Law firms and the 2026 data theft wave: what changed
Legal Sector

Law firms and the 2026 data theft wave: what changed

Mathew Potter

Security Analyst

August 21, 2026

If you skimmed the headlines in August 2026, you probably noticed the same pattern: another large law firm disclosed a breach, another regulator filing, another rumour about a multi-million dollar payment to keep client files off the internet.

What is different from the ransomware stories we got used to is how little encryption matters now. Groups like Silent Ransom (also tracked as Luna Moth or UNC3753) often move from first contact to data theft in hours, sometimes less. Mandiant has documented cases where exfiltration and the first extortion email landed inside a single business day.

How they get in

The playbook is social, not exotic. Voice phishing. Callers who sound like IT. Emails that push you to install remote support tools you already trust. In a few cases, attackers have shown up in person pretending to be help desk staff or tried USB drops on unlocked machines.

That is uncomfortable for firms that budget for firewalls and endpoint suites but spend less time on remote access hygiene and user verification. If someone can talk a receptionist or a junior associate into opening a session, the rest is often just file copying.

Law firms hold exactly the data criminals price highest: identity numbers, financial records, health information tied to matters, and privileged correspondence. Reputation is the product. The threat of public disclosure is leverage even when systems still boot normally.

Regulatory filings this summer from firms including Herbert Smith Freehills Kramer, Mayer Brown, Goodwin Procter, Fox Rothschild, and others describe the same categories of loss: government IDs, financial account details, and sensitive personal data. Troutman Pepper Locke was hit again in mid-August. The details differ, but the shape of the problem does not.

What actually helps

We are not going to pretend one checklist stops a determined actor. Practical steps we see hold up under review:

  • Treat remote monitoring tools like privileged access. Inventory them, restrict who can approve installs, log sessions.
  • Run tabletop exercises that include fake IT calls, not just phishing links.
  • Keep an external assessment report you can hand to insurers and corporate clients when they ask what you did this year.
  • Separate backup and restore tests from backup jobs. Carriers increasingly ask for proof of restore, not proof of backup.

Bottom line

The industry is shifting from "pay to decrypt" to "pay to suppress." That is still a crisis, but it is a different one. Firms that only measured success by uptime are recalibrating. If you want an independent read on mail, access, and exposed services before renewal season, that is the work we do at Forensic Five. Scoped, written, and explicit about limits.

Tags

law firms data theft extortion Silent Ransom legal sector security

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.