How We Saved a Law Firm From a $2M Ransomware Attack
Geek Heros War Stories
The Call That Changes Everything
It was 2:14 AM on a Tuesday when my phone rang. The caller ID showed the managing partner of a mid-size Chicago law firm — 35 attorneys, roughly 80 total staff. His voice was shaking.
"Patryk, everything is locked. Every computer. There's a message on every screen demanding two million dollars in Bitcoin. What do we do?"
I was already pulling on clothes before he finished the sentence. This is the call every MSP owner prepares for but hopes never comes. For us, preparation was about to pay off in ways that saved this firm from catastrophe.
How the Attack Happened
The forensic investigation later revealed the full timeline. Three days before the attack, a paralegal received an email that appeared to come from the Cook County Circuit Court e-filing system. The email claimed there was an issue with a recent filing and included a link to "verify the document." The email was sophisticated — correct logos, proper formatting, even a case number that matched a real pending case.
The paralegal clicked the link and entered her credentials on a convincing fake login page. Within minutes, the attackers had her email password. Because the firm had not yet implemented MFA on all accounts (it was scheduled for the following month — a painful irony), the attackers logged directly into her email, harvested additional credentials, and began moving laterally through the network.
For three days, they quietly mapped the firm's infrastructure, identified backup systems, and planted ransomware payloads on every accessible machine. At 2:00 AM on Tuesday, they detonated everything simultaneously.
The Ransom Demand
Every workstation and server displayed the same message: the firm's files were encrypted with military-grade encryption, and the decryption key would cost $2,000,000 in Bitcoin, payable within 72 hours. After that, the price would double. After seven days, the attackers threatened to publish client files on the dark web.
The managing partner's first instinct — understandably — was to consider paying. Two million dollars is a staggering sum, but the firm's client files, billing records, case documents, and email archives represented decades of work and hundreds of active matters. The thought of losing it all, or having client data published, was terrifying.
Why We Didn't Pay
Here's where preparation made all the difference. Six months earlier, we had implemented a comprehensive BCDR (Business Continuity and Disaster Recovery) plan for this firm. This wasn't just "we have backups somewhere." This was a tested, documented, regularly verified recovery system built on three principles:
The 3-2-1-1-0 Backup Rule: - 3 copies of all data - 2 different storage media types - 1 copy stored offsite - 1 copy that is immutable (cannot be modified or deleted by anyone, including administrators) - 0 errors in backup verification testing
The immutable backup was the key. Ransomware operators know that their attack is worthless if the victim can simply restore from backups. So modern ransomware specifically targets backup systems — deleting snapshots, encrypting backup repositories, and destroying recovery points. Our immutable backups were stored in an air-gapped, append-only cloud repository that even we couldn't delete. The attackers couldn't touch them.
The Recovery — 4 Hours to Full Operations
At 2:30 AM, I was at the firm's office with two of our senior engineers. Here's what happened next:
Hour 1 (2:30 - 3:30 AM): We isolated the network — killed internet connectivity, shut down the firewall's WAN interface, and segmented the internal network to prevent any further lateral movement. We verified that our immutable backups were intact and uncompromised. They were. Every single one.
Hour 2 (3:30 - 4:30 AM): We began spinning up the firm's critical systems from backup images. Practice management system first — attorneys had court appearances starting at 9:00 AM and needed access to case files. Email server second. Document management third.
Hour 3 (4:30 - 5:30 AM): Critical systems were online and verified. We began restoring workstations in priority order — partners first, then associates with morning court dates, then support staff.
Hour 4 (5:30 - 6:30 AM): All critical systems were operational. By the time the first attorneys arrived at 7:00 AM, they could access their files, email, and practice management system. Some non-critical systems took another few hours to fully restore, but the firm was functional.
Total ransom paid: $0. Total data lost: approximately 4 hours of work (the gap between the last backup and the attack). Total client files exposed: zero.
The Aftermath and Lessons Learned
In the weeks following the attack, we conducted a thorough post-incident review and implemented additional safeguards:
MFA was deployed immediately on every account — no more "we'll do it next month." This single control would have prevented the initial compromise entirely.
Security awareness training was intensified, with monthly phishing simulations. The paralegal who clicked the initial link wasn't negligent — the phishing email was genuinely sophisticated. But regular training teaches staff to verify unusual requests through a second channel before clicking.
EDR (Endpoint Detection and Response) was deployed on every endpoint. Our monitoring detected the attackers' lateral movement in retrospect — but the alerts had been classified as low priority by the previous antivirus system. A proper EDR solution with 24/7 SOC monitoring would have caught the intrusion during those three days of reconnaissance.
The firm's cyber insurance carrier was notified, and because we had documented the entire incident and recovery, the claim process was straightforward. The carrier covered the incident response costs.
Why Testing Your Backups Monthly Is Non-Negotiable
Here's the detail that most firms miss: having backups is not the same as having working backups. We test full recovery from our clients' backups every single month. Not a spot check. A full restoration to verify that every system, every database, and every file can be recovered within the defined recovery time objective.
The reason is simple: we've seen firms who thought they had backups discover during an actual emergency that their backup software had been failing silently for months, their backup repository was corrupted, or their recovery process took 72 hours instead of the 4 hours they expected. Testing eliminates these surprises.
The Bottom Line
This firm survived a $2M ransomware attack because of three things: immutable backups that the attackers couldn't destroy, a tested recovery plan that we'd practiced, and an incident response team that knew exactly what to do at 2:00 AM.
The total cost of the BCDR solution that saved them? Less than $2,000 per month. The cost of the ransomware attack without it? Potentially the firm itself.
Don't wait for your 2AM call. [Get a free site audit](#assessment) and find out if your backups would survive a ransomware attack.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.