New ransomware documents are arriving alongside ransom notes: AI-generated legal analyses that claim to detail exactly what data was stolen, which regulators will get involved, and how much the penalty will be. These reports read like proper legal advice but aren't. Lawyers who handle incident response say the documents are designed to create panic, not inform anyone. For insurance professionals, a client receiving one of these reports can make decisions in the first 24 hours that shape the next 12 months based on unchecked claims. That's worth flagging to clients now, before any of them are staring at one for real.
Why attackers are adding fake legal reports
Ransomware pressure has escalated in stages: encryption, leak-site countdowns, then phone calls to executives and staff. Arran Roberts, a partner in the cyber and data risk team at law firm Kennedys, says the latest stage fills a gap attackers had never closed before: actually understanding what's inside the stolen data.
"It's only in the last couple of months that we've really started to see these sorts of legal risk analyses coming to the forefront," Roberts said. His team logged several examples inside a single week. So far the tactic appears confined to established, better-resourced groups. Alexandra O'Hare, a senior associate at the firm, attributes that to cost: feeding stolen data into an AI model at scale takes more time and money than most smaller attackers have to spend.
This is two lawyers at one firm describing what they've personally handled, not a market-wide study. Treat it as an early trend when raising it with clients, not a confirmed shift at scale.
What clients need to understand about these reports
The reports are built to scare, not inform. O'Hare described a case where a threat actor's report cited regulatory fines based on the worst possible reading of the data, ignoring anything that would have lowered the real risk. She called it a scare tactic rather than genuine legal analysis.
Roberts is blunt about how much weight these documents deserve. "I always take that with a very healthy pinch of salt," he said. Nobody outside the criminal group knows how they were actually produced - from a real look at the stolen files or something closer to a generic template run through a model. His approach is the same one incident responders have always taken with claims made by criminals: check it before acting on it. The single most useful thing for a client to hear early is that whatever the attacker hands over is not a finding, it's a pitch.
That doesn't make the reports completely useless. O'Hare said they can sometimes point a forensic team toward files worth checking early, or give a business a head start on preparing for regulatory questions. The distinction to draw for a client is between using the report as a lead and treating it as verified fact.
The consequences if a client gets this wrong
Money is the most obvious risk. A report that exaggerates how much data was taken can push a client into paying a ransom to stop a leak that was never as serious as claimed, or into expensive containment work for data that was never taken at all. Roberts pointed out that a claim to hold "the crown jewels" of a company is designed to provoke one response - pay up - whether or not that turns out to be the sensible move once the facts are known.
There's also a regulatory trap that works in both directions. Under UK GDPR, a notifiable breach must be reported to the ICO within 72 hours of becoming aware of it, and that clock starts long before an investigation is finished. A fabricated report can push a client to notify too early on claims that turn out to be overstated, which can look badly judged once a regulator reviews it later. But a client that dismisses a report too quickly, assuming it's a bluff, risks missing a genuine deadline on a real breach. Neither mistake is solved by taking the criminal's version at face value.
Reputational harm doesn't depend on the underlying claims being true. Roberts and O'Hare both described AI-driven tactics where damage lands before anyone can verify anything: fabricated internal documents threatened with publication, deepfake voice calls, phishing emails cloned convincingly enough to fool colleagues and customers. A client's share price or customer trust can take a hit from a leak that turns out to be entirely invented, purely because the public saw it first.
There's exposure to the people whose data was actually involved. If AI is helping criminals pull usable personal information out of stolen files that used to be too unstructured for anyone to bother with, it weakens an argument businesses and their advisers have relied on for years: that stolen data is usually too messy to actually exploit. Weaken that argument and a single ransomware incident has a better chance of turning into individual claims or a class action months later. It's also worth a quiet word with clients about how decisions taken under manufactured pressure hold up in hindsight, including whether directors and officers face scrutiny over the calls they made in the moment.
Finally, flag the cost of wasting time. Even a report that changes nothing still eats hours a forensic team needs for the real investigation. According to Coveware's own negotiation data, the ransom payment rate sat around 20% by the end of 2025. Encryption on its own is losing its ability to force a payment, so attackers are leaning harder on tactics like this to make up the difference. That trend line is useful for brokers to bring into client conversations about why incident response planning matters more than it did two years ago.
The fake legal reports sit alongside other tactics Roberts described: phishing emails that used to give themselves away through poor grammar, now polished enough to copy a real colleague's tone and sign-off, and deepfake voice calls built from a company's own public-facing video, used to talk IT help desks into resetting credentials. None of this needs to be true to cause damage. The useful frame to give clients directly is that their ability to check claims quickly, rather than their speed in reacting to them, tends to decide how badly things go.
What to actually tell clients
Tell them to treat anything handed over by an attacker as a sales pitch, not evidence. It exists to manufacture urgency, and the right response is to pass it to the forensic team as a lead, not to act on it directly.
Tell them to hold off notifying anyone, in either direction, until their own investigation has caught up. The 72-hour clock starts at genuine awareness of a breach, not at the moment a criminal claims one happened. Rushing to notify or dismissing a claim too fast are both mistakes that are hard to reverse once made.
Tell them to keep the ransom decision separate from the fear it's designed to provoke. If a payment is genuinely on the table, it should rest on what's been independently checked, not on how frightening the attacker's report reads.
Tell them to write down the reasoning at the time, whatever gets decided. If a client chooses to disregard part of what a threat actor claims, that decision should be documented as it's made, because regulators and courts tend to look at the judgement behind a decision, not just how things turned out.
The broader point for any client conversation is that a response plan agreed before an attack, rather than improvised during one, is what separates a bad first day from a bad first year. NCSC guidance on ransomware and ICO guidance on ransomware and data protection are both built around that idea, and both are worth pointing clients toward directly as part of renewal or risk review conversations, rather than waiting until an incident forces the discussion.
Why this matters for insurance professionals
Insurance professionals are the early warning line for clients who may never have thought about AI-generated ransomware pressure. When a client calls in a crisis, the credibility of a risk report baked by a criminal will determine whether they waste money, notify regulators too soon, or miss a real deadline. Your ability to brief them now - before any incident - on how to treat these documents as leads, not facts, directly reduces the chance of a bad first day shaping a bad first year. Pointing clients toward AI for Insurance training and certification courses can help them understand AI-driven risk assessment and claims processing relevant to advising on these threats. For clients in regulated or data-heavy sectors, the AI for Cybersecurity Analysts learning path also directly covers ransomware attack response and AI threat detection. The clients who have a decision framework ready will handle the first 72 hours far better than those who improvise.
Your membership also unlocks: