Skip to content

Invest1 publisher2 min readPublished

Law-firm breach cases nearly doubled in the book of the firm that counts them

Greenberg Traurig says an intruder took client documents and posted them on the dark web. The doubling behind that story is nearly 60 law-firm matters inside BakerHostetler's 1,250-incident book for 2025.

The Investor · Invest desk

Illustration accompanying Law-firm breach cases nearly doubled in the book of the firm that counts them

What happened

  • Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted them on the dark web, and a Vermont notice identified exposed Social Security information.
  • The same firm's 2026 Data Security Incident Response Report draws on more than 1,250 incidents across all industries in 2025.
  • Quinn Emanuel said a social-engineering attack on August 14 compromised one account and exposed stored files, a week after Goodwin Procter disclosed an incident on August 7.
  • An alleged May breach at WilmerHale prompted a proposed class action, and both WilmerHale and Eckert Seamans are facing lawsuits over exposed personal data.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure The records at risk belong to clients while the notification duty sits with the firm, so a general counsel learns of an exposure on a vendor's timetable.
  • precedent With a class action already proposed against a firm over an alleged breach, litigation is the expected sequel to a law-firm disclosure, and the firm holding the documents is the named defendant.
  • contradiction Law firms are under 5% of one responder's 2025 caseload, so the same figures support both a targeting story and a story about one vendor selling more legal-sector work.

Put nearly 60 law-firm matters against more than 1,250 incidents across all industries and law firms come to about 4.8% of BakerHostetler's 2025 book, roughly one matter in twenty-one [18]. Almost double 2024 means the 2024 count was around 30, so the year-over-year increase is about 30 engagements at a single responder [19].

Decrypt's account of the Greenberg Traurig disclosure does not say how many documents [21], while the other disclosures name the data. Herbert Smith Freehills Kramer, the London-based firm, said in May that unauthorized access exposed Social Security numbers, government identification numbers and health records [7]. Taft Stettinius & Hollister found unusual activity on one system in March 2026 that exposed client Social Security numbers [6].

The crypto incidents in the same account share a structure with the law-firm ones, in that the data left through a supplier the customer never picked. Ledger confirmed in January 2026 that a breach at e-commerce partner Global-e exposed order data belonging to some Ledger.com customers [14]. "Some of the data accessed as part of this incident pertained to customers who made a purchase on Ledger.com using Global-e as a merchant of record," a Ledger spokesperson told Decrypt [15]. SafePal said in August that an order-tracking plug-in flaw exposed personal information belonging to roughly 39,798 customers [16]. Trezor said hackers breached its third-party email provider and sent phishing emails disguised as security alerts [17].

One dollar figure appears anywhere in this. After criminals bribed overseas support agents to steal personal data from 69,461 users in May 2025, Coinbase refused a $20 million ransom demand and offered the same amount for information leading to the attackers' arrest and conviction [12][13]. Spread across those users, the bounty is about $288 a head [22].

Phishing accounted for 30% of the more than 1,250 incidents in the report [5]. A client cannot inspect that entry point from outside, and would want to ask outside counsel about it.

The narrow claim I would make is about custody: client records sit in document stores at firms the client hired, and the number of incidents at those firms went up in one responder's engagement book [3]. The counter-thesis: nearly 60 is a small number, it comes from one vendor's own matters, and a doubling there is consistent with that vendor winning more legal-sector work [3]. The next report separates the two readings. If law firms rise again as a share of a stated total, the targeting claim holds; if the total rises with them, this was one practice's growth.

What to watch

  • Whether BakerHostetler's next report gives law-firm incidents as a share of a stated total, which would separate more attacks from more legal-sector clients.
  • Whether the proposed class action over the alleged May WilmerHale breach is certified, and what the Eckert Seamans suits claim in damages.
  • Whether Greenberg Traurig client notifications produce state notices beyond the Vermont one.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories