Major Law Firms Targeted in Cyberattacks Highlighting Growing Legal Industry Vulnerabilities

In recent developments, prominent law firms Herbert Smith Freehills Kramer (HSF Kramer) and Mayer Brown have been targeted in significant data breaches, underscoring the escalating cybersecurity threats facing the legal sector. These incidents follow reports that Weil Gotshal & Manges, Goodwin Procter, and WilmerHale collectively paid approximately $50 million in ransom to prevent the release of stolen data.

HSF Kramer, a firm that has previously emphasized the importance of robust data governance, now finds itself confronting the very risks it has cautioned against. In a 2025 publication, the firm highlighted that 63% of organizations only begin addressing data risk management after experiencing a cyber incident, a figure that had risen from 58% in the preceding year. This trend reflects a reactive approach to cybersecurity, which can leave organizations vulnerable to attacks. ([hsfkramer.com](https://www.hsfkramer.com/dam/jcr%3A082b22e3-4916-4974-892d-7f3fd5c650c8/HSF%20Kramer%20-%20Are%20you%20cyber%20ready%20-%202025.pdf?utm_source=openai))

Mayer Brown, known for its comprehensive cybersecurity and data privacy practice, has also been affected. The firm has a history of advising financial services clients on navigating complex data privacy laws and responding to data breaches. Notably, Mayer Brown represented Boeing Employees’ Credit Union in class action lawsuits following a 2022 ransomware attack on a third-party vendor, highlighting the firm’s experience in managing cybersecurity incidents. ([mayerbrown.com](https://www.mayerbrown.com/-/media/files/perspectives-events/publications/2025/02/2024-consumer-financial-services-highlights.pdf?utm_source=openai))

These breaches are part of a broader trend of cyberattacks targeting the legal industry. The 2026 Aura data breach serves as a pertinent example, where the consumer digital safety company Aura suffered a security incident affecting approximately 900,000 records. The breach was attributed to the cybercriminal group ShinyHunters, known for exploiting vulnerabilities in organizations’ data security practices. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Aura_data_breach?utm_source=openai))

The legal sector’s susceptibility to cyberattacks is heightened by the sensitive client information firms handle. Despite existing cybersecurity measures, the recent breaches at HSF Kramer and Mayer Brown highlight the need for continuous vigilance and proactive strategies to mitigate data security risks.

As cyber threats evolve, law firms must reassess and strengthen their cybersecurity frameworks to protect client data and maintain trust. The incidents at these leading firms serve as a stark reminder of the critical importance of robust data protection measures in the legal industry.