Herbert Smith Freehills Kramer, Goodwin Procter, Blank Rome and More Disclose Data Breaches as Law Firm Cyberattacks Continue

Table of Contents

At least three major law firms—Herbert Smith Freehills Kramer, Goodwin Procter, and  Stettinius & Hollister—disclosed data breaches to U.S. state regulators in early August 2026, adding to a growing list of legal industry cyber incidents this year. The disclosures underscore the persistent targeting of law firms, which hold large volumes of sensitive client, employee, and litigation-related information.

Herbert Smith Freehills Kramer, a global firm with more than 2,700 lawyers, reported that it became aware of a security incident in late May. According to a regulatory filing with the Vermont attorney general, the firm’s investigation found unauthorized access to a “limited portion” of its systems that month. Categories of data involved included Social Security numbers, government identification numbers, and health records.

In a statement, the firm said: “We experienced an incident earlier this year in a part of our US IT environment which was investigated and contained. The small number of people affected have been notified.”

Additional Firm Disclosures

Goodwin Procter and Stettinius & Hollister also notified state regulators of breaches during the same period.

Goodwin Procter stated that it “identified and responded to a limited data security incident.” The firm said it notified the limited number of clients whose data was involved, as well as individuals as required by applicable law. Separate reporting indicated the incident involved an employee being deceived into providing credentials to an unauthorized party, after which the firm disabled the account, eliminated access, and engaged third-party experts.

This is on the heels of the news about Blank Rome and other law firms being targeted. A call with one of the top DC firms that works with Captain Compliance said this is becomming more common with Microsoft Team Meetings scheduled with fake prospective clients, screen share requests happening with suspicious links and it only takes one connected computer to fall for it.

Part of a Broader Pattern

These incidents add to a series of cyberattacks against law firms in 2026. Other firms that have reported breaches in recent months include WilmerHale, Jones Day, and Wiley Rein. WilmerHale has faced class-action lawsuits related to its incident and retained outside counsel to defend against the claims. In a prior statement, WilmerHale said an unauthorized third party that has been targeting firms across the legal industry obtained a limited set of information from the firm.

Industry reporting has also noted that some firms, including Goodwin Procter, Weil Gotshal & Manges, and WilmerHale, have reportedly paid substantial sums in connection with data theft incidents, though the firms have not publicly confirmed those details.

Law firms remain attractive targets because of the confidential corporate, litigation, personal, and financial data they maintain. Unauthorized access can expose not only employee records but also highly sensitive client information, creating both regulatory notification obligations and potential litigation exposure.

Compliance and Risk Implications

The recent wave of disclosures reinforces several ongoing challenges for the legal sector:

  • Credential-based attacks continue to succeed, including through social engineering of individual employees.
  • Limited-scope incidents can still involve high-sensitivity data such as Social Security numbers, government IDs, and health records.
  • Notification obligations under state data breach laws require timely assessment of the data involved and outreach to affected individuals and regulators.
  • Client data exposure, even when described as limited, raises professional responsibility, contractual, and reputational considerations.

Firms are under pressure to strengthen access controls, improve detection of anomalous activity, test incident response plans, and ensure that employee training addresses current social-engineering tactics. The frequency of reported incidents suggests that baseline security measures alone are not sufficient against determined threat actors targeting the legal industry.

Law Firm Breach Disclosures About Themselves

The cluster of disclosures from Herbert Smith Freehills Kramer, Goodwin Procter, and another national firm all in a single week illustrates that cyber risk remains an active operational and compliance issue for law firms of all sizes. As more firms report incidents and related litigation proceeds, pressure is likely to increase for stronger technical controls, more rigorous vendor and access management, and clearer communication with clients about how their data is protected.

Organizations that handle sensitive professional and personal data—whether law firms or their clients—should treat these disclosures as a reminder to review incident response readiness, data inventory practices, and the effectiveness of existing safeguards against credential theft and unauthorized system access.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.