Cyberattacks on Law Firms and Crypto Firms Surge as Data Breaches Double
- Law firms and cryptocurrency companies face a surge in sophisticated data breaches driven by phishing, social engineering, and third-party vendor vulnerabilities.
- BakerHostetler reported nearly 60 cybersecurity incidents involving law firms in 2025, almost double the 2024 caseload, with phishing accounting for 30% of incidents across industries.
- High-profile legal firms including Greenberg Traurig, Taft Stettinius & Hollister, and WilmerHale have disclosed breaches exposing sensitive client data, including Social Security numbers and health records.
- The cryptocurrency sector is also affected, with CoinbaseCOIN-- revealing a May 2025 incident where criminals bribed overseas support agents to steal personal data from nearly 70,000 users.
- These incidents underscore systemic security gaps in professional services and digital asset custodians, highlighting vulnerabilities in third-party integrations and human-centric attack vectors.
How Are Law Firms Experiencing Increased Cybersecurity Threats?
The legal sector is experiencing a significant increase in cyberattacks, with data breaches nearly doubling in 2025 compared to the previous year. BakerHostetler, a prominent law firm, handled nearly 60 cybersecurity incidents involving law firms in 2025, reflecting a sharp rise in targeted attacks . Phishing remains a primary vector for these breaches, accounting for 30% of incidents across various industries according to BakerHostetler’s 2026 Data Security Incident Response Report .
Several high-profile law firms have publicly disclosed recent security incidents. Greenberg Traurig reported that an unauthorized actor accessed and posted limited documents on the dark web, notifying affected clients of the breach . A Vermont notice identified exposed Social Security information among the compromised data, highlighting the sensitivity of the information at risk .
Other major firms have also faced similar challenges. In March 2026, Taft Stettinius & Hollister detected unusual activity that exposed client Social Security numbers . Herbert Smith Freehills Kramer reported unauthorized access in May that exposed Social Security numbers, government IDs, and health records . WilmerHale faced a proposed class action following an alleged May breach, indicating potential legal repercussions for firms failing to protect client data .
Goodwin Procter disclosed an incident on August 7, while Quinn Emanuel reported a social-engineering attack on August 14 that compromised one account and exposed stored files . These incidents collectively demonstrate a growing trend of data breaches targeting the legal sector, emphasizing increasing vulnerabilities in cybersecurity infrastructure .

What Security Vulnerabilities Are Exposed in the Crypto Sector?
The cryptocurrency sector is not immune to these rising security threats. Coinbase revealed in May 2025 that criminals bribed overseas support agents to steal personal data from nearly 70,000 users. Although no funds or private keys were compromised, the incident highlights the risk of human-centric attack vectors targeting customer support operations . Coinbase refused a $20 million ransom demand, underscoring the financial pressures and ethical dilemmas faced by digital asset exchanges .
Other cryptocurrency companies have also reported significant breaches. Ledger confirmed a breach via its e-commerce partner Global-e exposed customer order data in January 2026 . This incident illustrates the risks associated with third-party integrations, where vulnerabilities in partner systems can compromise customer data .
SafePal disclosed a plug-in flaw affecting nearly 40,000 customers, while Trezor reported phishing emails disguised as security alerts sent via a breached third-party email provider . These examples emphasize the growing risk to digital asset holders, particularly those relying on hardware wallets and third-party services for secure transactions .
Why Do These Breaches Matter for Investors and Markets?
The increasing frequency and sophistication of cyberattacks on law firms and crypto firms have broader implications for investors and markets. Sensitive client data, including Social Security numbers and financial information, is increasingly exposed, raising concerns about identity theft and fraud . Investors in professional services and digital asset companies may face reputational and financial risks associated with data breaches .
The reliance on third-party vendors and integrations introduces additional vulnerabilities that can be exploited by cybercriminals. Law firms and crypto companies must prioritize robust cybersecurity measures to protect client data and maintain trust . The potential for class action lawsuits and regulatory scrutiny adds to the financial liabilities associated with data breaches .
As cyber threats evolve, companies must adopt comprehensive security strategies that address both technical and human factors. Phishing and social engineering attacks remain prevalent, requiring ongoing employee training and awareness programs . The integration of advanced security technologies and continuous monitoring can help mitigate risks and enhance overall cybersecurity posture .
The trend of stolen documents hitting the dark web further complicates the security landscape for these industries. Law firms and crypto companies must remain vigilant and proactive in addressing cybersecurity challenges to protect sensitive information and maintain market confidence . The increasing volume of breaches underscores the need for industry-wide collaboration and shared best practices to combat cyber threats effectively .
Blending traditional trading wisdom with cutting-edge cryptocurrency insights.
Latest Articles
Stay ahead of the market.
Get curated U.S. market news, insights and key dates delivered to your inbox.



Comments
No comments yet