Law Firm Cyberattacks Rise as Stolen Files Surface on the Dark Web, With Crypto Firms Facing Similar Breaches

Law Firm Cyberattacks Rise as Stolen Files Surface on the Dark Web, With Crypto Firms Facing Similar Breaches

N
News Editor
2026-09-11 21:45:05
International law firm Greenberg Traurig said an unauthorized actor accessed a limited set of documents and posted them on the dark web, according to a Thursday Reuters report. The incident adds to a broader rise in cyberattacks against law firms, a sector that increasingly holds sensitive client records and case materials. Reuters said BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost twice the number it handled in 2024. In a report released earlier this year, the firm said its 2026 Data Security Incident Response Report drew on more than 1,250 incidents across industries in 2025, with phishing making up 30% of cases. Reuters also pointed to recent disclosures by Taft Stettinius & Hollister, Herbert Smith Freehills Kramer, WilmerHale, Goodwin Procter, and Quinn Emanuel. The article also linked the legal sector’s troubles to recent breaches disclosed by crypto companies including Coinbase, Ledger, SafePal, and Trezor, each involving some form of customer information exposure while companies said wallet credentials, funds, or private keys were not affected where specified.

International law firm Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted them on the dark web, Reuters reported Thursday.

Law firms are reporting more security breaches

The incident fits into a wider pattern of data breaches hitting law firms. Reuters said BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double its 2024 caseload.

In a report published earlier this year, BakerHostetler said its 2026 Data Security Incident Response Report drew on more than 1,250 incidents across industries in 2025. Phishing accounted for 30% of those incidents.

Recent disclosures span several firms

Reuters said other law firms have also disclosed breaches. In March 2026, Taft Stettinius & Hollister detected unusual activity on one system that exposed client Social Security numbers.

In May, London-based Herbert Smith Freehills Kramer said unauthorized access exposed Social Security numbers, government identification numbers, and health records. A separate alleged breach at WilmerHale that same month led to a proposed class action.

More recently, Goodwin Procter disclosed an incident on August 7. Quinn Emanuel, for its part, said an August 14 social-engineering attack using deception to obtain information or access compromised one account and exposed stored files.

Crypto companies have disclosed customer-data incidents too

Crypto firms have also reported breaches involving customer personal information.

In May 2025, Coinbase said criminals bribed overseas support agents and stole personal data from 69,461 users, including names, addresses, phone numbers, and images of government-issued identification. The exchange said no funds, passwords, or private keys were compromised. Coinbase rejected a $20 million ransom demand and instead offered the same amount for information leading to the attackers’ arrest and conviction.

In January 2026, Ledger confirmed that a breach at e-commerce partner Global-e exposed order data belonging to some Ledger.com customers.

A Ledger spokesperson said in a statement to Decrypt: "This incident consisted of unauthorized access to order data in Global-e information systems. Some of the data accessed as part of this incident pertained to customers who made a purchase on Ledger.com using Global-e as a merchant of record."

More recently, in August, SafePal said an order-tracking plug-in flaw exposed personal information belonging to roughly 39,798 customers, including names, emails, shipping addresses, phone numbers, and purchase details. The company said wallet credentials and payment information were unaffected, and that it had fixed the flaw and notified customers.

Earlier this week, Trezor said hackers breached its third-party email provider and sent phishing emails disguised as security alerts. The messages falsely claimed that a hardware flaw threatened users’ recovery phrases. Trezor said it had taken down the malicious domain and was investigating the breach.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.