Ransomware Gang Claims Attack on Global Law Firm Baker McKenzie
A criminal group called Silentransomgroup has listed Baker McKenzie on its dark-web extortion site. The firm has not confirmed any incident, and the claim cannot be independently verified.

Key points
- Threat Vectr's own leak-site tracking has recorded 91 claimed victims for Silentransomgroup since September 3, 2025, placing Baker McKenzie among the most recent.
- The listing appeared on October 8, 2026, monitored by the tracking service Ransomware.live.
- Baker McKenzie, a global law firm founded in 1949 and headquartered in Chicago, has not publicly confirmed any breach.
- Silentransomgroup has claimed 18 victims in the past 30 days alone, with business services firms targeted most often.
- The claim is unverified; leak-site listings are written by criminals to pressure companies and are sometimes exaggerated or false.
A criminal ransomware group, meaning a gang that breaks into organisations, steals data, and threatens to publish it unless paid, has listed Baker McKenzie on its dark-web extortion site. The listing appeared on October 8, 2026, first observed by the monitoring service Ransomware.live.
Baker McKenzie is one of the world's largest law firms, with offices across North America, Europe, Asia-Pacific, Latin America, and the Middle East. The firm has not made any public statement about the claim, and Threat Vectr could not independently verify it at the time of publication.
Who is Silentransomgroup?
They are a relatively active criminal operation. Threat Vectr's own leak-site tracking has recorded 91 organisations claimed as victims since September 3, 2025, with 18 of those claims posted in the past 30 days. Business services firms appear most often in their listings.
Ransomware groups run extortion sites on the dark web to pressure targets into paying. A listing does not prove a breach happened. The criminals' own description of Baker McKenzie reads as generic background information about the firm, which is common in AI-generated filler posts designed to look credible while saying almost nothing specific.
That detail matters. It doesn't tell us what, if anything, was taken.
Should clients or staff be worried right now?
Not yet, and certainly not in a way that requires immediate action. Unconfirmed claims like this one circulate regularly, and many turn out to be exaggerated or wrong.
That said, a law firm holds genuinely sensitive material: contracts, merger details, dispute records, personal data for corporate clients and individuals. If a breach were eventually confirmed, the consequences could extend well beyond the firm itself.
While the claim remains unverified, a few practical steps are worth taking:
- Watch for phishing emails, where criminals send fake messages pretending to be from Baker McKenzie or a related party, especially ones asking you to click a link or verify account details.
- Be sceptical of any call claiming to offer "breach compensation" or asking you to confirm personal information. That is a scam pattern that follows breach headlines.
- If you reuse a password across accounts and Baker McKenzie is one of them, change it on the other accounts now. Password reuse is how one incident becomes several.
None of that requires panic. It requires the same low-level alertness that any credible claim against an organisation holding sensitive data should prompt.
Baker McKenzie has not publicly confirmed any incident. This story will be updated if the firm responds or if additional verified information becomes available.



