International law firm Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted them on the dark web, Reuters reported Thursday.
Law firms are reporting more security breaches
The incident fits into a wider pattern of data breaches hitting law firms. Reuters said BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double its 2024 caseload.
In a report published earlier this year, BakerHostetler said its 2026 Data Security Incident Response Report drew on more than 1,250 incidents across industries in 2025. Phishing accounted for 30% of those incidents.
Recent disclosures span several firms
Reuters said other law firms have also disclosed breaches. In March 2026, Taft Stettinius & Hollister detected unusual activity on one system that exposed client Social Security numbers.
In May, London-based Herbert Smith Freehills Kramer said unauthorized access exposed Social Security numbers, government identification numbers, and health records. A separate alleged breach at WilmerHale that same month led to a proposed class action.
More recently, Goodwin Procter disclosed an incident on August 7. Quinn Emanuel, for its part, said an August 14 social-engineering attack using deception to obtain information or access compromised one account and exposed stored files.
Crypto companies have disclosed customer-data incidents too
Crypto firms have also reported breaches involving customer personal information.
In May 2025, Coinbase said criminals bribed overseas support agents and stole personal data from 69,461 users, including names, addresses, phone numbers, and images of government-issued identification. The exchange said no funds, passwords, or private keys were compromised. Coinbase rejected a $20 million ransom demand and instead offered the same amount for information leading to the attackers’ arrest and conviction.
In January 2026, Ledger confirmed that a breach at e-commerce partner Global-e exposed order data belonging to some Ledger.com customers.
A Ledger spokesperson said in a statement to Decrypt: "This incident consisted of unauthorized access to order data in Global-e information systems. Some of the data accessed as part of this incident pertained to customers who made a purchase on Ledger.com using Global-e as a merchant of record."
More recently, in August, SafePal said an order-tracking plug-in flaw exposed personal information belonging to roughly 39,798 customers, including names, emails, shipping addresses, phone numbers, and purchase details. The company said wallet credentials and payment information were unaffected, and that it had fixed the flaw and notified customers.
Earlier this week, Trezor said hackers breached its third-party email provider and sent phishing emails disguised as security alerts. The messages falsely claimed that a hardware flaw threatened users’ recovery phrases. Trezor said it had taken down the malicious domain and was investigating the breach.


