Please also note if anybody from WilmerHale reads this that the website has a cookie consent banner engaging in a dark pattern and please reach out to one of our team members regarding the cookie consent to have it remediated.

Law firms have spent years advising clients about ransomware, data breach notification, privacy class actions, regulatory investigations, cyber insurance, vendor risk, and incident response.
Increasingly, those same firms are finding themselves on the other side of the complaint and numerous law firms have been targets of late so please take extra precaution with your privacy and security.
Now law firms are attacking other law firms something we did not see at this level until recently. While we want everybody to get along and work through their issues on July 14, 2026, a proposed class action was filed against Wilmer Cutler Pickering Hale and Dorr in federal court in Washington, D.C. The lawsuit alleges that a May cyberattack exposed personal information maintained by the firm, including names and Social Security numbers. The plaintiff seeks to represent what the complaint describes as thousands of similarly situated individuals.
WilmerHale has said an unauthorized third party targeting firms across the legal industry obtained a limited set of information. According to the firm, the incident was isolated, the attacker did not directly access its systems or network, and it has found no evidence that the information was misused or disseminated. Those statements matter, as do the unresolved allegations in the complaint. A newly filed lawsuit is not a finding that the firm violated a law or failed to maintain reasonable safeguards.
But the larger story is no longer about one firm or one incident.
WilmerHale joins a growing list of prominent law firms that have recently faced cyberattacks, breach notifications, and lawsuits alleging that client, investor, employee, or other personal information was improperly exposed.
The trend should be a warning to every participant in the legal and privacy industries.
A law firm’s obligation to protect information does not begin and end with attorney-client privilege. It includes the full privacy lifecycle: what the firm collects, why it collects it, where it stores it, which vendors receive it, who can access it, how long it is retained, how changes are monitored, and how the firm responds when something goes wrong.
Cybersecurity is part of that responsibility. It is not the entire responsibility.
The WilmerHale Lawsuit Is Part of a Wider Pattern
The recent series of law firm incidents makes it increasingly difficult to dismiss any one attack as an isolated event.
Blank Rome was sued in July 2026 after a breach reportedly exposed personal information associated with more than 57,000 people. The lawsuits allege that the compromised information included sensitive data maintained by the firm. Blank Rome is only one of several large firms facing similar claims.
In May 2026, Wiley Rein was named in a proposed class action alleging that sensitive personal information had been stolen in an incident attributed in the complaint to hackers believed to be affiliated with the Chinese government. The lawsuit sought to represent potentially thousands of affected individuals.
Pillsbury Winthrop Shaw Pittman faced proposed class litigation over an April 2025 incident that allegedly exposed names, Social Security numbers, addresses, birth dates, and financial information. Pillsbury reportedly attributed the event to sophisticated social engineering involving a compromised user account and said it acted to block the intrusion and strengthen safeguards.
Fried Frank was sued in connection with an incident involving information associated with Goldman Sachs investment clients. Other firms, including Fox Rothschild, Kelley Drye, Gunster, Orrick, and Bryan Cave Leighton Paisner, have also faced breach litigation or settlements in recent years.
These cases involve different facts, different systems, different information, and different alleged attack methods. They should not be treated as proof that every affected firm made the same mistake—or any legally actionable mistake.
Collectively, however, they show that law firm data has become a persistent target and that a cyber incident can quickly transform a firm from legal adviser into class-action defendant.
Why Attackers Target Law Firms
Cybercriminals do not target law firms because lawyers are uniquely careless. They target law firms because the information inside them can be exceptionally valuable.
A single firm may possess data belonging to hundreds or thousands of clients. Its systems can contain:
- Social Security numbers and government identifiers
- Financial account and investment information
- Medical records
- Employment and compensation records
- Litigation strategy
- Internal investigation materials
- Merger and acquisition plans
- Intellectual property
- Trade secrets
- Regulatory correspondence
- Criminal and civil investigative information
- Settlement discussions
- Insurance records
- Employee and applicant information
- Privileged communications
- Discovery files containing data about nonclients
That concentration creates a multiplier effect.
An attacker that compromises one company may gain access to information about that company. An attacker that compromises a major law firm may gain information involving many companies, executives, employees, investors, witnesses, counterparties, and government matters.
The law firm becomes a potentially efficient route into an entire network of valuable relationships.
Confidentiality Does Not Create Technical Protection
Attorney-client privilege and professional confidentiality are legal doctrines. They do not encrypt a file, prevent credential theft, restrict a subcontractor, identify an abandoned database, or stop an employee from approving a fraudulent multifactor-authentication request.
Attackers are not deterred because the information they want is privileged.
In some cases, privilege may make the information more attractive. Legal files can reveal what a company fears, what it intends to do, where its vulnerabilities are, how it plans to negotiate, and what it believes its legal exposure may be.
That information can be useful for extortion, insider trading, commercial espionage, litigation strategy, identity theft, political intelligence, or state-sponsored operations.
Law Firms Operate Under Constant Time Pressure
Legal work rewards speed and responsiveness. Lawyers regularly receive urgent document requests, unexpected attachments, revised deal papers, court filings, remote-access requests, signature links, shared folders, and communications from unfamiliar parties.
Those workflows create opportunities for social engineering.
Attackers can impersonate clients, internal support personnel, opposing counsel, courts, vendors, prospective employees, consultants, or deal participants. The message does not always need to appear obviously suspicious. In a busy legal environment, urgency itself can make a fraudulent request seem normal.
The FBI has specifically warned that the Silent Ransom Group has targeted law firms using IT-themed social engineering. The FBI described tactics that can include calls from people impersonating technical support and, in some reported scenarios, an individual appearing at an office while posing as an IT worker and attempting to use a storage device to steal data.
Separately, the FBI investigated a series of suspected intrusions targeting prominent U.S. law firms in 2025. Williams & Connolly confirmed that attackers had accessed some of its systems, although it did not publicly attribute the incident to China.
These are not ordinary lost-laptop scenarios. The threat environment can include organized criminal groups, experienced social engineers, commercial espionage, and nation-state interests.
A Data Breach Is Not Only a Cybersecurity Failure
Law firm breach discussions frequently focus on security controls:
- Was multifactor authentication enabled?
- Was software patched?
- Were systems segmented?
- Were endpoint alerts functioning?
- How did the attacker obtain access?
- How quickly was the intrusion contained?
Those are essential questions. But privacy governance asks an additional set of questions:
- Why did the firm possess the compromised information?
- Was all of it still necessary?
- How long had it been retained?
- Was it associated with a current matter?
- Were copies stored in multiple systems?
- Which vendors and subprocessors could access it?
- Did access permissions match current job responsibilities?
- Could sensitive information have been tokenized, redacted, or segregated?
- Did the firm know which individuals and jurisdictions were affected?
- Were privacy notices and contractual representations accurate?
- Could the firm identify affected records without weeks of manual reconstruction?
Security controls are intended to reduce the likelihood of unauthorized access.
Privacy controls reduce both the likelihood and the consequences.
A company cannot expose data it never collected. An attacker cannot steal an unnecessary duplicate that was securely deleted. A former employee cannot access a matter from which permissions were removed. A compromised vendor cannot disclose information it was never permitted to receive.
This is why data minimization is not an abstract privacy principle. It is breach-loss containment.
The Size of a Breach Is Often Determined Before the Intrusion
Organizations often think the breach begins when an attacker enters the environment.
Operationally, the incident may begin months or years earlier.
Its eventual impact may already have been shaped by decisions involving:
- Indefinite document retention
- Uncontrolled email archives
- Matter files retained beyond legal or business requirements
- Shared drives without clear ownership
- Excessive administrative privileges
- Dormant user accounts
- Untracked downloads
- Unapproved cloud tools
- Duplicate discovery databases
- Legacy client portals
- Vendor access that was never terminated
- Sensitive attachments copied across email chains
- Personal information collected “just in case”
When a firm retains every file forever, the attacker benefits from every prior matter, former client, departed employee, inherited database, and forgotten archive.
Legal retention requirements are real. Litigation holds, professional obligations, statutes of limitation, insurance requirements, client instructions, and defensibility concerns may require firms to preserve information.
But “some information must be retained” is not the same as “all information should be retained indefinitely.”
A mature privacy program identifies the legal basis for retention, applies holds where necessary, disposes of information when the purpose expires, and documents the exceptions.
Protecting Client Information Is Also an Ethical Obligation
The American Bar Association’s Model Rule 1.6(c) states that a lawyer must make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to a client’s representation.
The rule does not impose strict liability for every successful attack. The accompanying commentary explains that reasonableness may depend on the sensitivity of the information, the likelihood of disclosure without additional safeguards, the cost and difficulty of implementing protections, and the effect those safeguards may have on the lawyer’s ability to represent the client.
ABA Formal Opinion 483 addresses lawyers’ responsibilities after an electronic data breach or cyberattack. It connects breach response to duties involving competence, confidentiality, communication, supervision, and safeguarding client property.
The opinion states that when a lawyer knows or reasonably should know that a breach has occurred, the lawyer must evaluate notification responsibilities. It also concludes that an obligation exists to communicate with current clients when a breach involves or has a substantial likelihood of involving material client confidential information.
The opinion further directs lawyers to evaluate applicable statutory and regulatory notification requirements when personally identifiable information is compromised. Importantly, it encourages firms to actively manage the amount of confidential and personally identifiable information they maintain and to consider limiting its receipt, possession, and retention when there is no ethical, statutory, or legal obligation to keep it.
ABA opinions and Model Rules are not substitutes for the professional-conduct rules, statutes, and judicial decisions applicable in a particular jurisdiction. State adoption and interpretation can vary. But the central expectation is clear: protecting client information is part of competent legal practice, not merely an IT department assignment.
A Privacy Program for a Law Firm Must Extend Beyond the Document System
Many firms equate data protection with securing their document-management environment.
That is no longer enough.
Personal information enters and leaves a modern firm through numerous channels:
- Website contact forms
- Client intake systems
- Document-management platforms
- E-discovery providers
- Practice-management software
- Billing systems
- Background-check vendors
- Human resources platforms
- Marketing databases
- Customer relationship management tools
- Cloud storage
- Video-conferencing systems
- AI assistants
- Transcription services
- File-transfer platforms
- Expert witnesses and consultants
- Local counsel
- Litigation-support vendors
Every one of those systems can create a separate privacy obligation and attack surface.
A firm may carefully protect privileged work product while overlooking personal information submitted by a job applicant, website visitor, former employee, expert witness, class member, deal participant, or prospective client.
Privacy governance must account for all personal data in the organization—not only files that have been formally assigned to an active legal matter.
What Law Firms Should Be Doing Now
No privacy or security program can guarantee that a sophisticated attacker will never succeed.
The appropriate objective is to reduce the probability of an incident, limit the information available if one occurs, detect unauthorized activity quickly, and produce defensible evidence that reasonable safeguards were operating.
1. Build a Real Data Inventory
The firm should know what categories of personal and confidential information it maintains, where they are stored, why they are processed, and which systems and vendors receive them.
The inventory should include structured databases, document repositories, shared drives, email, archives, backups, intake tools, marketing systems, human resources platforms, and AI services.
A spreadsheet created for a client questionnaire is not sufficient if it becomes outdated immediately.
Data mapping should be maintained as an operational process.
2. Connect Data to Its Business and Legal Purpose
Every major category of sensitive information should have a defined purpose.
The firm should be able to explain:
- Why it is collected
- Which matter or business function requires it
- Who owns it
- Which legal or contractual requirements apply
- How long it must be retained
- What event triggers deletion or review
Information without a current purpose should not remain indefinitely merely because storage is inexpensive.
3. Apply Enforceable Retention Rules
Retention schedules should distinguish among active matters, closed matters, litigation holds, employee information, applicant data, accounting records, marketing information, discovery material, and other operational records.
Deletion must extend beyond the primary system. Copies may remain in email, exports, local devices, cloud tools, archived systems, and vendor environments.
A defensible retention program needs governance, exceptions, approvals, and evidence—not just a policy document.
4. Govern Vendors as Extensions of the Firm
Law firms routinely transmit information to third parties that support discovery, research, hosting, billing, transcription, investigations, analytics, communications, and AI-enabled work.
The firm should evaluate each vendor’s:
- Data access
- Security posture
- Privacy practices
- Subprocessors
- Retention policies
- Incident-notification terms
- International transfers
- AI training practices
- Deletion capabilities
- Audit rights
- Exit procedures
The contract should reflect the actual sensitivity of the information—not the vendor’s standard sales language.
5. Restrict Access by Matter and Role
Access should be based on a demonstrated need.
Not every lawyer, employee, contractor, vendor, or administrator needs visibility into every matter. Ethical walls, sensitive investigations, criminal cases, internal misconduct reviews, healthcare matters, and major transactions may require additional segmentation.
Access rights should be reviewed when personnel change roles, leave the firm, complete an engagement, or no longer support a particular client.
6. Prepare a Privacy-Specific Incident Response Plan
A technical incident-response plan may focus on containment, eradication, system restoration, and forensic investigation.
The privacy response must also determine:
- What information was affected
- Whose information was involved
- Where those individuals reside
- Which breach laws apply
- Whether clients must be notified
- Whether regulators, insurers, or contractual partners must be informed
- What representations have previously been made
- Whether affected people have rights or remediation options
- How decisions will be documented
The privacy, legal, communications, insurance, compliance, and technology teams should know their roles before the incident occurs.
7. Test the Plan
Tabletop exercises should simulate realistic law firm scenarios:
- Compromised email credentials
- Ransomware affecting document systems
- Data theft from an e-discovery vendor
- An unauthorized AI upload
- A fraudulent IT support call
- Loss of a privileged investigation file
- Exposure involving multiple states or countries
- A client demanding immediate answers before the forensic review is complete
The purpose is not to produce a perfect rehearsal. It is to expose gaps in authority, documentation, vendor contacts, escalation, and decision-making.
8. Govern Generative AI Before It Becomes Another Data Leak
Lawyers are increasingly using AI for research, drafting, summarization, discovery, transcription, and document analysis.
That creates important questions about whether client information is retained, used for training, reviewed by humans, processed outside approved jurisdictions, or incorporated into provider telemetry.
ABA Formal Opinion 512 states that lawyers using generative AI must consider ethical responsibilities involving competence, confidentiality, client communication, and fees.
Firms need an approved AI inventory, use-case assessments, vendor reviews, input restrictions, access controls, training, and a process for responding when personnel use unapproved tools.
A policy telling lawyers not to paste confidential information into public AI systems is necessary. It is not a complete AI governance program.
9. Review Website and Intake Privacy
Law firm privacy risk can begin before the person becomes a client.
Firm websites may use advertising pixels, analytics tools, session-replay software, chat systems, scheduling services, cookies, and third-party forms. Contact forms may invite visitors to describe sensitive legal problems before conflicts are checked or representation begins.
Firms should know what website technologies are active, what information they collect, where that information is sent, and whether consent or disclosure requirements apply.
A privacy firm defending clients against tracking litigation should not discover through a demand letter that its own website was deploying undisclosed third-party technologies.
10. Maintain Evidence of Compliance
After a breach, the question will not merely be whether the firm says it took privacy seriously.
Clients, insurers, regulators, courts, and plaintiffs may ask for evidence.
That evidence can include:
- Risk assessments
- Vendor reviews
- Access certifications
- Retention records
- Training completion
- Incident-response tests
- Security assessments
- Data maps
- Policy acknowledgments
- AI approvals
- Deletion logs
- Remediation records
The best time to create an audit trail is before it is requested.
Privacy Professionals Must Apply the Same Standards Internally
The legal and privacy industries operate on trust.
Clients disclose information because they believe their lawyers, consultants, auditors, and technology providers will treat it with exceptional care.
A breach does not automatically prove that an organization was reckless. Sophisticated and well-resourced organizations can be victimized despite substantial safeguards. ABA guidance expressly recognizes that reasonable protection does not require a lawyer to be invulnerable.
But the standard cannot become: “Attacks happen, so nothing more could have been done.”
The more useful questions are:
- Did the organization know what it had?
- Did it need to retain it?
- Did access remain limited?
- Were vendors properly governed?
- Were warning signs monitored?
- Was the response rehearsed?
- Could affected records be identified?
- Were clients told what they reasonably needed to know?
- Can the organization prove that its controls were functioning?
For those of us working in privacy, those questions carry added significance.
We tell organizations to map their data, minimize collection, govern vendors, automate rights requests, monitor risk, build retention rules, and document compliance. Our credibility depends on whether we are willing to apply those same principles to our own operations.
How Captain Compliance Supports Law Firm Privacy Programs
Captain Compliance helps law firms and other professional-services organizations move from written privacy policies to operational privacy management.
That can include:
- Data inventory and governance
- Privacy impact assessments
- Vendor-risk workflows
- Data-subject request management
- Consent and website tracking controls
- Dynamic privacy notices
- AI governance
- Risk documentation
- Compliance evidence
- Ongoing monitoring
Technology cannot replace legal judgment, cybersecurity expertise, or incident-response counsel.
It can, however, give those teams a structured system for identifying where personal information exists, assigning responsibility, documenting controls, monitoring changes, and demonstrating that the privacy program operates beyond a collection of policies and spreadsheets.
The Legal Industry Should Assume It Is Being Targeted
The lesson from the WilmerHale lawsuit is not that one prominent firm should have been able to eliminate every cyber risk.
The lesson is that every law firm should assume that someone may be actively looking for a way into its information environment.
Attackers understand what law firms possess. Plaintiffs’ lawyers understand what follows when personal information is exposed. Regulators understand that law firms are businesses processing data. Clients increasingly understand that outside counsel can become part of their own third-party risk.
The legal profession can no longer treat privacy as a service offered to clients while viewing its own data practices as an internal administrative concern.
For a law firm, confidentiality is not only a professional promise.
It is infrastructure.
Frequently Asked Questions
Why are law firms frequent cyberattack targets?
Law firms maintain concentrated collections of valuable information involving multiple clients, transactions, disputes, investigations, employees, and third parties. Attackers may seek that information for identity theft, extortion, espionage, financial advantage, or litigation intelligence.
Does every law firm data breach violate professional ethics?
No. A successful attack does not automatically establish an ethical violation. ABA Model Rule 1.6 focuses on whether the lawyer made reasonable efforts to prevent unauthorized access or disclosure. The analysis may depend on the sensitivity of the information, available safeguards, cost, implementation difficulty, and other circumstances.
Is attorney-client privilege enough to protect breached information?
No. Privilege may protect information from compelled legal disclosure in certain circumstances, but it does not provide a technical security control or prevent criminal access.
What is the difference between privacy and cybersecurity?
Cybersecurity focuses primarily on protecting systems and information against unauthorized access, disruption, or misuse. Privacy governance addresses what information is collected, why it is processed, where it flows, who can use it, how long it is retained, and what rights and obligations apply.
Why is data minimization important after a breach?
Data minimization reduces the amount of information available to an attacker. It can also simplify investigation, notification, regulatory analysis, and remediation by limiting unnecessary duplication and legacy retention.
Should law firms conduct privacy assessments of AI tools?
Yes. Firms should evaluate whether AI tools receive confidential or personal information, where that information is processed, whether it is retained or used for training, which subcontractors are involved, and what contractual and technical controls apply.
Can cyber insurance replace a privacy program?
No. Insurance may help finance investigation, notification, defense, remediation, and other covered costs. It does not prevent an incident, satisfy professional duties, correct excessive retention, or replace an operational privacy and security program.