Desk live·
ForensicPost
Breaches/Legal/File 26-0309

Two in Five Law Firms Were Breached, and Most Exposed Client Data

About 39% of law firms reported a breach in the past year, and among those, more than half exposed client information. A firm holds the material its clients most needed to keep private.

Constructed geometry · not a chart of case data
TargetLaw firms
ActorMultiple
D. Kennedy12 min readConfidence: medium2 sources reviewed

Sector research reports that around 39% of law firms experienced a breach in the past year, and that among breached firms more than half exposed client data. Reported attacks on the sector have risen sharply, and the average cost of a law firm breach is put near $5.08 million.

The Concentration Is Unusual Even By This Database’s Standards

A firm advising on a merger holds the deal before it is announced. A firm running litigation holds the strategy, the weaknesses and the internal assessment of the case. A firm handling a regulatory investigation holds the client’s own account of what went wrong.

These are not incidental records. They are material a client assembled specifically because it was too sensitive to handle alone, and handed to an organisation that is typically far smaller than they are.

The Size Mismatch Is The Structural Problem

A mid-sized firm advising large corporate clients has a fraction of their security capability and all of their most sensitive documents. That asymmetry is exactly what makes the sector attractive.

It is the same shape as the business-associate pattern filed at 26-0731 and the outsourced service desk at 26-0413: the data moves to whoever does the specialist work, and the security posture does not move with it.

Client Due Diligence Is Now The Pressure Point

The change worth noting is that corporate clients have begun auditing their firms’ security as a condition of instruction, in the way they audit other suppliers.

That is more likely to shift behaviour than professional guidance has, because it attaches a commercial consequence. A firm that loses a panel appointment over an authentication finding will act faster than one issued an ethics reminder.

How we reported this

This is a sector analysis file built on published research, listed below. Survey figures rely on self-reporting and definitions vary between studies. Corrections: corrections@forensicpost.com.

Sources
  1. Law firm data breach statistics 2026: client data, ransomware and legal cyber riskDeepstrike
  2. The latest law firm cyberattack statistics (2026)Programs.com
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary