Summary

  • Greenberg Traurig reported unauthorized access to documents, which have surfaced on the dark web.
  • The firm informed impacted clients, with a Vermont notice revealing exposed Social Security details.
  • Other law firms, including WilmerHale and Eckert Seamans, have also reported data breaches and are facing lawsuits.

Greenberg Traurig, an international law firm, has announced that unauthorized individuals accessed a limited set of documents and subsequently posted them on the dark web, as reported by Reuters on Thursday.

This incident highlights a concerning trend of increasing data breaches targeting legal firms. The law firm BakerHostetler managed nearly 60 cybersecurity incidents related to law firms in 2025, which is nearly double the incidents reported in 2024, according to Reuters.

BakerHostetler’s 2026 Data Security Incident Response Report, released earlier this year, details over 1,250 incidents across various sectors in 2025, with phishing attacks constituting 30% of these breaches.

Reuters, several other law firms have reported data breaches. For instance, Taft Stettinius & Hollister identified atypical activity in March 2026 that exposed clients' Social Security numbers.

In May, the London-based firm Herbert Smith Freehills Kramer revealed that unauthorized access led to the exposure of Social Security numbers, government ID numbers, and health records. Additionally, a breach at WilmerHale in May resulted in a proposed class action lawsuit.

More recently, Goodwin Procter reported a security incident on August 7, and Quinn Emanuel disclosed an August 14 social-engineering attack that compromised an account through deceptive means, exposing stored files.

Breaches at Crypto Firms

In the cryptocurrency sector, breaches involving customer personal information have also come to light.

In May 2025, Coinbase revealed that criminals bribed overseas support staff to access personal data from 69,461 users, which included names, addresses, phone numbers, and government ID images. The platform confirmed that no funds, passwords, or private keys were compromised, and it rejected a $20 million ransom demand, instead offering that amount for information leading to the arrest of the attackers.

In January 2026, Ledger confirmed that a breach involving e-commerce partner Global-e compromised order data of some customers from Ledger.com.

“This incident involved unauthorized access to order data in Global-e information systems. Some of the data accessed related to customers who made purchases on Ledger.com using Global-e as a merchant,” a Ledger spokesperson stated to Decrypt.

In August, SafePal reported that a flaw in an order-tracking plug-in exposed personal information of approximately 39,798 customers, including names, emails, shipping addresses, phone numbers, and purchase details. The company assured that wallet credentials and payment information remained secure and that they had rectified the flaw and informed customers.

Earlier this week, Trezor disclosed that hackers breached its third-party email provider, sending phishing emails disguised as security alerts. These emails falsely claimed that a hardware flaw jeopardized users’ recovery phrases. Trezor stated it has taken down the malicious domain and is investigating the breach.

Daily Debrief Newsletter

Stay updated with the latest news stories, along with original features, podcasts, videos, and more.