Article is online

Law Firms Face Surge in Cyberattacks as Stolen Files Appear on the Dark Web

Law Firms Face Surge in Cyberattacks as Stolen Files Appear on the Dark Web

Preface


Overview: Recent months have seen a notable escalation in cyberattacks against law firms, with stolen documents appearing on the dark web and multiple firms reporting data exposures. This article summarizes the incidents, highlights how attackers are gaining access, and places these events in the broader context of rising breaches across industries. The purpose is to provide a clear, factual update and to underscore the growing risks law firms face as custodians of sensitive client information.



Lazy bag


Key takeaway: Law firms are increasingly targeted by cybercriminals, resulting in stolen documents posted online and repeated disclosures of exposed personal data. Several major firms have reported breaches, and industry data show a steep rise in incidents year over year.



Main Body


The legal sector has become a prominent target for cybercriminals, as recent disclosures show that stolen client files from multiple firms have surfaced on the dark web. International firm Greenberg Traurig confirmed that an unauthorized actor accessed a limited set of documents and posted some of them online. The firm notified affected clients; in at least one instance, a notification filed in Vermont indicated that Social Security numbers had been exposed. Such incidents highlight the sensitive nature of the information law firms store and the reputational and legal risks tied to breaches.



Data collected by incident response providers paints a clear picture of a rising trend. BakerHostetler’s recent report documented a near doubling of cybersecurity incidents involving law firms in 2025 compared with 2024. Their 2026 Data Security Incident Response Report, which draws on more than 1,250 incidents across industries in 2025, attributed roughly 30% of incidents to phishing. This pattern reinforces how attackers often exploit human weaknesses and email-based vectors to gain initial access to systems that contain confidential client records.



Other firms have disclosed similar events. In March 2026, Taft Stettinius & Hollister reported unusual activity on a system that led to the exposure of client Social Security numbers. In May, London-based Herbert Smith Freehills Kramer said that unauthorized access exposed Social Security numbers, government ID numbers, and health records. A separate alleged breach at WilmerHale in May prompted a proposed class action complaint. More recent incidents include Goodwin Procter’s disclosure on August 7 and Quinn Emanuel’s statement that a social-engineering attack on August 14 compromised a single account and exposed stored files. These varied incidents illustrate that both technical vulnerabilities and targeted deception contribute to breaches.



Cyber threats to professional services are not limited to law firms. The cryptocurrency sector has also faced notable exposures. In May 2025, Coinbase revealed that malicious actors had bribed overseas support staff to steal personal data for 69,461 users — including names, addresses, phone numbers, and government ID images. Coinbase stated that no account funds, passwords, or private keys were taken; the company declined to pay a $20 million ransom and instead offered the same amount for information leading to the attackers’ arrest. In January 2026, Ledger confirmed unauthorized access at its e-commerce partner Global-e, which exposed order data for some Ledger.com customers. And in August, SafePal reported that a flaw in an order-tracking plug-in exposed personal information for roughly 39,798 customers, though wallet credentials and payment details remained unaffected.



Supply-chain and third-party risks remain a recurring theme. Trezor recently disclosed that hackers compromised a third-party email provider and used that access to send phishing messages impersonating security alerts, falsely claiming a hardware flaw threatened users’ recovery phrases. Trezor removed the malicious domain and is investigating the intrusion. These incidents emphasize how attackers exploit peripheral vendors and services to reach primary targets, making robust vendor risk management essential.



The ongoing pattern of breaches raises important questions about preparedness and response. Law firms are data-rich targets: they hold client identities, financial records, health information, and privileged legal documents. Safeguarding that data requires layered security controls, continuous monitoring for unusual activity, proactive phishing prevention and employee training, rigorous access controls, and clear incident response plans. When breaches occur, timely notifications to affected clients and coordination with regulators and law enforcement are critical to limit harm and meet legal obligations.



Finally, these developments have broader implications for clients and the legal industry. Clients should inquire about their firms’ cybersecurity posture, data-handling practices, and breach response plans. Firms, in turn, must treat cybersecurity as a core operational priority and invest in both technical defenses and user-focused controls. The rise in incidents underscores a reality: legal organizations are part of an expanding attack surface, and mitigating this risk requires sustained attention and investment.



Conclusion: The recent wave of cyberattacks and dark-web disclosures underscores a growing threat to law firms and other professional services. As attackers continue to use phishing, social engineering, and third-party compromises, firms must adopt comprehensive security strategies to protect sensitive client information and preserve trust.



Key Insights Table



















Aspect Description
Key Fact 1 Multiple law firms, including Greenberg Traurig, reported unauthorized access and documents posted on the dark web.
Key Fact 2 Industry data show nearly double the number of law-firm incidents in 2025 versus 2024, with phishing a common entry vector.

Last edited at:2026/9/11
#Coinbase

Mr. W

ZNews full-time writer