In January 2024, a 12-lawyer litigation firm in Ottawa was hit by a ransomware attack that disrupted the firm for nearly a month. According to the LAWPRO case study, the attackers had already been inside MBC Law’s network for weeks before anyone realized there was a problem. In exchange for not publishing or releasing the stolen information, they demanded a ransom after providing sensitive listings as proof they had stolen the data.
For about two weeks, the firm struggled to keep operations moving while responding to the attack. It took roughly four weeks to return to normal operations.
There are endless articles about ransomware, but it’s rare to get a walkthrough of what happened to an actual Canadian law firm. This case study offers a rare look at what a ransomware attack looked like inside a small Canadian law firm.
What Happened at MBC Law
The case study provides one of the few detailed public timelines of a ransomware incident affecting a Canadian law firm. Most companies assume the attack begins when the ransom demand arrives, but it was the final stage of an attack that had started weeks before while going undetected.
The MBC Ransomware Attack Timeline
Here’s a look at why MBC Law’s recovery took weeks instead of days.
| DATE | WHAT HAPPENED |
| December 2023 | Repeated brute-force attacks eventually worked. The attackers got into MBC Law’s network and spent the next several weeks copying data before anyone realized they were there. |
| January 17, 2024 | MBC Law’s IT contractor detected suspicious activity and immediately contacted an external cybersecurity incident response firm. The firm also disconnected from the internet to keep the damage from spreading. |
| January 19-21, 2024 | Investigators found malicious software on many workstations, concluding that confidential information was likely copied before anyone at the firm knew they had been breached. |
| January 22, 2024 | The attackers contacted MBC Law with a ransom demand, supplying file listings as proof they had stolen data. |
| January 23, 2024 | A second file listing arrived, later found to contain files from another victim outside the firm, indicating the attackers were running multiple attacks simultaneously. |
| January 30, 2024 | The attackers escalated pressure by emailing clients, opposing counsel, and other lawyers directly. |
| Recovery | All workstations were wiped and rebuilt from scratch. The firm’s server was rebuilt. Severe disruption lasted approximately two weeks. Full functionality was not restored for approximately four weeks. |
Encrypting the firm’s files was only part of the attack. The attackers also exploited the fact that law firms depend on confidentiality, trust, and professionalism.
Why the Firm Didn’t Pay
MBC Law ultimately didn’t pay the ransom. They launched an overnight, off-site backup and restored everything without paying. The backup helped avoid losing their data altogether, but didn’t remove what was already stolen. If they didn’t have a backup in place, they may have been forced to pay the ransom or lose their files.
The firm’s recovery is just as important as the attack itself. MBC Law didn’t pay the ransom because it didn’t have to. The firm already had an off-site backup that provided a working copy of its data before the attack ever happened.
When ransomware encrypts your files, they can’t just be hacked and unlocked. Without a usable backup in place, a law firm usually has to decide between paying up the ransom or losing access to its data altogether.
What Recovery Cost MBC Law
LAWPRO estimates rebuilding a firm’s IT systems after an incident like MBC Law’s could cost $50,000 to $150,000 or more for a firm of this size. The estimate includes:
- Forensic investigators
- Rebuilding servers
- Reinstalling operating systems
- Restoring data
- Replacing hardware where necessary
- Technical labour required to get everything up and running safely
Recovery also isn’t complete just because the systems are restored. The case study estimates a firm may need another $30,000 to $60,000 to upgrade security controls to stay safe from future attacks. When a company is in recovery, they usually need stronger firewalls, multi-factor authentication, endpoint monitoring, security software, password management, and employee awareness training.
Those figures only cover the technology costs. MBC Law also experienced roughly two weeks of severe, ongoing disruption and didn’t return to full functionality for approximately four weeks.
Lawyers couldn’t work normally and staff were forced to spend their time responding to the incident instead of serving clients. It also complicated court appearances because they didn’t have access to their electronic files. At one time during the interruption, MBC’s lawyers were forced to attend court using only their phones and relied on opposing counsel to share documents because they couldn’t access their own systems.
Every day of downtime for a legal firm is lost productivity, interrupted billable work, delayed client communication, postponed deadlines, overtime hours, and the possibility of losing future business once a client’s confidence is damaged.
| RECOVERING AFTER AN ATTACK | PREPARING BEFORE AN ATTACK |
| $50,000–$150,000+ to rebuild IT systems* | Ongoing security monitoring |
| $30,000–$60,000 in post-incident security upgrades* | Tested off-site backups |
| Approximately 2 weeks of severe operational disruption | Disaster recovery planning |
| Approximately 4 weeks to full operational recovery | Regular backup testing |
| Lost billable hours and interrupted client service | Multi-factor authentication and employee security training |
*LAWPRO estimates for a firm the size of MBC Law
What Made MBC Law Vulnerable, and What Made Its Recovery Possible
The MBC Law ransomware case is valuable without assigning blame. LAWPRO presents it as a learning opportunity instead of a cautionary tale. The public also doesn’t have all of the technical details. The published case study only says that attackers gained access after brute-force attacks, but it doesn’t identify the specific account, password, remote access system, or security weakness involved.
The case shows how a successful compromise can cause a domino effect of an entire firm or business. Once attackers gained access, they moved through the network, stole files, and were ready to extort the law firm without the breach even being detected. That’s why we always tell our clients at Intraworks that a layered security approach is better than relying on a single defence.
MBC Law had an overnight off-site backup that could be restored. That backup allowed the firm to rebuild its systems without paying the attackers for a decryption key or risking permanent loss of its files. Recovery still required weeks of work, but the off-site backup and disaster recovery plan gave the firm control over the process instead of leaving that decision in the attacker’s hands.
MBC Law’s backup kept the firm from losing access to its own files, but there are still potential risks. Once data is copied outside of your network, restoring your own files doesn’t erase the attacker’s copies. That’s why ransomware planning needs to address the recovery process and the possibility of stolen information.
What BC Law Firms Can Learn and Are Obligated to Do
Law firms face ongoing responsibilities because of how much confidential client information they handle. In BC, LSBC Rules 10-3 and 10-4 require lawyers to take reasonable security measures to protect their records and to immediately notify the Law Society in writing upon loss of custody or control of those records. Since March 2024, BC lawyers also carry an updated duty of technological competence, which includes understanding how the technology they use protects client information and what the risks are if it fails.
The Federation of Law Societies of Canada also encourages lawyers to understand the technology they use and how to protect client information. The cost of not doing so is not just reputational. It is regulatory.
Cyber Insurance Will Not Save You If the Controls Were Not in Place
Cyber insurance is increasingly a requirement for law firms, but coverage is not guaranteed when a claim is filed. Canadian carriers now require verifiable multi-factor authentication, endpoint detection and response, tested backups, patch management, and incident response plans as a condition of coverage. When those controls are missing, claims are denied. In July 2025, the City of Hamilton, Ontario, had a claim of roughly $5 million denied after a ransomware attack because the insurer found MFA was not in place — the attackers had demanded approximately $18.5 million. A BC law firm in 2024 had no coverage at all because it had not fixed network vulnerabilities identified by its insurer two years earlier. The firm handled a ransomware demand of over US$150,000 entirely on its own.
Before your next renewal, confirm that the controls you have attested to are actually in place. The gap between what firms say they have and what they have documented is where claims get denied.
The checklist below includes a question about where your data lives. If the honest answer is an American-owned cloud platform, that conversation is overdue. Data stored in Canada by a US-owned provider can still be accessed under US law regardless of where it is physically held. It is one of the reasons Intraworks operates its own Class A data centre in Nanaimo — so that client data stays on Canadian soil under Canadian law, not subject to the legal reach of a foreign jurisdiction.
A managing partner or firm administrator should be able to answer these questions:
- Do we have an off-site backup?
- When was our off-site backup last tested?
- How long would it take to restore all of our workstations and systems?
- Do we already use multi-factor authentication on critical systems?
- Who would we call if we found suspicious activity tomorrow morning?
- Do our lawyers and staff know how to recognize phishing attempts?
- Who does our staff report suspicious emails to?
If you are not sure how to answer any of those questions, it is time to address them before a ransomware attack forces the conversation.
Frequently Asked Questions About Ransomware
Does a small law firm need to worry about ransomware attacks?
Yes, even small law firms can be targets of ransomware attacks. MBC Law only had 12 lawyers. Smaller practices often have fewer cybersecurity resources, making them more appealing to cybercriminals.
How much does a ransomware attack usually cost a small law firm?
LAWPRO estimates a firm the size of MBC Law might spend $50,000 to $150,000 or more rebuilding its IT systems, plus another $30,000 to $60,000 on post-incident security upgrades. Those figures do not include lost billable hours, disrupted client work, or the time it takes to get the firm back to full functionality.
Do I have to report a data breach at my law firm in BC?
LSBC Rules 10-3 and 10-4 require lawyers to take reasonable security measures and to immediately notify the Law Society upon loss of custody or control of client records. A significant breach could also trigger obligations under BC PIPA and potentially PIPEDA. Firms should obtain their own legal guidance as part of an incident response plan before a breach occurs, not after.
What cybersecurity measures should a small law firm have in place to prevent ransomware?
A tested off-site backup is the single most important factor in recovering without paying a ransom. Although a backup alone will not prevent an attack, it can increase your ability to recover without paying up a ransom. Combine a backup with multi-factor authentication, security monitoring, employee training, and a documented incident response plan.
Should a firm ever pay a cybercriminal a ransom?
Whether or not you pay a ransom depends on the circumstances and the different legal, operational, and ethical considerations. Canadian authorities usually discourage paying because it does not guarantee the data will be returned or deleted and encourages criminals to do it again.
What is the duty of technological competence for BC lawyers?
The Law Society of BC requires lawyers to develop an understanding of the technology they use and how to protect client information. That includes knowing how your firm’s data is stored, who can access it, and what your incident response plan looks like if something goes wrong.
Does Canadian data residency protect my law firm’s client files from US law?
Not necessarily. Storing data on Canadian servers does not automatically mean it is protected under Canadian law if your provider is a US-based company. US laws including the CLOUD Act can still apply to data held by US-owned providers regardless of where it is physically stored. Choosing a Canadian-owned provider with a Canadian data centre is the only way to ensure true data sovereignty.
The Question Every Law Firm Should Ask
If ransomware disrupted your firm tomorrow, how quickly could you recover?
The MBC Law case shows how ransomware isn’t limited to oversized, multinational companies or government agencies. A single incident can disrupt client service, interrupt billable work, and require weeks of recovery, even for a relatively small law firm.
If you could not confidently answer the questions above, that is where to start. We work with law firms across Vancouver Island to make sure those answers are clear before something forces them. Book a free IT and security assessment and we will walk through your backup, access controls, and incident response plan together.
Book your free assessment or call us at 866-729-8624.
Future-proof Your Business with Our IT Company
Book a discovery call with Intraworks today and let us show you how our IT company can take your business to new heights.