Home Crypto Law firm documents appear on dark web as cyberattacks rise

Law firm documents appear on dark web as cyberattacks rise

3
0



A limited number of Greenberg Traurig documents have appeared on the dark web after an unauthorized actor accessed them, the international law firm has said.

Summary

  • Greenberg Traurig said an unauthorized actor accessed and posted a limited number of documents.
  • BakerHostetler handled nearly 60 cyber incidents involving law firms in 2025, according to Reuters.
  • Other firms have reported breaches involving client identity and health information.
  • Crypto wallet providers have also reported customer-data leaks and phishing attacks through outside service providers.

Reuters reported on Sep. 10 that Greenberg Traurig had confirmed the unauthorized access and dark web posting. The firm described the number of documents as limited. The supplied account does not identify what the documents contained or say how many people, if any, were affected.

The disclosure comes after other law firms reported unauthorized access to systems holding personal information. The incidents did not all involve the same type of data or method of attack, but several exposed records that firms kept for clients and others who dealt with them.

Law firm breach reports include identity and health records

In March, Taft Stettinius & Hollister detected unusual activity on one of its systems, according to Reuters. The incident exposed the client’s Social Security numbers. Reuters also reported that London-based Herbert Smith Freehills Kramer disclosed unauthorized access in May involving Social Security numbers, government identification numbers, and health records.

A separate alleged breach at WilmerHale in May led to a proposed class action in July. The lawsuit concerns the alleged exposure of information held by the firm; the filing of a proposed class action does not establish the allegations as fact.

Goodwin Procter disclosed another incident on Aug. 7. Later that month, Quinn Emanuel said a social-engineering attack had compromised one account and exposed files stored in it. In a social-engineering attack, the attacker uses deception to gain information or access, rather than necessarily breaking into a system through a software flaw.

The affected records also differ from case to case. Greenberg Traurig has described documents posted on the dark web, while the reports about Taft and Herbert Smith Freehills Kramer identify particular categories of personal data. Quinn Emanuel’s disclosure concerns files accessible through a compromised account. The available details do not establish that the Greenberg Traurig documents contained the same kinds of information reported in the other incidents.

Cyber incident data shows the scale of the problem

Reuters said BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost twice the number it handled in 2024. The figure describes matters handled by BakerHostetler, not a count of every breach at a law firm during either year.

In its 2026 incident-response report, BakerHostetler analyzed more than 1,250 data security incidents across industries in 2025. Phishing was the leading identified cause, accounting for 30% of incidents. The firm said outside vendors were the cause in 25% of the matters it analyzed.

The report also tracked what happened after incidents were disclosed. BakerHostetler said class actions were filed in 14% of incidents in 2025, up from 9% in 2024. Among the incidents in its dataset that were disclosed, lawsuits followed 68 of 482 in 2025, compared with 51 of 518 in the previous year.

BakerHostetler’s figures cover clients across several industries, so they should not be read as rates specific to law firms. Its report placed business and professional services behind health care and finance and insurance among the sectors represented in the incidents it handled.

Crypto customer data has also been exposed through service providers

For U.S. crypto customers, a separate set of disclosures shows how personal details can be exposed even when a company says its users’ funds or wallet credentials were not accessed.

In May 2025, U.S. exchange Coinbase disclosed that criminals had bribed overseas support agents to obtain customer information. The breach affected 69,461 users and included names, addresses, phone numbers, and images of government IDs. Coinbase said passwords, private keys, and customer funds were not compromised. The exchange rejected a $20 million ransom demand and offered a reward of the same amount for information leading to the attackers’ arrest and conviction.

Hardware wallet companies have reported incidents involving firms that process orders or send customer messages. In January, Ledger said unauthorized access to e-commerce partner Global-e had exposed order information belonging to some people who bought products through Ledger.com. A Ledger spokesperson told Decrypt that the accessed information was held in Global-e’s systems and included data related to purchases for which Global-e acted as the merchant of record.

In August, SafePal said a flaw in an order-tracking plug-in exposed information belonging to about 39,798 customers. The records included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said the incident did not affect wallet credentials or payment information; it also said it had fixed the flaw and notified affected customers.

Trezor has reported two distinct incidents involving outside providers. As previously covered by crypto.news, the wallet maker said information belonging to more than 80,000 customers was exposed through shipping provider ShipMonk. Trezor said its own systems, hardware wallets, private keys, and recovery phrases were not compromised. Its expanded disclosure included records belonging to about 67,000 additional U.S. customers who had placed orders between November 2019 and August 2021.

On Sep. 9, Trezor warned that an attacker had breached its third-party email provider and sent phishing messages posing as urgent security alerts. The emails falsely claimed that a hardware flaw put users’ recovery phrases at risk. Trezor said it had taken down the domain used in the attempt and was investigating. BitBox warned users the same day about emails impersonating its company and said its newsletter provider was likely compromised.

Earlier in 2026, scammers also sent physical letters posing as notices from Trezor and Ledger. The wallet phishing letters directed recipients to scan QR codes and enter their recovery phrases on malicious websites. Trezor and Ledger said they do not ask users to share recovery phrases through websites or other outside channels.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here