In brief
- Greenberg Traurig said an unauthorized actor accessed documents and posted them on the dark web.
- The firm notified affected clients; a Vermont notice identified exposed Social Security information.
- Other law firms have disclosed breaches involving personal data, with WilmerHale and Eckert Seamans facing lawsuits.
International law firm Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted them on the dark web, Reuters reported on Thursday.
The report is part of a growing trend of data breaches targeting law firms. According to Reuters, the law firm of BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double its 2024 caseload.
In a report published earlier this year, BakerHostetler’s 2026 Data Security Incident Response Report draws on more than 1,250 incidents across industries in 2025, with phishing accounting for 30% of incidents.
According to Reuters, other law firms have disclosed data breaches, including an incident in March 2026, when Taft Stettinius & Hollister detected unusual activity on one system that exposed client Social Security numbers.
In May, the London-based law firm Herbert Smith Freehills Kramer said unauthorized access exposed Social Security numbers, government identification numbers, and health records. A separate alleged May breach at WilmerHale prompted a proposed class action.
More recently, Goodwin Procter disclosed an incident on August 7, while Quinn Emanuel said an August 14 social-engineering attack that uses deception to obtain information or access compromised one account and exposed stored files.
Crypto companies have also disclosed breaches involving customers’ personal information.
In May 2025, Coinbase disclosed that criminals bribed overseas support agents to steal personal data from 69,461 users, including names, addresses, phone numbers, and government-ID images. The exchange said no funds, passwords, or private keys were compromised. It refused a $20 million ransom demand and instead offered the same amount for information leading to the attackers’ arrest and conviction.
In January 2026, Ledger confirmed that a breach at e-commerce partner Global-e exposed order data belonging to some Ledger.com customers.
“This incident consisted of unauthorized access to order data in Global-e information systems. Some of the data accessed as part of this incident pertained to customers who made a purchase on Ledger.com using Global-e as a merchant of record,” a Ledger spokesperson told Decrypt in a statement.
More recently in August, SafePal said an order-tracking plug-in flaw exposed personal information belonging to roughly 39,798 customers, including names, emails, shipping addresses, phone numbers, and purchase details. The company said wallet credentials and payment information were unaffected, and it had fixed the flaw and notified customers.
Earlier this week, Trezor said hackers breached its third-party email provider and sent phishing emails disguised as security alerts. The messages falsely claimed a hardware flaw threatened users’ recovery phrases. Trezor said it took down the malicious domain and was investigating the breach.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Source link
Jason Nelson
https://decrypt.co/378094/cyberattacks-law-firms-stolen-documents-dark-web
2026-09-11 21:45:00

