Ransomware gangs are using AI to fake your clients’ legal exposure | Insurance Business
Ransomware gangs are using AI to fake your clients’ legal exposure
Here’s what to tell them
Cyber
Some ransomware groups have started handing victims a new document alongside the ransom note. It’s an AI-generated write-up claiming to spell out exactly what data was taken, which regulators will get involved, and how much trouble is coming. It reads like proper legal advice. It isn’t. Lawyers who work incident response cases say these reports exist to create panic, not to inform anyone, and a client on the receiving end can end up making decisions in the first day that shape the next twelve months, based on information nobody has checked. That’s worth flagging to clients now, before any of them are staring at one of these reports for real.
Why this is happening now
Ransomware pressure has built up in stages over the past few years. First encryption, then leak-site countdowns, then phone calls to executives and staff. Arran Roberts, a partner in the cyber and data risk team at law firm Kennedys, says the latest stage fills a gap attackers had never closed before: actually understanding what’s sitting inside the data they’ve stolen.
“It’s only in the last couple of months that we’ve really started to see these sorts of legal risk analyses coming to the forefront,” Roberts said. His team logged several examples inside a single week recently. So far the tactic seems confined to established, better-resourced groups rather than opportunistic ones. Alexandra O’Hare, a senior associate at the firm, put that down to cost: feeding stolen data into an AI model at scale still takes more time and money than most smaller attackers have to spend.
Worth flagging: this is two lawyers at one firm describing what they’ve personally handled, not a market-wide study. Treat it as an early trend rather than an established one when raising it with clients, rather than something confirmed at scale.
What clients need to understand about these reports
The reports are built to scare, not inform. O’Hare described a case where a threat actor’s report cited regulatory fines based on the worst possible reading of the data, ignoring anything that would have lowered the real risk. She called it a scare tactic rather than genuine legal analysis.
Roberts is blunt about how much weight these documents deserve. Nobody outside the criminal group knows how they were actually produced, whether from a real look at the stolen files or something closer to a generic template run through a model. His approach is the same one incident responders have always taken with claims made by criminals: check it before acting on it. “I always take that with a very healthy pinch of salt,” he said. This is the single most useful thing for a client to hear early: whatever the attacker hands over is not a finding, it’s a pitch.
That doesn’t make the reports completely useless, and it’s worth telling clients that too. O’Hare said they can sometimes point a forensic team toward files worth checking early, or give a business a head start on preparing for regulatory questions. The distinction to draw for a client is between using the report as a lead and treating it as verified fact.
The consequences if a client gets this wrong
This is the part worth walking clients through directly, because the damage isn’t hypothetical.
Money is the most obvious risk. A report that exaggerates how much data was taken can push a client into paying a ransom to stop a leak that was never as serious as claimed, or into expensive containment work for data that was never taken at all. Roberts pointed out that a claim to hold “the crown jewels” of a company is designed to provoke one response, pay up, whether or not that turns out to be the sensible move once the facts are known.
There’s also a regulatory trap that works in both directions, and it’s a genuinely useful thing to walk a client through before an incident, not during one. Under UK GDPR, a notifiable breach needs reporting to the ICO within 72 hours of becoming aware of it, and that clock starts running long before an investigation is finished. A fabricated report can push a client to notify too early, on claims that turn out to be overstated, which can look badly judged once a regulator reviews it later. But a client that dismisses a report too quickly, assuming it’s just a bluff, risks missing a genuine deadline on a breach that turns out to be real. Neither mistake is solved by simply taking the criminal’s version at face value.
Reputational harm is a separate problem worth raising, and it doesn’t depend on the underlying claims being true. Roberts and O’Hare both described AI-driven tactics where damage lands before anyone can verify anything: fabricated internal documents threatened with publication, deepfake voice calls, phishing emails cloned convincingly enough to fool colleagues and customers. A client’s share price or standing with customers can take a hit from a leak that turns out to be entirely invented, purely because the public saw it first.
Then there’s exposure to the people whose data was actually involved, which is a point worth making to any client who assumes stolen data disappearing into a criminal’s server is the end of the story. If AI is helping criminals pull usable personal information out of stolen files that used to be too unstructured for anyone to bother with, it weakens an argument businesses and their advisers have relied on for years, that stolen data is usually too messy to actually exploit. Weaken that argument and a single ransomware incident has a better chance of turning into individual claims or a class action months later, long after the initial headline has faded. It’s also worth a quiet word with clients about how decisions taken under this kind of manufactured pressure hold up in hindsight, including whether directors and officers face scrutiny over the calls they made in the moment.
Finally, flag the cost of simply wasting time. Even a report that changes nothing in the end still eats hours a forensic team needs for the real investigation. That time matters more than it used to: Coveware’s own negotiation data put the ransom payment rate at a record low of around 20% by the end of 2025. Encryption on its own is losing its ability to force a payment, so attackers are leaning harder on tactics like this to make up the difference, and that trend line is a useful thing for brokers to bring into client conversations about why incident response planning matters more than it did two years ago.
The fake legal reports sit alongside other tactics Roberts described from recent cases: phishing emails that used to give themselves away through poor grammar, now polished enough to copy a real colleague’s tone and sign-off, and deepfake voice calls built from a company’s own public-facing video, used to talk IT help desks into resetting credentials. None of this needs to be true to cause damage. It’s a useful frame to give clients directly: their ability to check claims quickly, rather than their speed in reacting to them, is what tends to decide how badly things go. The same shift shows up in which sectors are facing the sharpest rise in AI-driven cyber exposure more broadly, which is worth checking against where a client sits.
What to actually tell clients
Tell them to treat anything handed over by an attacker as a sales pitch, not evidence. It exists to manufacture urgency, and the right response is to pass it to the forensic team as a lead, not to act on it directly.
Tell them to hold off notifying anyone, in either direction, until their own investigation has caught up. The 72-hour clock starts at genuine awareness of a breach, not at the moment a criminal claims one happened, and rushing to notify or dismissing a claim too fast are both mistakes that are hard to reverse once made.
Tell them to keep the ransom decision separate from the fear it’s designed to provoke. If a payment is genuinely on the table, it should rest on what’s been independently checked, not on how frightening the attacker’s report reads.
Tell them to write down the reasoning at the time, whatever gets decided. If a client chooses to disregard part of what a threat actor claims, that decision should be documented as it’s made, because regulators and courts tend to look at the judgement behind a decision, not just how things turned out.
The broader point for any client conversation is that a response plan agreed before an attack, rather than improvised during one, is what separates a bad first day from a bad first year. NCSC guidance on ransomware and ICO guidance on ransomware and data protection are both built around that idea, and both are worth pointing clients toward directly as part of renewal or risk review conversations, rather than waiting until an incident forces the discussion.
