1 in 5 U.S. Law Firms Suffer Cyberattacks Amid Rising Threats

A Proton study finds 20% of U.S. law firms were hit by cyberattacks in the past year, highlighting gaps in breach response and the evolving risk landscape.

Key points:

  • One in five U.S. law firms reported being targeted in a cyberattack over the past year.
  • 8% of firms lost data or suffered exposure, while most lack clarity on legal breach obligations.
  • Experts warn that evolving threats demand stronger client confidentiality and incident readiness.

Twenty percent of U.S. law firms were hit by cyberattacks in the past 12 months, and nearly 1 in 10 lost or exposed sensitive data, according to a new study by Geneva-based Proton. The survey of 500 firms revealed widespread vulnerability, knowledge gaps, and escalating client pressure on firms to meet cybersecurity expectations.

While the size of the targeted firms was not disclosed, recent breaches involving Am Law 100 firms—including Fenwick & West, Taft Stettinius & Hollister, and global players like Kirkland & Ellis and Allen & Overy—highlight that no tier is immune.

Proton found that 65% of surveyed firms were unfamiliar with their legal obligations following a breach, and 42% were uncertain about their ability to recover post-incident. The findings expose a critical disconnect between risk awareness and preparedness across the sector.

Tristan Hall, a partner in CMS’s cybersecurity practice, noted the complexity of the modern threat landscape: “Attackers are increasingly targeting people and processes rather than just technology. Even multi-factor authentication, once a reliable safeguard, can now be bypassed through social engineering and technical exploitation.”

Recent warnings from the FBI spotlight criminal gangs like Luna Moth, which have targeted law firms under the guise of IT support, exfiltrating data related to M&A activity and litigation strategies. Ransom demands are often accompanied by threats to publish or leak files, with staff contacted directly to apply pressure.

“Law firms are extremely sensitive to breaches involving client data,” said Philip Tansley, a crisis management partner at Osborne Clarke. “The reputational and legal fallout of leaked court or transaction documents could be catastrophic.”

Proton's report suggests a growing dependence on digital platforms has contributed to the risk. Cloud adoption and remote collaboration tools have increased firms’ attack surfaces, often without commensurate increases in security spending or training.

In the U.K., the implications of poor cybersecurity were illustrated by the £60,000 fine imposed on DPP Law in April. Attackers accessed 32GB of highly sensitive data through an unprotected admin account, exploiting basic failures in account security.

Proton’s head of security, Patricia Egger, recommended technical and procedural controls, including end-to-end encryption, strict access privileges, and real-time device monitoring. “Firms should assume compromise is possible and design systems to minimize exposure when it happens,” she said.

Dechert’s global cyber practice chair, Brenda Sharton, framed the current situation as an “arms race.” While threat actors evolve, so too do defensive technologies, including AI-powered detection tools. But Sharton warned that attackers often exploit legacy systems or overlooked components—“the places organisations deprioritize, sometimes justifiably.”

CMS’s Hall emphasized that cybersecurity is now a precondition for client trust: “Firms must view confidentiality not only as a legal obligation but as a commercial imperative. Testing breach readiness should be as routine as reviewing contracts.”

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


Sixth Circuit Blocks FCC’s Effort to Restore Net Neutrality Rules

A U.S. appeals court ruled the Federal Communications Commission did not have legal authority to reinstate landmark net neutrality rules. FCC Chair Rosenworcel urged Congress to enact the laws, while industry groups praised the decision, citing anti-consumer concerns.

Jan 03, 2025
Read More
Special Visa Categories for Canadians
Special Visa Categories for Canadians

Despite the media attention surrounding immigration from Mexico, it’s important to remember that the United States shares a border to the north with Canada as well.

Aug 19, 2015
Read More
10 Steps to Starting Your Business
10 Steps to Starting Your Business

Starting a business requires many steps, and takes hard work and dedication. This guide covers ten things you should think about to increase your chances of success.

Mar 14, 2018
Read More
U.S. House Passes Bill to ByteDance - Divest TikTok or Face Ban
U.S. House Passes Bill to ByteDance - Divest TikTok or Face Ban

The U.S. House of Representatives passed a bill requiring TikTok's parent company ByteDance to divest its U.S. assets or face a ban, citing national security concerns over Chinese influence.

Mar 20, 2024
Read More
Surge in Data Breach Class Actions in 2023
Surge in Data Breach Class Actions in 2023

One of the key factors contributing to the surge is the increased sophistication of cybercriminal activities.

Oct 17, 2023
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.