Law Firms Increasingly Targeted by Cyber Attacks

Cyberattacks against law firms rose sharply in 2025, according to a BakerHostetler report based on more than 1,250 incidents across industries. The firm saw law firm cases nearly double from the previous year, driven in part by a threat group that used social engineering tactics—impersonating IT staff, gaining remote access to attorneys’ devices, and quickly stealing sensitive data for ransom. Law firms are especially attractive targets because of the high-value confidential information they hold. The report recommends stronger employee training on phishing and tighter data retention practices, while also urging clients to treat law firms as potential security risks within vendor management programs.  

Ransom demands rose significantly, with the average increasing to $4.2 million and average payments also climbing. Many organizations paid to prevent public release of stolen data rather than to regain system access, likely due to better backup capabilities. Negotiating lower ransom amounts often took several weeks.  

Legal fallout also grew. Class action lawsuits were filed in 14% of incidents, up from the prior year, with large companies particularly likely to face litigation even in smaller breaches. Overall, the report highlights an evolving cyber threat landscape marked by more targeted tactics, higher financial stakes, and increasing legal exposure.  

This serves as an important reminder that securing a robust Cyber insurance policy is no longer optional for any prudent business. In a recent blog, I discussed the rising prevalence of AI-enhanced hacking incidents as well as some key policy terms to consider when selecting a policy. See David A. Gauntlett, New AI-Enhanced Cyber Attacks Increase Risks for the Uninsured, https://lnkd.in/gUmd5rs5 (Feb. 19, 2026). Prime among those key terms is the language addressing the “period of restoration.” Insurers commonly attempt to curtail benefits long before a business has been fully restored to its pre-incident level of operation. A company may have restored its email server and enterprise resource planning system, yet still face weeks or months of backlog clearance, customer attrition, regulatory review or vendor re-onboarding.

Previous
Previous

Narrow Cyber Coverage Provision Proves Fatal for Law Firm’s Claim

Next
Next

Delaware Court Distinguishes Between Negligent Outcomes and Negligent Actions