Cybersecurity Challenges Escalate for Law Firms Amid Rising Ransomware Incidents and Emerging Threats

In recent years, law firms, like many other organizations, have been the target of cyber attacks, meaning cybersecurity precautions have become as critical as any other form of protection. Data from Above the Law report highlights that in the year 2024, a staggering 69% of organizations were affected by ransomware, representing a significant rise in cyber threats.

The 2024 ‘State of the Phish’ report, generated by Proofpoint, revealed some alarming cybersecurity statistics. Interestingly, 71% of the surveyed end-users admitted to taking risky actions online, such as reusing passwords or clicking links from unknown senders. This statistic emphasizes the critical need for regular cybersecurity awareness training for employees.

Moreover, the report mentions that despite the one million attacks launched every month intending to bypass multifactor authentication (MFA) methods, 89% of security professionals believe MFA offers complete protection against account takeovers. This discrepancy demonstrates a lack of understanding regarding the limitations of MFA. Although it is an important layer of protection, it is not infallible.

The training programs offered by most organizations cover only a quarter of essential topics. Malware, Wi-Fi security, ransomware, and email phishing are frequently covered, but other significant risks such as SMS phishing, the use of deepfake audio and video, and employee social engineering are often ignored.

The report also exposes the changing landscape of cyber threats. Traditional attack methods such as phishing, business email compromise (BEC), and ransomware continue to pose significant threats. But newer methods such as telephone-oriented attack delivery (TOAD) and more sophisticated techniques bypassing MFA are emerging. For instance, attackers are increasingly using proxy servers to intercept MFA tokens and perpetrate account takeovers.

Artificial Intelligence (AI) is becoming a part of this threat landscape too. AI is being utilized by attackers for various purposes, but notably for constructing more convincing and personalized emails in diverse languages. Proofpoint’s data shows that there’s an average of 66 million targeted BEC attacks with AI every month.

Finally, the report stresses that while various companies are being targeted in malicious email attacks, Microsoft tops the list. This news is followed by insights on ransomware – it’s still prevalent, with 69% percent of businesses encountering an attack. And the surprising part? Ninety-six percent of those attacked have cyberinsurance.

It’s essential for legal professionals to be aware of the shifting landscape of cybersecurity, and implement robust measures to safeguard their operations. This includes regular training that covers a broad range of threats, embracing effective protective measures like MFA while understanding its limitations and ensuring widespread awareness about the potential risks of emerging technologies like AI