Cyberattacks on law firms nearly double amid data theft

International law firm Greenberg Traurig recently reported that an unauthorized entity accessed a limited number of documents and subsequently published them on the dark web. This incident highlights a growing trend of cyberattacks specifically targeting law firms.

The number of cybersecurity incidents involving law firms nearly doubled from 2024 to 2025, with almost 60 cases handled in 2025, according to BakerHostetler. Their 2026 Data Security Incident Response Report analyzed over 1,250 incidents across various industries in 2025, indicating that phishing was responsible for 30% of these breaches.

Recent Cyberattacks on Law Firms

Several other law firms have also disclosed data breaches. Taft Stettinius & Hollister identified unusual activity on a system in March 2026, leading to the exposure of client Social Security numbers. In May, Herbert Smith Freehills Kramer, a London-based firm, reported unauthorized access that compromised Social Security numbers, government identification numbers, and health records.

A separate alleged breach at WilmerHale in May resulted in a proposed class-action lawsuit. More recently, Goodwin Procter disclosed an incident on August 7, and Quinn Emanuel reported on August 14 that a social-engineering attack compromised one account and exposed stored files.

Data Breaches in the Cryptocurrency Sector

Beyond law firms, cryptocurrency companies have also experienced significant data breaches. In May 2025, Coinbase revealed that criminals bribed overseas support agents to steal personal data from 69,461 users, including names, addresses, phone numbers, and government ID images. Coinbase stated that no funds, passwords, or private keys were compromised.

Coinbase rejected a $20 million ransom demand. Instead, they offered the same amount for information leading to the attackers' arrest and conviction. This demonstrates a firm stance against ransomware payments.

In January 2026, Ledger confirmed a breach at its e-commerce partner Global-e, which exposed order data for some Ledger.com customers. A Ledger spokesperson indicated that the incident involved unauthorized access to order data within Global-e's systems, affecting customers who purchased through Ledger.com using Global-e as the merchant of record.

In August, SafePal reported that a flaw in an order-tracking plug-in exposed personal information of approximately 39,798 customers. This included names, emails, shipping addresses, phone numbers, and purchase details. The company confirmed that wallet credentials and payment information remained secure, and the flaw was rectified with affected customers notified.

Earlier in the week, Trezor disclosed that hackers breached its third-party email provider. This led to phishing emails disguised as security alerts that falsely claimed a hardware flaw threatened users' recovery phrases. Trezor has since taken down the malicious domain and is investigating the breach.

Simonas Brazionis

Blockchain Expert

Simonas is a crypto and blockchain expert with 6 years of experience. Passionate about the industry he educates others on blockchain technology, and continuously expands his knowledge. He has helped many newcomers understand crypto, navigate investments, and stay informed about trends like DeFi and NFTs.