Law-Firm Documents Turn Up on Dark Web as Cyberattacks Increase
Phishing, social‑engineering scams and vendor compromises are driving the rise in intrusions and raising firms’ litigation risk.
Overview
- Greenberg Traurig said an unauthorized actor accessed a limited number of its documents and posted them on the dark web, but the firm did not identify what the documents contained or how many people, if any, were affected.
- A BakerHostetler incident‑response report showed a sharp rise in matters handled for law firms, reporting nearly 60 cyber incidents in 2025 and identifying phishing as the leading cause in about 30% of cases.
- Other recent law‑firm disclosures have involved exposed Social Security numbers, government IDs and health records, and some incidents have prompted proposed class actions or lawsuits against firms.
- The problem extends beyond law firms: crypto companies and vendors have reported breaches where third‑party service providers or bribed agents exposed customer data without compromising funds or private keys, and Trezor said its email provider was breached and used to send phishing alerts.
- The mix of human‑targeted tactics and vendor weaknesses increases risk to clients’ sensitive data, which experts warn will likely drive more breach notices, litigation and tighter third‑party security checks across the legal industry.