In late December 2016, attorneys across the U.S. received emails with the subject line “The Office of The State Attorney Complaint,” purporting to hold, in an attached PDF, information regarding a vague legal action against them that required their attention. Only, such emails were never sent by any government or legal official. Nor did the PDF files contain complaints, but instead hidden ransomware files.

The emails, which the New York Attorney General’s office posted a copy of on its website, were but one of two phishing attacks—a method whereby cybercriminals try to trick unsuspecting users into voluntarily downloading malware on their systems—targeting attorneys in multiple states, including New York, Florida, Maryland, and Texas.