In brief

  • Greenberg Traurig said an unauthorized actor accessed a limited number of documents and published them on the dark web.
  • The firm notified affected clients, while a Vermont notice identified exposed Social Security information.
  • Other law firms have reported data breaches, with WilmerHale and Eckert Seamans facing lawsuits.

International law firm Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted them on the dark web, Reuters reported on Thursday.

The incident reflects a rising wave of cyberattacks targeting law firms. According to Reuters, BakerHostetler managed nearly 60 cybersecurity matters involving law firms in 2025, almost twice the number handled in 2024.

Other firms have also disclosed breaches. In March 2026, Taft Stettinius & Hollister detected unusual activity on one system, which exposed clients’ Social Security numbers, according to Reuters.

In May, London-based Herbert Smith Freehills Kramer said unauthorized access exposed Social Security numbers, government identification numbers and health records. A separate alleged breach at WilmerHale in May led to a proposed class-action lawsuit. Eckert Seamans has also faced litigation over data breaches.

Goodwin Procter disclosed an incident on August 7. Quinn Emanuel said an August 14 social-engineering attack compromised one account and exposed stored files. The attack used deception to obtain information or system access.

Crypto Companies Report Personal-Data Breaches

Cryptocurrency companies have likewise disclosed incidents involving customers’ personal information.

In May 2025, Coinbase said criminals bribed overseas customer-support employees to steal data belonging to 69,461 users. The exposed information included names, addresses, phone numbers and images of government-issued identification. Coinbase said no funds, passwords or private keys were compromised. The company rejected a $20 million ransom demand and offered the same amount for information that would help secure the attackers’ arrest and conviction.

In January 2026, Ledger confirmed that a breach involving its e-commerce partner Global-e exposed order information belonging to some Ledger.com customers.

A Ledger spokesperson told Decrypt that the incident involved unauthorized access to order data in Global-e systems. Some of the accessed records belonged to Ledger.com customers who purchased through Global-e as the merchant of record.

In August, SafePal said a vulnerability in an order-tracking plug-in exposed personal information belonging to approximately 39,798 customers. The data included names, email addresses, shipping addresses, phone numbers and purchase details. The company said wallet credentials and payment information were not affected. SafePal said it fixed the vulnerability and notified customers.

Earlier this week, Trezor said hackers compromised its third-party email provider and sent phishing messages disguised as security alerts. The emails falsely warned that a hardware flaw threatened users’ recovery phrases. Trezor said it removed the malicious domain and continued investigating the breach.

Source link

Exit mobile version