About
Law Firm Cybersecurity

Law Firm Cybersecurity

Tracking Law Firm Cybersecurity legal and regulatory developments.

1 entry in Legal Intelligence Tracker

LawSnap Briefing Updated October 7, 2026

State of play.

  • A wave of Am Law 100 and major firm breaches has made 2026 a defining year for law firm cybersecurity liability. Weil Gotshal, WilmerHale, Blank Rome, HSF Kramer, Taft, and Goodwin Procter have all disclosed incidents, with attackers uploading client files to external storage, exposing Social Security numbers and health records, and exploiting social engineering against attorneys .
  • Plaintiffs' counsel is monitoring firm breach disclosures in real time and filing class actions within days. The WilmerHale suit was filed within days of public disclosure; the Blank Rome actions followed within weeks of the breach becoming public .
  • Procedural barriers are providing temporary shelter but not resolution. The Blank Rome federal suits were voluntarily dismissed after the court raised jurisdictional questions -- plaintiffs withdrew rather than litigate the threshold, leaving refiling in a different forum as the likely next move .
  • BakerHostetler's 2026 Data Security Incident Response Report documents a rising ransomware and cyberattack trend against law firms specifically, giving plaintiffs' counsel and regulators a published baseline against which to measure firm preparedness .
  • For counsel advising law firm clients or managing their own firm's risk, the practical baseline is that a breach at a major firm now triggers class action filings within days, state AG notification obligations, and potential client notification duties simultaneously -- and the Blank Rome social engineering vector (IT impersonation leading an attorney to upload files to an unauthorized Google Drive) is a known, FBI-warned attack pattern that courts may treat as a per se failure of reasonable care.

Where things stand.

  • Social engineering is the dominant attack vector in documented 2026 firm breaches. The Blank Rome breach involved a cybercriminal impersonating IT staff and tricking an attorney into uploading sensitive files to an unauthorized external Google Drive -- a technique the FBI has previously warned the legal profession about . The Weil Gotshal incident similarly involved client files uploaded to external cloud storage .
  • State AG breach notification filings are the primary regulatory trigger. HSF Kramer filed with the Vermont AG; state-by-state notification obligations are the immediate compliance vector firms face post-incident .
  • Negligence, breach of fiduciary duty, and consumer protection statutes are the pleading template. The Blank Rome complaints allege negligence, breach of contract, breach of fiduciary duty, HIPAA violations, and FTC Act violations -- a multi-theory approach that gives plaintiffs multiple paths to survive motions to dismiss .
  • Ransomware and cyberattack frequency against law firms is rising, with the BakerHostetler 2026 DSIR Report documenting the trend and providing a published industry benchmark .
  • Privilege and confidentiality implications of exfiltrated client files remain unresolved doctrine. The Weil incident raises the question of whether privilege attaches to documents that have been exfiltrated and published externally -- a question courts have not uniformly addressed .
  • Market competition for cybersecurity and privacy counsel is intensifying. Cooley's hire of a former Hunton Andrews Kurth partner to lead its New York cyber, data, and privacy practice signals that firms are investing in this capability as both a client service and a competitive differentiator .
  • Weil reportedly paid up to $20M to cybercriminals (Luna Moth) to protect client data, a ransom payment that raises its own set of legal, ethical, and insurance questions for firms facing similar demands .

Latest developments.

Active questions and open splits.

  • What standard of care applies to law firm cybersecurity? The Blank Rome complaints target failure to train staff on social engineering -- a known FBI-warned vector -- as the negligence hook. Whether courts will treat inadequate social engineering training as a per se breach of reasonable care, or require expert testimony on industry standards, is the central liability question across these cases .
  • Jurisdiction and venue for law firm breach class actions. The Blank Rome dismissals show that federal jurisdiction is not automatic even with 57,000+ affected clients -- plaintiffs withdrew rather than litigate the threshold, suggesting the jurisdictional theory was weak. Where these cases ultimately land (state court, different federal district, or consolidated MDL) will shape the litigation environment .
  • Privilege status of exfiltrated client documents. When attackers exfiltrate and publish privileged client files, whether privilege is waived -- and whether the firm bears liability for that waiver -- is unresolved. The Weil incident puts this squarely in play .
  • Ransom payment ethics and disclosure obligations. Weil's reported $20M payment to Luna Moth raises questions about whether firms have disclosure obligations to clients, bar authorities, or insurers when they pay ransoms -- and whether payment constitutes a sanctionable act under OFAC or state bar rules .
  • Scope of fiduciary duty in data security. Plaintiffs are pleading breach of fiduciary duty alongside negligence, arguing the attorney-client relationship imposes a higher standard than ordinary data custodians. No appellate court has squarely addressed whether the fiduciary duty extends to cybersecurity practices .
  • HIPAA and FTC Act as liability multipliers. The Blank Rome complaints invoke both HIPAA and the FTC Act -- statutes not traditionally applied to law firms -- as bases for liability. Whether courts accept these theories for firms that hold health-related client data as incidental custodians is unsettled .

What to watch.

  • Whether Blank Rome plaintiffs refile in state court or a different federal district, and what jurisdictional theory they advance on refiling.
  • Whether the WilmerHale D.C. class action survives a motion to dismiss -- the first appellate-level test of the negligent-security theory against a major firm.
  • Whether any state bar issues formal cybersecurity guidance or amends professional conduct rules in response to the 2026 breach wave.
  • Whether the Weil ransom payment triggers OFAC scrutiny, bar disciplinary proceedings, or insurance coverage disputes -- any of which would set precedent for firm ransom decisions.
  • Whether additional Am Law 100 firms disclose breaches from the same May 2026 attack window, suggesting a coordinated campaign against the sector.
  • Whether plaintiffs' counsel consolidates the WilmerHale, HSF Kramer, and related actions into a coordinated MDL or parallel state-court strategy.

1 Contributing Entry

WilmerHale Faces Class Action After Employee Disclosed Client Data

WilmerHale faced a proposed class action lawsuit filed this week in U.S. District Court for the District of Columbia over a May 8, 2026 data incident in which a firm employee disclosed sensitive client information to an unauthorized third party who had misrepresented their identity. The breach exposed names and Social Security numbers of thousands of clients. Nevada resident Jason Perry filed the suit, styled Perry v. Wilmer Cutler Pickering Hale & Dorr LLP, No. 1:26-cv-02470, seeking negligence and contract damages on behalf of affected clients.

mail Subscribe to Law Firm Cybersecurity email updates

Primary sources. No fluff. Straight to your inbox.

Also on LawSnap