NewsMacroCyberattacks on Law Firms Nearly Double as Stolen Documents Appear on Dark Web

Cyberattacks on Law Firms Nearly Double as Stolen Documents Appear on Dark Web

Author: Decrypt·

Key Takeaways

  • Greenberg Traurig said an unauthorized actor accessed a limited number of documents that were posted on the dark web, and the firm notified affected clients after a Vermont notice identified exposed Social Security information.
  • BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double its 2024 caseload, according to Reuters.
  • Phishing accounted for 30% of the more than 1,250 incidents analyzed in BakerHostetler's 2026 Data Security Incident Response Report, with other cases involving social engineering and unauthorized access.
  • Multiple law firms disclosed 2026 breaches, including Taft Stettinius & Hollister, Herbert Smith Freehills Kramer, Goodwin Procter, and Quinn Emanuel, while an alleged May breach at WilmerHale prompted a proposed class action.
  • Crypto companies Coinbase, Ledger, SafePal, and Trezor reported personal-data exposures often tied to third-party providers or support staff, with each company stating that funds, passwords, private keys, or wallet credentials were not compromised.
Cyberattacks on Law Firms Nearly Double as Stolen Documents Appear on Dark Web

International law firm Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted them on the dark web, Reuters reported on Thursday. The firm said it notified affected clients, while a Vermont notice identified exposed Social Security information.

The incident comes amid a broader increase in cyberattacks targeting law firms. BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double its 2024 caseload, according to Reuters. The reported incidents show why law firms can be attractive targets: their systems may contain both confidential legal documents and clients’ personal information.

BakerHostetler’s 2026 Data Security Incident Response Report, published earlier this year, analyzed more than 1,250 incidents across industries in 2025. Phishing accounted for 30% of those incidents, according to the firm’s report. Other disclosures described in the report involve social engineering and unauthorized access, indicating that the exposure can result from both deceptive messages and compromised accounts.

Other law firms have also disclosed breaches involving personal information. In March 2026, Taft Stettinius & Hollister detected unusual activity on one system, exposing clients’ Social Security numbers, Reuters reported. In May, London-based Herbert Smith Freehills Kramer said unauthorized access exposed Social Security numbers, government identification numbers, and health records, according to Reuters.

A separate alleged breach at WilmerHale in May prompted a proposed class action, according to Reuters. Goodwin Procter disclosed an incident on August 7. Quinn Emanuel later said an August 14 social-engineering attack—using deception to obtain information or access—compromised one account and exposed stored files, Reuters reported. Notifications to affected parties, proposed litigation, and continuing investigations are among the developments that can follow such disclosures.

Crypto companies also report data breaches

Crypto companies have disclosed breaches involving customers’ personal information as well. The incidents also show that exposure can occur through service providers and other connected systems, rather than through a company’s core wallet or custody infrastructure.

In May 2025, Coinbase said criminals had bribed overseas support agents to steal personal data from 69,461 users, including names, addresses, phone numbers, and government-ID images. The exchange said no funds, passwords, or private keys were compromised. Coinbase refused a $20 million ransom demand and instead offered the same amount for information leading to the attackers’ arrest and conviction.

In January 2026, Ledger confirmed that a breach at its e-commerce partner Global-e exposed order data belonging to some Ledger.com customers. “This incident consisted of unauthorized access to order data in Global-e information systems. Some of the data accessed as part of this incident pertained to customers who made a purchase on Ledger.com using Global-e as a merchant of record,” a Ledger spokesperson told Decrypt in a statement.

In August, SafePal said a flaw in an order-tracking plug-in exposed personal information belonging to roughly 39,798 customers, including names, email addresses, shipping addresses, phone numbers, and purchase details. The company said wallet credentials and payment information were unaffected, and that it had fixed the flaw and notified customers.

Earlier this week, Trezor said hackers breached its third-party email provider and sent phishing emails disguised as security alerts. The messages falsely claimed that a hardware flaw threatened users’ recovery phrases. Trezor said it took down the malicious domain and was investigating the breach.