Desk live·
ForensicPost
Breaches/Legal/File 26-0422

Attorney-client Privilege Offers No Protection Against an Intruder Copying Files

Attorney-client privilege protects communications from compulsion. It offers nothing against an intruder copying them, and a breach can trigger ethics obligations of its own.

Constructed geometry · not a chart of case data
TargetPrivileged communications
ActorMultiple
S. Rosler11 min readConfidence: medium2 sources reviewed

Attorney-client privilege is one of the strongest protections in law. It prevents a court compelling disclosure of communications between a client and their lawyer, and it exists because legal advice is worthless if the client cannot be candid.

It protects against compulsion. It does not protect against copying, and the distinction is doing a great deal of unacknowledged work.

A Doctrine About Admissibility, Not Confidentiality

If an intruder takes privileged material and publishes it, the privilege has not been defeated in any legal sense. It simply never addressed that scenario. The information is out, and the protection was about what an opposing party could demand, not about what a third party could take.

Which means the practical confidentiality of privileged communications rests entirely on the firm’s technical controls — the least examined layer of a protection everybody treats as robust.

A Breach Carries Its Own Professional Consequences

Professional conduct rules on confidentiality — Rule 1.6 in the ABA model and its equivalents elsewhere — impose a duty to safeguard client information. A breach exposing client data can therefore generate an ethics complaint alongside the ordinary regulatory and contractual fallout.

That is unusual. In most sectors a breach is a data protection matter. In law it can also be a question of whether the practitioner met their professional obligations, which is a personal exposure rather than a corporate one.

What This Should Change

Firms tend to treat information security as an IT budget line. On this analysis it is closer to professional indemnity: a control on which a core duty depends, where failure attaches to individuals.

Framed that way, questions like whether the document management system enforces phishing-resistant authentication stop being technical preferences and become questions about whether the firm can keep the promise its clients are relying on.

How we reported this

This is an analysis file built on published legal-sector guidance, listed below. It is not legal advice; professional obligations vary by jurisdiction. Corrections: corrections@forensicpost.com.

Sources
  1. Attorney client privilege and legal IT 2026 guideCompassMSP
  2. Law firm data breach statistics 2026Deepstrike
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary