Blog

Cyber Extortion and Social Engineering: What Law Firms Should Review Now

Aug 18, 2026

Cyber risk is not standing still and neither are the tactics behind it. Recent Oswald and URA cyber content points to a threat environment shaped less by flashy malware and more by deception, impersonation and pressure applied through everyday business workflows. For law firms, that shift matters because operational disruption is only part of the exposure. Sensitive client information, privileged communications and tight deadlines can all raise the stakes when an incident occurs. 

Social Engineering is Doing More of the Heavy Lifting

Many of today’s cyber incidents begin with manipulation, not code. URA’s recent cyber-fraud content highlights how threat actors use tech support scams, phishing, AI-enabled impersonation and other social-engineering tactics to create urgency and prompt employees to act before they verify a request. Oswald’s cyber liability content similarly notes the rise in phishing and social-engineering activity as a meaningful source of loss.  

That matters for law firms because attackers do not always need to “break in” through a sophisticated exploit if they can talk, email or message their way into access. When an employee is pressured to click, reply, approve or install something quickly, the window for error gets wider. Firms that treat cyber risk as only an IT issue may miss the larger operational reality: human behavior is often part of the attack surface.  

Why this Risk Carries Extra Weight for Law Firms

Legal organizations operate in an environment where confidentiality, documentation and timing all matter. A cyber event can affect more than systems. It can disrupt case work, trigger notification obligations, complicate client communications and create reputational strain at the same time. URA’s legal-risk webinar notes that cyber incidents increasingly raise questions around disclosures, accountability and internal escalation, especially as the legal and regulatory landscape becomes more complex.  

That is why prevention and response need to work together. A strong firewall or endpoint tool still matters, but so do internal reporting paths, role clarity and incident response planning. When responsibilities are vague, even a contained event can become harder to manage. 

Actions Law Firms Should Consider Now:

A practical response starts with foundational controls and consistent habits. Based on current URA and Oswald cyber guidance, law firms should consider the following:  

A More Resilient Approach to Cyber Risk

Law firms do not need to predict the next headline to justify action. The current threat environment already supports a more disciplined approach to verification, employee awareness and response planning. At Oswald, we work with organizations on cyber risk assessments, incident response planning, tabletop exercises and broader cyber risk strategy discussions so they can make more informed decisions in a changing environment.