Leading Australian Law Firm Struggles With Massive Cyberattack: A Growing Threat to the Legal Industry

A ransomware attack at HWL Ebsworth, one of Australia’s leading law firms, shows the importance of enforcing appropriate IT security measures.

Leading Australian Law Firm Struggles With Massive Cyberattack: A Growing Threat to the Legal Industry

In an era where digital information is increasingly becoming the lifeblood of organizations, the legal industry is no exception. Law firms, with their vast repositories of sensitive client and corporate data, are becoming lucrative targets for cybercriminals. The recent cyberattack on HWL Ebsworth, one of Australia’s leading law firms, underscores this growing threat.

On April 28, 2023, HWL Ebsworth fell victim to a ransomware attack orchestrated by the Russian-linked ALPHV/BlackCat ransomware group. On May 8, 2023, HWL Ebsworth communicated the incident to the Office of the Australian Information Commissioner (OAIC) – possibly a worrisome notification, since the OAIC is also a client of the firm. 

The firm initially learned about the attack through emails that were assumed to be spam. The attack resulted in the theft of client information and employee data. The hackers issued a ransom demand of $4.6M in bitcoin. They later published 1.1TB of the data they claimed to have stolen, which was later established to be 3.6TB worth of data.

The Impact

The cyberattack on HWL Ebsworth had far-reaching implications. It affected 65 Australian government departments and agencies that were clients of the firm. The national cybersecurity coordinator, Air Marshal Darren Goldie, revealed that some people and clients with personal information exposed in the hack have yet to be informed.

In response to the attack, HWL Ebsworth engaged McGrathNicol to investigate the incident and undertake containment and remediation actions. HWL Ebsworth has dedicated more than 5,000 hours and a quarter of a million dollars to combatting the hacking incident. After 16 weeks of support, the Australian government’s formal coordinated response to the incident ended, with HWL Ebsworth now able to manage its response without formal assistance from the Australian government.

A Growing Threat to the Legal Industry

The HWL Ebsworth incident is a stark reminder of the growing cyber threats facing the legal industry. Law firms handle vast amounts of sensitive client and corporate data, making them attractive targets for cybercriminals. Furthermore, many law firms are still using outdated IT systems and are slow to adopt cybersecurity policies, making them easy targets for hackers.

Basic security measures like using up-to-date security software, using current versions of operating systems and software, promptly applying patches to the operating system and all application software, employing effective backup, and training of attorneys and staff, can help protect against these kinds of threats. As the threat landscape continues to evolve, the legal industry must stay one step ahead to safeguard its data and maintain the trust of its clients.

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


Know Your Options: Inappropriate Job Interview Questions
Know Your Options: Inappropriate Job Interview Questions

When interviewing for your dream job, it can feel counterintuitive to not answer every question asked of you. However, some seemingly innocuous questions are actually quite inappropriate (and sometimes illegal) when asked during a job interview. Regardless of intent, here is a guide on how to handle these types of questions.

Apr 22, 2020
Read More
Community Perspectives: With current inflation at 7.7% and a recession likely, how is your team handling rate increases in 2023?
Community Perspectives: With current inflation at 7.7% and a recession likely, how is your team handling rate increases in 2023?

In-house legal professionals talk about how their legal teams are handling the economic downturn and inflation challenges with regards to compensation.

Dec 15, 2022
Read More
Legal.io Webinar Series: Sales and Commercial Counsel Partnership
Legal.io Webinar Series: Sales and Commercial Counsel Partnership

In our latest webinar, Jacob True (Senior Managing Corporate Counsel at ServiceNow), Amanda Gray Williams (Commercial Counsel at Datadog), and Robert Graham (Director, Commercial Counsel at Fivetran) engaged in an insightful conversation exploring the intricacies of the sales and commercial counsel partnership. Gain valuable insights into optimizing the relationship between sales and legal, learning key strategies to enhance deal velocity, and discover the tools and processes that contribute to successful collaboration. Watch our on-demand webinar to unlock the benefits of fostering a strong sales and legal alliance, ultimately accelerating deal cycles and fostering business success.

Jan 08, 2024
Read More
GPT-4's Potential In e-Discovery and Legal Document Review
GPT-4's Potential In e-Discovery and Legal Document Review

Sidley Austin, a leading law firm, recently undertook a groundbreaking experiment to evaluate the efficacy of GPT-4, the latest generative AI model from OpenAI, in the realm of e-discovery and document review. This article delves into their findings, shedding light on both the advantages and limitations of employing GPT-4 for legal document review.

Dec 14, 2023
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.