Law Firm Cyberattacks: Evolving Risks and Uncertainty

By Canaan Suitt, J.D. | Reviewed by Andrew Leonatti | Last updated on September 15, 2026 Featuring practical insights from contributing attorneys Lisa J. Sotto and Kathryne (Kate) M. Morris

Cyberattacks against law firms are increasing, driven by the highly valuable data they hold and the growing sophistication of threat actors, including AI-enhanced social engineering tactics.

“We are facing an extremely malicious threat environment right now, with businesses in every industry sector susceptible to cyberattacks,” says Lisa Sotto, chair of Hunton’s global data, cyber, and privacy practice.

Within the legal industry, Sotto says, small and medium-sized firms are most vulnerable to cyber risks, due to a lack of dedicated cybersecurity resources.

Fighting the threat is an uphill battle. “After all, it only takes one successful attempt to access a law firm’s data. Threat actors don’t have to succeed that often; if they’re successful just once in tricking a law firm employee, they get access to all the data and files that employee had access to.”

Law firms can’t prevent cyberattacks. Getting targeted is inevitable. Law firms cannot control whether they are targeted, but they can control how they prepare for and respond to cyber threats. Up-to-date cybersecurity policies and ongoing staff training are non-negotiable for law firms to maintain cyber resilience.

“Every lawyer needs to appreciate how much it’s accelerating,” says Kate Morris, a technology transactions lawyer at Carrington Coleman in Dallas, Texas. “I especially think about smaller law firms that are dealing with really sensitive information. They’re fighting this battle now.”

Why Do Cybercriminals Target Law Firms?

Law firms are hubs of highly valuable information, holding confidential data about the many corporations and individuals they represent, including intellectual property, trade secrets, and financial records.

“For cybercriminals, this makes law firms prime targets,” says Morris. 

“Threat actors are targeting everyone and have supercharged their ability to attack with AI. They’re after all the information they can get, including encrypted data. The idea is that, with advances in quantum computing, human-encrypted information will become readable, so they collect it now and can use it one day.”

Law firms that fall victim to cyberattacks and data breaches can face huge financial losses, reputational damage, and legal fallout. “There’s been a trend toward astronomically high extortion payments, which further emboldens threat actors,” says Sotto.

“And there are mixed views on whether law firms should pay extortion demands. Law enforcement makes clear that they would like them not to. On the other hand, some clients may want the law firm to do everything it can to prevent data from being posted on the dedicated leak site these threat actors run. But making an extortion payment also carries stigma. It’s complicated.”

Sotto notes that cyber insurance is an important factor in deciding whether to pay out. “Law firms often have insurance that covers extortion payments.”

Do Your Due Diligence in Tech Transactions

Make sure your technology deal or license agreement is legally sound. Find an experienced tech transaction lawyer near you using the Super Lawyers directory.

Find a lawyer today

Cyber Threat Vectors and Tactics

One of the most common tactics used against law firms is phishing, where threat actors send fake messages to trick people into giving up sensitive information, such as passwords.

One threat actor active in the legal sector is Silent Ransom Group, aka “Luna Moth” and “Chatty Spider.” According to Sotto, the group likes to use vishing (voice phishing) — calling law firm staff, pretending to be someone in IT (using a spoofed phone number to make it look like an internal call), and tricking them into providing system access.

Cheap, easy-to-use AI-generated voice deepfakes can enhance — and automate — these vishing threats. “With respect to AI, we’re very concerned about deepfakes and voice cloning, though much of this is still done in the old-fashioned way,” Sotto says.

Personnel are routinely socially engineered in cyberattacks. Some see this as human failure. I don’t. Rather, I think it’s human nature to respond to a request in which somebody is deceiving you into thinking they’re being helpful: ‘Here’s this problem; I’m here to help.’

Lisa J. Sotto

Although cybercriminals’ tactics, as well as the security measures to prevent data breaches, involve sophisticated technology, humans remain the weakest link in cyber incidents.

“Personnel are routinely socially engineered in cyberattacks. Some see this as human failure. I don’t,” says Sotto.
”Rather, I think it’s human nature to respond to a request in which somebody is deceiving you into thinking they’re being helpful: ‘Here’s this problem; I’m here to help.'”

Certain situations can make personnel more vulnerable. “For example, sometimes we see less active lawyers being targeted, like counsels who might be in the office less and be less attuned to some of the security warnings that have been issued.”

No one has really had a choice; AI has just been integrated. And that is a huge issue, because that’s not a bad actor coming into your organization. That is one of your own service providers you’ve relied on who’s changed the services they’re providing you without a lot of notice…

Kathryne (Kate) M. Morris

In addition to law firm personnel, third-party service providers law firms use are also a significant piece of the puzzle putting firm data at risk, Sotto says. 

Morris notes that the rapid integration of AI into the tech law firms and their service providers use adds another twist. “Every organization’s technology stack has drastically changed in the last couple of years by the introduction of AI within services they were already providing,” she says.

“No one has really had a choice; AI has just been integrated. And that is a huge issue, because that’s not a bad actor coming into your organization. That is one of your own service providers you’ve relied on who’s changed the services they’re providing you without a lot of notice and without a lot of ability for even the biggest companies to configure what is happening within their own portals.”

Morris explains that generative and agentic AI systems all present data-leakage issues. “Zoom is a perfect example. Tons of law firms use Zoom. Then Zoom introduced all these new AI features, which you have to go into settings to turn off. Otherwise, they’re automatically on, start recording your client calls, and deliver you a transcript. No one ever bargained for that, or even asked for it.”

Furthermore, many generative AI systems use input data to train their systems, says Morris. And according to a recent ruling out of New York’s Southern District Court, United States v. Heppner, when a client enters confidential information into a public AI tool, it’s no longer protected by attorney-client privilege or the work product doctrine.

Thus, exposure of important information doesn’t have to involve a cyberattack; it can emanate from seemingly innocent workflows or efficiency gains involving AI tools. Clients’ data privacy can be compromised and legal strategies demolished.

Cyberattacks and AI: A Time of Great Uncertainty

Responding to cyber threats requires constant vigilance and agility. Every law firm must create and implement cybersecurity policies and training.

“The safeguards that firms put in place need to continue to evolve to meet the evolving threat environment. What was considered a reasonable safeguard 10 years ago may not be a reasonable safeguard today. With respect to social engineering, the best medicine is constant training and awareness of these sorts of attacks,” says Sotto.

“We are living in a time of unprecedented cybersecurity threats driven by artificial intelligence,” adds Morris. “Recent incidents targeting major AI platforms, including reported compromises by autonomous AI agents, may be a harbinger of a future in which AI systems are actively pitted against one another in the cybersecurity arena. 

“The uncomfortable truth is that traditional defensive measures are no longer sufficient. It’s a time of great uncertainty. But the threat landscape is evolving at a pace we have not seen before, and our security posture must evolve just as quickly.”

Was this helpful?

What do I do next?

Enter your location below to get connected with a qualified attorney today.

State Technology Transactions articles

0 suggestions available Use up and down arrow keys to navigate. Touch device users, explore by touch or with swipe gestures.

At Super Lawyers, we know legal issues can be stressful and confusing. We are committed to providing you with reliable legal information in a way that is easy to understand. Our legal resources pages are created by experienced attorney writers and writers that specialize in legal content in consultation with the top attorneys that make our Super Lawyers lists. We strive to present information in a neutral and unbiased way, so that you can make informed decisions based on your legal circumstances.

0 suggestions available Use up and down arrow keys to navigate. Touch device users, explore by touch or with swipe gestures.

Find top lawyers with confidence

The Super Lawyers patented selection process is peer influenced and research driven, selecting the top 5% of attorneys to the Super Lawyers lists each year. We know lawyers and make it easy to connect with them.

Find a lawyer near you