Cyberattacks on Law Firms Nearly Double as Stolen Documents Hit the Dark Web

Greenberg Traurig said an unauthorized actor obtained a limited number of its documents and posted them on the dark web, prompting the firm to notify affected clients and state authorities after some Social Security numbers were identified. The disclosure is part of a wider surge in incidents targeting law firms, with BakerHostetler reporting a near doubling in law-firm cybersecurity cases in 2025 compared with 2024.

By AI NewsroomPublished about 1 hour agoUpdated about 1 hour ago0 views
Cyberattacks on Law Firms Nearly Double as Stolen Documents Hit the Dark Web

Why It Matters

Law firms hold sensitive client data and are increasingly targeted, raising risks for client privacy and potential legal exposure; the trend is mirrored across industries, where phishing remains a leading cause of breaches. Rising incidents have led to client notifications, proposed litigation and broader scrutiny of third-party and support workflows in both legal and crypto sectors.

Key Facts

  • Firm reporting dark-web posting: Greenberg Traurig said documents were posted to the dark web after unauthorized access.
  • Client notification and exposed data: The firm notified affected clients; a Vermont notice identified exposed Social Security information.
  • BakerHostetler 2025 law-firm incidents: Nearly 60 cybersecurity incidents involving law firms in 2025, almost double its 2024 caseload.
  • BakerHostetler dataset: 2026 report draws on more than 1,250 incidents across industries in 2025; phishing accounted for 30% of incidents.
  • Other law-firm breaches (examples): Taft Stettinius & Hollister (March 2026), Herbert Smith Freehills Kramer (May), WilmerHale (alleged May breach prompted proposed class action), Goodwin Procter (Aug 7), Quinn Emanuel (Aug 14 social-engineering attack).

International law firm Greenberg Traurig disclosed that an unauthorized actor accessed a limited set of documents and later posted them on the dark web. The firm said it notified clients who were affected, and a notice filed in Vermont indicated that some Social Security numbers were among the exposed information.

The incident adds to a broader uptick in attacks on law firms. BakerHostetler’s 2026 Data Security Incident Response Report, which reviewed more than 1,250 incidents across industries in 2025, recorded nearly 60 law-firm-related cybersecurity cases last year — almost twice the number the firm handled in 2024. The report also found that phishing accounted for roughly 30% of incidents in its dataset.

Several other firms have revealed breaches or suspected intrusions in recent months. Taft Stettinius & Hollister reported unusual activity in March 2026 that exposed client Social Security numbers. London-based Herbert Smith Freehills Kramer said a May incident exposed Social Security numbers, government ID numbers and health records. An alleged May breach at WilmerHale has led to a proposed class-action suit. More recent disclosures include Goodwin Procter on August 7 and Quinn Emanuel, which reported that a social-engineering attack on August 14 compromised one account and exposed stored files.

The pattern of attacks is not confined to law firms. Crypto companies have also faced data theft and third-party weaknesses: Coinbase said in May 2025 that criminals bribed overseas support agents to steal personal data from 69,461 users; Ledger attributed a January 2026 exposure to a breach at e-commerce partner Global-e; SafePal disclosed that an order-tracking plug-in flaw in August exposed roughly 39,798 customers’ personal details but not wallet credentials or payment data; and Trezor reported that hackers accessed a third-party email provider and used it to send phishing messages disguised as security alerts. These cases underscore growing concerns about the security of sensitive customer and client information across service providers and their partners.

Keep Reading