Desk live·
ForensicPost
Breaches/Legal/File 26-0313

The Client Portal Is Where the Documents and the Weak Authentication Meet

Reporting identifies unencrypted client portals and weak multi-factor authentication as the recurring weaknesses in legal sector attacks. The portal exists because clients demanded convenience.

Constructed geometry · not a chart of case data
TargetLaw firm client portals
ActorMultiple
D. Kennedy10 min readConfidence: medium2 sources reviewed

Sector reporting identifies a consistent pattern in law firm attacks: client-facing document portals with weak or optional multi-factor authentication.

The portal is not an oversight. It exists because clients wanted to stop emailing documents, which was a genuine security improvement over the alternative.

The Access Population Is The Difficulty

A firm can enforce strong authentication on its own staff. A portal serves the client’s people — general counsel, finance, executives at organisations the firm does not administer.

Enforcing hardware-backed authentication on those users means a project inside every client organisation. Firms compete on responsiveness, so the friction usually loses, and the control ends up optional.

What The Portal Contains

A matter portal holds the working documents for a live engagement: draft agreements, discovery material, valuation models, board papers. It is organised by matter, which is convenient for the client and equally convenient for anyone else who reaches it.

This desk filed the same shape at Salesforce Experience Cloud in 26-0314. A portal built to share selected material with external parties, whose permission model nobody has audited since launch, is a recurring architecture with a recurring outcome.

The Economics Point One Way

The average breach cost cited for the sector — around $5.08 million — sits against the cost of enforcing phishing-resistant authentication across a client base, which is measured in inconvenience rather than millions.

The obstacle is not budget. It is that the person who would have to insist is also the person selling to the client.

How we reported this

This is an analysis file built on published sector reporting, listed below. It describes a general pattern rather than any named firm. Corrections: corrections@forensicpost.com.

Sources
  1. The latest law firm cyberattack statistics (2026)Programs.com
  2. 2026 law firm data security guide: how to keep your law firm secureClio
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary