International law firm Greenberg Traurig has confirmed that a limited number of its internal documents appeared on the dark web after an unauthorized actor accessed the firm’s systems, the latest in a string of breaches that has hit some of the largest names in the legal industry throughout 2026.
The disclosure was first reported by Reuters on September 10. Greenberg Traurig, one of the world’s biggest law firms by headcount, described the number of exposed documents as limited, but the firm’s statement did not identify what the files contained, how many were taken, or how many clients or individuals may be affected. The company has not publicly named the attacker or detailed the method used to gain access.
For the crypto industry, the incident lands at an uncomfortable intersection. Law firms hold some of the most sensitive records in the sector — token structuring opinions, licensing applications, litigation strategy, and identifying information for founders and executives — and the Greenberg Traurig breach is only the newest entry in what security professionals describe as a sharp escalation of attacks on legal practices.
A year of breaches across the profession
The Greenberg Traurig disclosure did not come in isolation. According to Reuters reporting, several other major firms have confirmed similar incidents this year, each with a different attack profile.
In March, Taft Stettinius & Hollister detected unusual activity on one of its systems, an incident that ultimately exposed client Social Security numbers. In May, London-based Herbert Smith Freehills Kramer disclosed unauthorized access involving Social Security numbers, government identification numbers, and health records.
A separate alleged breach at WilmerHale, also disclosed in May, led to a proposed class action filed in July. The lawsuit concerns the alleged exposure of information held by the firm, though the filing of a complaint does not establish the allegations as fact.
Goodwin Procter disclosed an incident on August 7. Later that month, Quinn Emanuel acknowledged that a social-engineering attack had compromised a single account and exposed files stored within it. Social engineering relies on deceiving an employee into granting access rather than exploiting a technical software flaw, a distinction that matters because it is far harder to patch than a vulnerability.
The nature of the exposed records differs from case to case. Greenberg Traurig has described documents posted publicly on the dark web, while the disclosures from Taft and Herbert Smith Freehills Kramer identified specific categories of personal data. The available details do not establish that the Greenberg Traurig documents contained the same kinds of information reported in the other incidents.
The numbers behind the trend
Data from law firm BakerHostetler, which handles cybersecurity incident response for corporate clients, quantifies the escalation. The firm handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double the number it handled in 2024. That figure counts only matters BakerHostetler itself worked on, not every breach at a law firm during either year.
BakerHostetler’s 2026 incident-response report analyzed more than 1,250 data security incidents across industries in 2025. Phishing remained the leading identified cause, accounting for 30 percent of incidents, while outside vendors were implicated in 25 percent of the matters analyzed. Those two categories overlap heavily with how the recent law firm breaches have reportedly unfolded.
The report also tracked litigation follow-through. Class actions were filed in 14 percent of disclosed incidents in 2025, up from 9 percent in 2024. Among disclosed incidents in the dataset, lawsuits followed 68 of 482 cases in 2025, compared with 51 of 518 the previous year. The figures cover clients across several industries, with business and professional services — the category that includes law firms — ranking behind health care and finance and insurance among the sectors represented.
Parallel lessons from the crypto sector
The pattern is familiar to anyone tracking security incidents at crypto companies, where a string of disclosures has shown how personal details can be exposed even when a company insists that user funds and wallet credentials were never touched.
In May 2025, Coinbase disclosed that criminals bribed overseas support agents to obtain customer information. The breach affected 69,461 users and included names, addresses, phone numbers, and images of government identification documents. Coinbase said passwords, private keys, and customer funds were not compromised, rejected a 20 million USD ransom demand, and offered an equal reward for information leading to the attackers’ arrest and conviction.
Hardware wallet makers have reported a similar cluster of third-party incidents. In January, Ledger said unauthorized access at e-commerce partner Global-e exposed order information for some customers who bought products through Ledger.com. In August, SafePal said a flaw in an order-tracking plug-in exposed records belonging to roughly 39,798 customers, including names, email addresses, shipping addresses, phone numbers, and purchase details.
Trezor has disclosed two distinct incidents involving outside providers: exposure of data belonging to more than 80,000 customers through shipping partner ShipMonk, followed in September by a breach of its third-party email provider that was used to send phishing messages posing as urgent security alerts. The fake emails claimed a hardware flaw put users’ recovery phrases at risk. Trezor took down the domain used in the attempt. On the same day, BitBox warned users about impersonation emails and said its newsletter provider was likely compromised.
What it means
Both the legal and crypto sectors are converging on the same lesson: the perimeter that matters is no longer the firm’s own network but every vendor, plug-in, and support desk connected to it. With vendor involvement in a quarter of analyzed incidents and phishing in nearly a third, the attack surface is increasingly human and contractual rather than purely technical.
For clients of large law firms — including crypto companies that depend on them for regulatory navigation — the Greenberg Traurig disclosure is a reminder that the confidentiality chain extends well beyond the company itself, and that class action risk after a disclosure is rising year over year.
law firm breaches nearly doubling in a year and the firms still wont say what was taken. limited number of documents is doing a lot of heavy lifting in that statement
bet the actual number of files is way higher than limited. its always limited until someone dumps the full archive
Think about what a firm like this actually holds on crypto clients. Token structuring opinions, licensing applications, litigation strategy. That is a roadmap for attackers and competitors alike.
Greenberg Traurig calling it a limited number of documents is doing a lot of heavy lifting. limited until the ransom note drops
Same language every firm uses in week one. By week three it is always more extensive than initially determined
The Quinn Emanuel incident was a single account taken through social engineering. If one phished employee exposes files, imagine what a patient crew does with months of access.
taft said limited in march and it ended up being social security numbers. same script every single time
law firms are the softest target in crypto right now. token structuring opinions, founder KYC, litigation strategy, all behind some partner email password lol
founder KYC behind a partner email password is the one that gets me. thats not a breach, thats a filing cabinet with the door left open
founder KYC and token structuring opinions sitting in one place is exactly why these firms get picked. one box with the whole industry paperwork in it
taft in march, hsf in may, goodwin on august 7, quinn emanuel later that month, now greenberg traurig. the pace is accelerating and every statement says limited
five firms in eight months and the common phrase is still unauthorized actor. nobody will say ransomware out loud until the invoices leak