Cyberattacks on Law Firms Surge as Stolen Documents Hit Dark Web
A doubling of cybersecurity incidents at BakerHostetler and breaches at major firms signal a systemic vulnerability in the legal sector.
Cyberattacks targeting law firms have seen a significant surge across 2025 and 2026, exposing the high-value data held by the legal industry. This trend underscores a growing vulnerability in how privileged client information is protected against evolving digital threats.
The scale of the increase is evident in the caseload of BakerHostetler, which handled nearly 60 cybersecurity incidents involving law firms in 2025. According to reports from Decrypt, this figure represents almost double the firm's caseload from 2024. This spike in activity coincides with high-profile disclosures from prominent firms. Greenberg Traurig confirmed in a statement to Reuters that an unauthorized actor gained access to a limited number of documents and subsequently posted them on the dark web. Additionally, the firm Eckert Seamans disclosed a data security incident that occurred on or around April 17, 2025.
The High Value of Legal Data
Law firms have become primary targets for cybercriminals because they serve as centralized repositories for sensitive client data, intellectual property, and privileged communications. Unlike a breach at a single corporation, a successful attack on a law firm can provide threat actors with a gateway to the secrets of multiple corporate clients simultaneously. This makes the legal sector a high-leverage target for espionage and extortion, as the stolen materials often include strategic business plans and confidential litigation strategies.
Systemic Risks to Privilege
The doubling of incidents reported by BakerHostetler suggests that existing security measures within the legal industry are failing to keep pace with modern attack vectors. The consequence extends beyond simple data loss; these breaches potentially compromise attorney-client privilege on a systemic scale. When privileged communications are leaked to the dark web, the fundamental confidentiality that underpins the legal profession is eroded, creating significant legal and financial risks for the clients involved.
Monitoring the Trend
As firms like Greenberg Traurig and Eckert Seamans navigate the aftermath of their respective breaches, the industry is facing increased pressure to overhaul its cybersecurity frameworks. Observers are now watching to see if this surge in attacks will lead to stricter regulatory requirements for data handling in the legal sector. While the immediate focus remains on the 2025-2026 spike, the persistence of these leaks indicates that threat actors view the legal industry as a soft target with high rewards.