International law firm Greenberg Traurig has confirmed that an unauthorized actor gained access to a limited volume of its internal documents and subsequently published them on the dark web. The incident marks the latest in an escalating wave of high-profile cyberattacks targeting premier legal institutions, which increasingly find themselves in the crosshairs of sophisticated threat actors seeking sensitive corporate data, client secrets, and personally identifiable information (PII).
The disclosure regarding Greenberg Traurig highlights a broader, troubling trajectory across the professional services sector. Law firms, long prized by cybercriminals for their repositories of confidential corporate litigation strategies, intellectual property, and high-net-worth client details, are experiencing an unprecedented surge in digital intrusions.
A Growing Trend: The Legal Sector Under Siege
The vulnerability of the legal industry is no longer theoretical; it is quantified by stark empirical data. According to incident response reports from major law firms like BakerHostetler, the frequency of cyberattacks targeting legal entities has grown exponentially. BakerHostetler handled nearly 60 distinct cybersecurity incidents involving law firms throughout 2025, representing an alarming nearly twofold increase compared to its 2024 caseload.
BakerHostetler’s 2026 Data Security Incident Response Report—which analyzed more than 1,250 security incidents across multiple industries during the previous year—underscores that phishing remains the primary vector for these breaches, accounting for approximately 30% of all recorded events. Threat actors continue to exploit human error, utilizing advanced social engineering techniques to compromise corporate credentials and gain initial access to secure networks.
The Greenberg Traurig event is merely one entry in a long roster of recent cyber incidents impacting major legal practices. A chronological look at the sector over the past year reveals a systematic targeting of legal infrastructure:
- March 2026: Taft Stettinius & Hollister detected unusual, unauthorized activity on one of its core systems, resulting in a data security event that exposed sensitive client information, including Social Security numbers.
- May 2026: London-headquartered law firm Herbert Smith Freehills Kramer disclosed an unauthorized access incident that compromised an array of sensitive records, spanning Social Security numbers, government-issued identification numbers, and confidential health records.
- May 2026 (Separate Incident): A separate cyber incident alleged to have impacted WilmerHale triggered swift fallout, leading to a proposed class-action lawsuit filed by affected parties.
- August 7, 2026: Prominent firm Goodwin Procter formally disclosed a data security incident, signaling ongoing vulnerabilities even among elite global practices.
- August 14, 2026: Litigation giant Quinn Emanuel fell victim to a sophisticated social-engineering attack. The deceptive maneuver allowed malicious actors to compromise a corporate account and expose stored internal files.
Parallels in the Cryptocurrency Industry
The wave of data breaches is not restricted to the legal sector. High-profile entities within the digital asset and cryptocurrency space have similarly grappled with significant security compromises involving customer and partner data. The overlap between legal and crypto breaches highlights a shared ecosystem vulnerability: the heavy reliance on third-party vendors and the high monetization value of the data these organizations store.
In May 2025, cryptocurrency exchange Coinbase faced a severe breach when malicious actors bribed overseas customer support agents. This inside-threat dynamic allowed criminals to extract personal data belonging to 69,461 users, including legal names, residential addresses, phone numbers, and images of government-issued identification cards. Demonstrating a hardline stance against extortion, Coinbase refused a $20 million ransom demand from the attackers. Instead, the company pivoted, offering an equivalent $20 million bounty for information leading directly to the arrest and conviction of the perpetrators.

The vulnerability of third-party supply chains was further illustrated in January 2026, when hardware wallet manufacturer Ledger confirmed a security failure at its e-commerce partner, Global-e. The breach compromised order data belonging to a subset of customers who completed purchases on Ledger.com utilizing Global-e as the merchant of record. A Ledger spokesperson confirmed the nature of the breach to media outlets, noting that the unauthorized access was confined to Global-e’s information systems rather than Ledger’s internal core infrastructure.
Similar incidents continued into the latter half of the year. In August 2026, Bitcoin wallet provider SafePal disclosed that a flaw within an order-tracking plug-in exposed the personal information of approximately 39,798 customers. The compromised datasets included customer names, email addresses, shipping destinations, phone numbers, and detailed purchase histories. SafePal assured its user base that recovery credentials, wallet seed phrases, and direct payment details remained secure, noting that the vulnerability was rapidly patched and affected users were notified.
Most recently, hardware wallet manufacturer Trezor faced a security scare when hackers breached its third-party email service provider. The attackers deployed malicious phishing campaigns, dispatching fraudulent emails disguised as security alerts to Trezor customers. The communications falsely claimed that a critical hardware flaw threatened users’ recovery phrases. Trezor acted swiftly to take down the malicious domains and launched a comprehensive forensic investigation into the third-party vector.
Analysis of Implications and Industry Response
The simultaneous targeting of law firms and cryptocurrency infrastructure points toward a calculated strategy by modern cybercriminal syndicates. Legal institutions manage high-stakes corporate mergers, intellectual property filings, and sensitive litigation data that can be leveraged for insider trading, corporate espionage, or extortion via ransomware. Meanwhile, the crypto sector attracts attacks aimed at obtaining user contact lists for targeted phishing campaigns, such as "wrench attacks" or sophisticated SIM-swapping operations.
For law firms, the reputational damage and regulatory fallout of a data breach can be catastrophic. Clients entrust law firms with their most tightly held secrets under the strict umbrella of attorney-client privilege. When those networks are breached, the foundational trust underpinning the client-lawyer relationship is severely tested.
Furthermore, the rise in class-action lawsuits following incidents—such as the legal actions faced by WilmerHale—signals that law firms will increasingly face direct financial and legal accountability for cybersecurity lapses. Cybersecurity experts stress that as traditional perimeter defenses harden, threat actors will continue to exploit the weakest links: third-party vendors, phishing-vulnerable employees, and outsourced support networks.
As Greenberg Traurig and other affected organizations navigate the aftermath of their respective incidents, the legal and financial sectors face mounting pressure to overhaul their vendor risk management, enhance employee security training, and implement zero-trust architectures to mitigate the ever-present threat of modern cybercrime.



