Cyber threat trends and implications for professional service firms
Cyber threats have continued to evolve in both speed and scale
The increased activity and fragmentation of threat actor groups and their attack strategies as well as leverage of AI in the development and delivery have made cyber attacks highly automated, personalized, and harder for humans to spot.
Recent reports indicate that organizations are approximately increasingly resistant to paying ransom demands as they strengthen recovery capability, face regulatory scrutiny, and recognize that payment offers no guarantee that systems will be restored or data secured. According to reports, the median and average ransom payments, when made and publicly disclosed, are declining with 63% to 69% of ransomware victims now rejecting extortion demands. At the same time, threat actors are being targeted by law-enforcement who have achieved notable successes in taking down the operations of several major ransomware operators. While these efforts have disrupted some threat actors, cyber-attacks continue to increase as cyber criminals regroup and change their tactics.
Professional service firms continue to be prime targets due to the volume of highly sensitive data held and the frequency of high-value financial transactions they handle. Social engineering attacks, such as phishing, impersonation, and business email compromise, are growing increasingly sophisticated, tricking employees into providing access to sensitive information or the diversion of the firm’s or client funds. At the same time, class action lawsuits after cyber breaches involving regulated Personally Identifiable Information (PII) and Portable Health Information (PHI) held in professional service firm systems are increasing in frequency and cost.
Ransomware still a common tactic
Even with the decrease in payments, ransomware attacks still make up over 18% of cyber attacks according to recent claims reports. Threat actors continuously regroup, reorganize and adopt new operational tactics:
- High-volume, low-demand campaigns targeting SMEs: Groups like Akira and Qilin appear to be deploying a “shotgun” approach, using phishing (often leveraging AI and deepfakes) and exploiting remote access vulnerabilities to hit hundreds of small-to-mid-sized firms with modest demands (often under $200K). This strategy maximizes success rates against less resilient victims.
- Sophisticated, high-value intrusions against larger enterprises: Actors such as Cl0p and RansomHub invest time in reconnaissance, exploiting zero-day vulnerabilities, cloud misconfigurations and attacks against vendors and / or service providers. These attacks often involve multi-layered strategies including data theft extortion, encryption, and denial of service, aimed at extracting more significant and often multimillion-dollar payouts. Silent Ransom Group (aka Luna Moth) specializes in social engineering attacks for data theft and extortion, mainly targeting law firms .
Tactics, techniques, and procedures (TTPs) of advanced groups
Professional service firms have invested heavily in improvements to cybersecurity over the last 10 years and the ransomware operators that target larger and more sophisticated organizations are responding to these improvements with changes in their attack methodologies:
- Initial Access: Social engineering of employees to gain access, exploiting vulnerable credentials (weak & default passwords), attacking known vulnerabilities in VPNs, Software-as-a-Service (SaaS) platforms and cloud implementations.
- Execution: “Living off the land” (LOTL) attack, utilizing existing network administration programs to evade detection and facilitate lateral movement, disabling defenses and attacking backups.
- Extortion: Encrypting data (particularly backups), exfiltrating data, reaching out to clients whose data they have stolen, harassing employees, and launching DDoS attacks are increasingly common strategies.
The AI factor: Phishing, vishing, and deepfakes
Threat actors quickly recognized the power of Artificial Intelligence (AI) and as its capabilities have evolved, they are increasingly leveraging it as a force multiplier for cybercrime :
- Phishing: AI-generated emails can achieve a materially higher click-through rate, adopting appropriate writing style, tone and context, which they will leverage for ongoing correspondence. This can be particularly powerful when used in combination with business email compromise where the attacker has access to the genuine email address of an employee, client or vendor.
- Vishing and voice deepfakes: Real-time voice-cloning enables attackers to impersonate executives during live calls, which can be used to authorize fraudulent transfers. Multimillion-dollar losses have been recorded from deepfake vishing.
- Video deepfakes: Synthetic video is used for high-level executive impersonation and fraud, eroding trust in virtual communications. In a recent incident, a deepfake video-conference call (involving multiple AI avatars), was used to convince a corporate CFO to transfer over $25m to a fraudulent account.
MIT research indicates that up to 80% of ransomware attacks now incorporate AI, from malware generation to social engineering.
Business email compromise (BEC) and social engineering fraud (SEF)
One of the changes in threat actor tactics, as ransomware becomes harder to monetize, is the adoption of business email compromise and social engineering fraud. Professional service firms are an attractive target for this strategy because of the frequency of substantial funds transfers (payments from clients, payments to vendors, management of funds for disbursement etc). According to IBM’s Cost of a Data Breach Report 2025 (based on a survey of 600 entities across a representative sample of industries / sizes), BEC remains the second most expensive breach type, averaging $4.89M per incident.
- Volume: BEC attacks rose substantially in early 2025, often exploiting trusted platforms. Data from the Howden Cyber Report 2025 indicates that this is the most frequent type of cyber-attack.
- AI augmentation: Once a threat actor has gained access to the victim’s email, they can use generative AI to hijack email threads and craft flawless messages, making detection harder.
- Tactics: Role-based impersonation (HR, finance, IT Helpdesk) is being used, leveraging urgency and familiarity to bypass controls. These tactics were successfully used recently in some of the largest incidents including attacks on resort casinos, hotels, major manufacturers and educational institutions. The Silent Ransom Group has even been known to deploy operatives impersonating IT personnel on-site, where they use thumb-drives to download data directly from victims’ computers.
Strategic implications for professional service firms
Professional service firms continue to be an attractive target for hackers:
- Concentration of sensitive / confidential client data
- Frequent high-value financial transactions
- Trust-based workflows involving third parties such as other firms, vendors etc.
- Reliance on third-party vendors and cloud platforms
These exposures create valuable opportunities for hackers looking for a financial payout for their activities. Unfortunately, such attacks also put professional service firms in a position of potential legal liability for having failed to protect the confidentiality of client data, or for inadvertently paying client funds into a fraudulent account. Compromise of regulated data (PII and PHI) held by professional service firms has also led to class action lawsuits that have resulted in multimillion-dollar settlements. Recommended strategies to address these types of cyberattack include:
- Implement zero-trust architecture and continuous behavioral monitoring
- Deploy AI-driven phishing detection and voice verification protocols
- Strengthen incident response and backup strategies
- Training, training and more training for all staff
- Conduct regular social engineering drills and insider risk assessments
- Engage in cyber insurance and legal readiness planning
What professional services firms should discuss with their broker
Cyber risks continue to grow as threat actors use AI to make attacks more effective, ransomware groups adopt new approaches, breach-related litigation and class action lawsuits continue to rise, and vulnerabilities in third-party platforms create new avenues for loss.
While cyber insurance is designed to respond to the impacts arising from these types of attack, the applicable coverage may be subject to restrictions and / or exclusions that limit the ability of the policy to cover the full extent of the loss. These would include typically low sub-limits in the case of social engineering fraud, differential coverage depending on whether specific controls or protocols were followed, and some cyber policies may even have an exclusion for any liability arising from the provision of professional services.
It is not unusual in a substantial ransomware event for the limits of the cyber policy to be fully eroded by the immediate cost of responding to the event (breach counsel, remediating systems, issuing notifications, loss of revenue, paying a ransom etc.) long before any allegations of liability arise. These limitations mean that it is critically important a) to understand the scope and limitations of the cyber, lawyer’s professional liability and commercial crime insurance policies and b) to ensure that the interface between policies is structured in such a way as to maximize coverage in situations where a cyber event may impact more than one policy.
Professional service firms must recognize that resilience is the cornerstone of survival. For professional services firms, the issue is no longer whether a breach will happen, it is a matter of when. Understanding what coverages are available and how available insurance policies will respond to each scenario is critically important. Investing in insurance coverage and engaging with an experienced broker who can deliver a cyber insurance program designed specifically to respond as expected in the event of an incident is a key part of your resilience strategy.
Our experienced risk advisory team can help professional services firms identify potential coverage gaps, assess emerging exposures, and ensure insurance programs keep pace with evolving business practices.