When you’re choosing victims as an attacker it’s important to waste as little time as possible. That means picking targets well, which in turn means:
It’s a simple formula.
The lucrative component can take multiple forms. Recently we’ve seen massive success with ransomware, where people lose what’s important to them (not to the attacker), and they pay money to get it back.
That obviously works well, but law firms have an even more potent mixture of characteristics.
It’s the Payoff Trifecta: ransomware, extortion, and data resale.
I think it’s quite logical to expect law firms to become major targets in coming years. They’re simply too attractive to avoid.