Why Ransomware Targets Law Firms, Contractors, and Engineering Practices

The ransomware victim profile is a census of professional small business
Ask who ransomware hits and most people picture hospitals and pipelines. The reporting data tells a more ordinary story. Among ransomware complaints from outside critical infrastructure, the businesses reporting most often were law firms and legal services (18 percent), contractors (17 percent), engineering and architectural firms (10 percent), and consultancies (7 percent), according to intSignal Research's review of FBI data.
That is a near-perfect description of California's professional small-business economy: firms that hold sensitive client data, depend completely on operational continuity, and rarely maintain internal security staff. They are attractive precisely because they combine valuable data with limited defenses.
The measurement paradox: small reported losses, large real impact
Ransomware presents a genuine measurement problem. The FBI's Internet Crime Complaint Center logged 3,611 ransomware complaints nationally in 2025 (up 14 percent) with just $32.3 million in reported losses — a figure that looks almost trivial next to California's multibillion-dollar fraud totals.
It is misleading, and the FBI says so explicitly: that number excludes lost business, downtime, wages, files, equipment, and third-party remediation, and reflects only what victims choose to report. The incident-based view is far starker. In Verizon's 2026 Data Breach Investigations Report, ransomware appeared in 48 percent of confirmed breaches, up from 44 percent. For a small firm, the real cost of ransomware is rarely the ransom line item; it is the weeks of downtime, the reconstruction, and the client relationships that do not survive the outage.
There is one encouraging number in the incident data: 69 percent of ransomware victims declined to pay, and the median payment fell to $139,875. Refusal, though, is only possible when restoration is — which points directly at what actually protects a business.
What actually stops it
The FBI's first-line ransomware recommendations, reproduced in the report's evidence, are not exotic:
- Immutable, tested backups. Encrypted, offline, immutable backups covering the full data estate are what let the 69 percent say no. A backup you have never restored from is a hope, not a control.
- Phishing-resistant MFA and least privilege. Credential abuse appears in 39 percent of breach chains; MFA, eliminating default credentials, and least privilege close the most common front doors.
- Patch internet-facing systems fast. Vulnerability exploitation is now the leading initial-access vector in the DBIR at 31 percent of breaches, driven by attacks on edge devices, VPNs, and remote access. Known-exploited vulnerabilities need patching on a days-not-months cadence.
- Segmentation and detection of lateral movement. Network segmentation to contain spread, plus managed detection and response to catch an intruder moving before encryption starts, is the difference between an incident and a catastrophe.
For a firm without internal security staff — most of the profile above — this is exactly the work a managed SOC exists to carry. The variants change every year (the FBI identified 63 new ones in 2025, with Akira, Qilin, and Play among the most reported); the controls that defeat them do not. See our companion piece on ransomware controls that work for the operational detail.
The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research, where each is traced to its source, method, and limitations.


