Crypto

Greenberg Traurig Joins Legal Sector’s Dark-Web Breach Wave

Law firms and crypto companies face escalating attacks through social engineering, vendors, and third-party providers

International law firm Greenberg Traurig, LLP has become the latest high-profile casualty in a systemic wave of data breaches targeting the highly sensitive repositories of professional services. The breach, first reported by Reuters, involved an unauthorized actor accessing a limited number of the firm’s internal documents and later publishing them on the dark web.

A regulatory notice filed by Greenberg Traurig with the state of Vermont said the compromised files contained highly sensitive personal data, including Social Security numbers. The firm, which employs more than 2,600 attorneys across dozens of offices worldwide, has begun notifying affected clients.

Legal practices routinely handle non-public corporate data, intellectual property, litigation strategies, and personal identifiable information (PII) belonging to corporate leaders and high-net-worth individuals. Cybercriminals increasingly view law firms as high-value, consolidated targets, frequently targeting a company’s legal counsel instead of trying to breach a heavily fortified corporate network.

The 2026 Data Security Incident Response Report from rival law firm BakerHostetler documented the vulnerability. After analyzing more than 1,250 security incidents across multiple industries in 2025, the report found that BakerHostetler’s own caseload involving cybersecurity incidents at law firms nearly doubled, reaching approximately 60 cases in 2025 compared to the previous year. Human error and social manipulation remained the most common entry points for hackers, while phishing campaigns accounted for 30% of all analyzed incidents.

Other major legal practices have also disclosed intrusions in recent months. Goodwin Procter, the global firm, disclosed its own cybersecurity incident on August 7. On August 14, Quinn Emanuel Urquhart & Sullivan said a social-engineering attack—a deceptive tactic used to manipulate individuals into giving up confidential access—had compromised a single user account and exposed stored files.

In May, London-based international firm Herbert Smith Freehills Kramer confirmed that unauthorized access to its systems exposed Social Security numbers, government-issued identification numbers, and confidential health records. An alleged May breach at Wilmer Cutler Pickering Hale and Dorr (WilmerHale) prompted a proposed class-action lawsuit from affected individuals, raising the stakes for corporate liability.

The same rise in sophisticated attacks against third-party custodians of data has appeared beyond the legal sector. Digital asset and cryptocurrency companies have faced breaches of customer databases through social engineering, bribery, and vendor supply chains. In May 2025, cryptocurrency exchange Coinbase disclosed that hackers had bribed overseas customer support agents to bypass security protocols and steal the personal data of 69,461 users.

The Coinbase data included names, physical addresses, phone numbers, and images of government-issued identification cards. The exchange confirmed that no passwords, private keys, or funds were compromised. Coinbase rejected a $20 million ransom demand and instead offered a $20 million bounty for information leading to the attackers’ arrest and conviction.

Hardware wallet manufacturers, which secure cryptocurrency offline, have also been exposed through external partners. In January 2026, Ledger confirmed that a breach at its e-commerce partner, Global-e, allowed unauthorized access to order data belonging to customers who had purchased devices on Ledger.com.

Taft Stettinius & Hollister detected unusual activity on its network in March 2026, ultimately exposing client Social Security numbers. Eckert Seamans Cherin & Mellott has faced ongoing lawsuits and legal scrutiny following disclosures of data security lapses.

In August, SafePal disclosed that a software vulnerability in an order-tracking plug-in exposed the shipping addresses, names, emails, phone numbers, and purchase details of roughly 39,798 customers. SafePal clarified that payment information and wallet credentials remained secure.

Most recently, Trezor reported that hackers compromised its third-party email service provider and used it to send fraudulent security alerts designed to trick users into revealing their recovery phrases.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *