Key facts
- Greenberg Traurig confirmed an unauthorized actor accessed and posted documents on the dark web.
- BakerHostetler reported nearly 60 cybersecurity incidents involving law firms in 2025, nearly double the 2024 figure.
- Phishing accounted for 30% of incidents handled by BakerHostetler in 2025.
- Other law firms, including Taft Stettinius & Hollister, Herbert Smith Freehills Kramer, WilmerHale, Goodwin Procter, and Quinn Emanuel, have also disclosed data breaches.
- Exposed data has included Social Security numbers, government identification numbers, and health records.
International law firm Greenberg Traurig has confirmed that an unauthorized actor accessed a limited number of documents and subsequently posted them on the dark web. The firm has notified its affected clients about the breach. A notice filed in Vermont identified exposed Social Security information related to the incident.
This incident is part of a broader trend of increasing cyberattacks targeting law firms. According to Reuters, the law firm BakerHostetler reported handling nearly 60 cybersecurity incidents involving law firms in 2025, a figure that is almost double its caseload from 2024. A report by BakerHostetler indicated that phishing was responsible for 30% of these incidents in 2025.
Other law firms have also disclosed data breaches in recent months. In March 2026, Taft Stettinius & Hollister detected unusual activity that exposed client Social Security numbers. In May, Herbert Smith Freehills Kramer reported that unauthorized access exposed Social Security numbers, government identification numbers, and health records. WilmerHale also faced a proposed class action lawsuit following an alleged breach in May. More recently, Goodwin Procter disclosed an incident on August 7, and Quinn Emanuel reported a social-engineering attack on August 14 that compromised an account and exposed stored files.
