DATABREACHES .net has reported that Silent Ransom Group (SRG) allegedly breached Hogan Lovells’ legacy infrastructure on 12 August 2026, remaining in the network for about 24 hours and taking data from several machines. The report says the infrastructure had separate firewalls, file systems and security controls, but does not identify the tools used. SRG contacted the firm on 25 August, and negotiations followed.
Hogan Lovells reportedly offered up to $5.34m, while SRG demanded at least $20m and ended talks on 21 September. The firm did not respond to DataBreaches’ requests for comment, so the breach remains unconfirmed, although the publication said its inspection found no indication that the data had been fabricated.
According to SRG, the first tranche contained more than 50GB of data, including about 500 passports, driving licences and Social Security numbers. DataBreaches said it found more than 930 files marked “Privileged and Confidential”, along with medical records, tax forms containing full Social Security numbers, and other sensitive documents.
On 23 September, SRG allegedly regained access using the same method and took additional data, including internal documents and emails, valid passports, credit and personal information, and detailed financial records. SRG said it would publish the second tranche and warned that it would continue attacking the firm until its demands were met. The report notes that SRG has previously carried out repeat attacks, but does not independently confirm either incident.