partners who need temporary access. Rome and Northwest Georgia firms do not need a Fortune 500 SOC. They need MFA that sticks, sharing that expires, backups that restore, and a one-page plan for the morning something looks wrong.
Brotherly Technology works with professional SMBs across Rome and Northwest Georgia on Microsoft 365 hardening, backups, vendor access hygiene, and practical ransomware readiness — including law, accounting, and other client-file businesses, not only healthcare.
Sources: public reporting on Greenberg Traurig's September 2026 Vermont AG-related disclosure and SilentRansomGroup law-firm targeting in Aug–Sep 2026. Pattern references to other firms are from open reporting and may include unverified leak-site claims. Not legal advice.