1 in 5 U.S. Law Firms Suffer Cyberattacks Amid Rising Threats

A Proton study finds 20% of U.S. law firms were hit by cyberattacks in the past year, highlighting gaps in breach response and the evolving risk landscape.

Key points:

  • One in five U.S. law firms reported being targeted in a cyberattack over the past year.
  • 8% of firms lost data or suffered exposure, while most lack clarity on legal breach obligations.
  • Experts warn that evolving threats demand stronger client confidentiality and incident readiness.

Twenty percent of U.S. law firms were hit by cyberattacks in the past 12 months, and nearly 1 in 10 lost or exposed sensitive data, according to a new study by Geneva-based Proton. The survey of 500 firms revealed widespread vulnerability, knowledge gaps, and escalating client pressure on firms to meet cybersecurity expectations.

While the size of the targeted firms was not disclosed, recent breaches involving Am Law 100 firms—including Fenwick & West, Taft Stettinius & Hollister, and global players like Kirkland & Ellis and Allen & Overy—highlight that no tier is immune.

Proton found that 65% of surveyed firms were unfamiliar with their legal obligations following a breach, and 42% were uncertain about their ability to recover post-incident. The findings expose a critical disconnect between risk awareness and preparedness across the sector.

Tristan Hall, a partner in CMS’s cybersecurity practice, noted the complexity of the modern threat landscape: “Attackers are increasingly targeting people and processes rather than just technology. Even multi-factor authentication, once a reliable safeguard, can now be bypassed through social engineering and technical exploitation.”

Recent warnings from the FBI spotlight criminal gangs like Luna Moth, which have targeted law firms under the guise of IT support, exfiltrating data related to M&A activity and litigation strategies. Ransom demands are often accompanied by threats to publish or leak files, with staff contacted directly to apply pressure.

“Law firms are extremely sensitive to breaches involving client data,” said Philip Tansley, a crisis management partner at Osborne Clarke. “The reputational and legal fallout of leaked court or transaction documents could be catastrophic.”

Proton's report suggests a growing dependence on digital platforms has contributed to the risk. Cloud adoption and remote collaboration tools have increased firms’ attack surfaces, often without commensurate increases in security spending or training.

In the U.K., the implications of poor cybersecurity were illustrated by the £60,000 fine imposed on DPP Law in April. Attackers accessed 32GB of highly sensitive data through an unprotected admin account, exploiting basic failures in account security.

Proton’s head of security, Patricia Egger, recommended technical and procedural controls, including end-to-end encryption, strict access privileges, and real-time device monitoring. “Firms should assume compromise is possible and design systems to minimize exposure when it happens,” she said.

Dechert’s global cyber practice chair, Brenda Sharton, framed the current situation as an “arms race.” While threat actors evolve, so too do defensive technologies, including AI-powered detection tools. But Sharton warned that attackers often exploit legacy systems or overlooked components—“the places organisations deprioritize, sometimes justifiably.”

CMS’s Hall emphasized that cybersecurity is now a precondition for client trust: “Firms must view confidentiality not only as a legal obligation but as a commercial imperative. Testing breach readiness should be as routine as reviewing contracts.”

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


Legal.io Newsletter - April 15, 2022
Legal.io Newsletter - April 15, 2022

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech.

Apr 15, 2022
Read More
Big Shifts in BigLaw: A&O Shearman Merger, Mayer Brown China Exit
Big Shifts in BigLaw: A&O Shearman Merger, Mayer Brown China Exit

The merger of A&O + Shearman & Sterling creates a global legal powerhouse with $3.5B in revenue. Meanwhile, Mayer Brown is reportedly scaling back its operations in Greater China.

May 02, 2024
Read More
Community Spotlight: Kim Perry, Legal Operations Principal at Blackbaud
Community Spotlight: Kim Perry, Legal Operations Principal at Blackbaud

Join our host and CEO, Pieter Gunst, as he dives into the career journey of Kim Perry, Legal Operations Principal at Blackbaud.

Feb 16, 2023
Read More
The Evolution of eDiscovery in Legal Operations
The Evolution of eDiscovery in Legal Operations

Understanding the challenges and embracing the opportunities of an ever-changing legal landscape.

Sep 25, 2023
Read More
California’s February 2025 Bar Exam Sees Record-High 56% Pass Rate

The February 2025 California bar exam saw a record 56% pass rate, aided by a Supreme Court-ordered score adjustment and bonuses for prior test participants.

May 05, 2025
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.