Greenberg Traurig data breach puts law firm cyber risks in focus
Greenberg Traurig said documents were posted on the dark web as one incident-response firm reported nearly 60 law-firm cases in 2025.
By Theo Nakamura · Staff Writer
· 3 min read
The Greenberg Traurig data breach involved an unauthorized actor accessing a limited number of documents and posting them on the dark web, the firm told Reuters. Greenberg Traurig said it notified a small number of affected clients, while a Vermont breach notice reported that Social Security information was exposed.
The disclosure arrives as legal practices report a series of cyber incidents. For people and businesses working with law firms, the immediate point is that legal advisers often hold confidential material tied to transactions, disputes and internal reviews, making a breach harder to contain and assess.
Greenberg Traurig, a firm with more than 3,200 lawyers, said its own systems were not compromised or breached and that its operations continued without disruption. That assertion sits alongside the firm’s statement that an unauthorized actor accessed documents, a distinction the firm made in its account to Reuters.
What happened in the Greenberg Traurig data breach?
According to Reuters, Greenberg Traurig said the actor accessed only a limited number of documents, then posted them on the dark web. The firm did not disclose the overall number of people affected in the reporting cited by Reuters. It said a small number of clients had been notified.
Reuters also reported that Greenberg Traurig filed a notice with Vermont’s attorney general stating that Social Security information was exposed. The available reporting does not establish whether that information was contained in the documents posted online.
The nearly doubled figure is not a count of every attack
The headline figure behind the wider trend needs a careful read. BakerHostetler said its digital-assets and data-management teams handled nearly 60 law-firm cyber incidents in 2025, almost twice the number they handled in 2024.
That is a measure of BakerHostetler’s incident-response caseload, not a complete tally of cyberattacks across the legal industry. Still, the firm said law practices make appealing targets because they possess confidential information related to pending transactions, active litigation and internal investigations.
The same concentration of records can also make an incident complex: the material may relate to a firm’s own operations, its clients or matters involving other parties.
Why social engineering is showing up in recent law-firm incidents
Several other disclosures reported by Reuters involved social engineering, a technique in which attackers manipulate people into revealing information or allowing access to protected systems.
- Eckert Seamans disclosed an August incident after an attorney was targeted in a social-engineering attack, according to proposed federal class-action complaints. The complaints allege unauthorized access to a limited set of files and exposure of dates of birth and Social Security numbers. The allegations have not established liability or the full scope of harm.
- Quinn Emanuel and McDermott Will & Schulte also recently disclosed social-engineering-related breaches, Reuters reported. McDermott described an isolated incident involving one user and a limited number of documents. Quinn said a limited number of client documents were affected and that it had informed affected parties.
The disclosures add to several recent reported incidents involving firms entrusted with confidential business and personal records. They also show why the BakerHostetler figure should be read as a useful signal from one response provider, rather than a sectorwide attack rate.
Read Reuters’ reporting on the Greenberg Traurig and Eckert Seamans disclosures.
This story draws on original reporting from Decrypt.