The Houston attorney had been practicing for 22 years. He had a corner office, a solid book of clients, and a reputation for closing complicated deals on time. On a Tuesday in February 2026, he lost $2.4 million in a single wire transfer — because someone spoofed the title company's email address six hours before a commercial real estate closing. The funds went to a mules account in Eastern Europe. He never saw a dime back. FBI IC3 Recovery Asset Team moved on the case within 90 minutes of the report. They froze 38% of the transfer. The remaining $1.5 million was gone.
The Threat Is Accelerating, Not Plateauing
Texas hosts the fourth-largest legal market in the United States. The concentration of M&A, energy, healthcare, and financial services clients in Dallas, Houston, Austin, and San Antonio law firms makes the sector a preferred target for threat actors who understand the extraordinary value of privileged communications and client financial data.
The 2026 threat landscape has three distinct layers — and most Texas firms are exposed on all three simultaneously.
Layer 1: Ransomware — Exfiltrate First, Encrypt Second
The ransomware playbook for law firms has fundamentally changed. Modern groups don't just encrypt your files — they exfiltrate the highest-value client data first, then threaten to publish it on a dark web leak site. Attorney-client privilege, once considered an impenetrable shield, is gone the moment privileged files appear on an extortion site.
Baker & Hostetler's 2026 Data Security Incident Report confirmed law firm incidents "nearly doubled" in 2025 vs. 2024. The groups active in the legal sector are not opportunistic — they are deliberate:
- ALPHV/BlackCat — Hit HWL Ebsworth (Australia, 2023): 1.45TB of client data published on dark web leak site. Used the same model on US firms throughout 2024–2025.
- Silent Ransom Group (SRG) — FBI IC3 Private Industry Notice CSA 2025/250523: explicitly warned that SRG has targeted law firms since spring 2023. Fried Frank Harris Shriver & Jacobson and Wood Smith Henning & Berman confirmed as SRG victims.
- INC Ransom — Halcyon confirmed INC Ransom is actively running campaigns specifically targeting the legal sector. Dwell time shorter than legacy groups — speed of containment is everything.
- Cl0p — Supply chain specialist targeting file transfer software. Cleo/Harmony zero-days (CVE-2024-50623, CVE-2024-55956) exploited Oct–Dec 2024. Hertz legal department and Western Alliance Bank (22,000 customers) confirmed compromised via this vector.
Layer 2: Business Email Compromise — The $2.9B Threat
FBI IC3 recorded $2.77 billion in BEC losses from 21,442 complaints in 2024. Attorney and law firm impersonation accounts for 12% of all BEC attack types — even though attorneys represent a small fraction of overall business recipients.
The math is stark: law firms move large wire transfers (closings, settlements, escrow) on predictable schedules, and they have institutional trust relationships that make impersonation plausible. A real estate closing with a $2.4M wire is the ideal BEC target — high value, predictable timing, institutional trust, and near-zero recovery once the funds leave the firm account.
The BEC Kill Zone — 4 Steps to Irreversible Loss
Layer 3: E-Discovery Exfiltration — The Hidden Risk
Law firms handling significant litigation or regulatory investigations are targets for e-discovery exfiltration. Attackers recognize that litigation holds and discovery productions create extended network access windows — and that the data within those windows is extraordinarily valuable.
The 2023 breach at a major international firm where opposing counsel's strategy was accessed via a compromised firm email before a critical deposition is now a recurring pattern, not an outlier.
The Regulatory Exposure Is Real and Growing
Cybersecurity is no longer an IT preference — it is a formal ethical obligation under ABA Model Rule 1.6(c) and Texas Disciplinary Rule of Professional Conduct 1.05. The consequences of non-compliance have teeth.
Orrick ($8M), HPMB ($200K), Gunster ($8.5M)
These are not edge cases. They are the leading precedents that bar discipline counsel and plaintiff's attorneys now cite as the definition of "reasonable efforts" in 2026. The HPMB case is particularly important for smaller firms: the NY AG fined the firm $200,000 — not for the breach itself, but for failing to apply an available security patch. The size of the firm didn't matter. The absence of basic controls did.
ABA Formal Opinion 483 establishes post-breach obligations that most firms have never documented: monitoring for continued unauthorized access, stopping the breach, remediating the vulnerability, and notifying affected clients. When a firm discovers it has been breached and has no documented procedure for any of those steps, the clock starts ticking on a professional responsibility violation.
HIPAA: When Legal Work Crosses Into PHI
Firms handling healthcare litigation, insurance disputes, employment matters involving medical records, or elder law cases often process Protected Health Information (PHI). HIPAA applies to any entity that "transmits, maintains, or receives" PHI — including law firms acting as business associates of covered entities. A breach involving unencrypted attorney work product containing PHI is both a HIPAA breach notification event and a state bar disciplinary matter.
TX SB 2610 Safe Harbor — Do This or Face Punitive Damages
Effective September 1, 2025, Texas SB 2610 creates an affirmative defense to punitive damages for Texas businesses that implement NIST CSF, CIS Controls, or ISO 27001 before a breach. Firms that don't qualify for safe harbor face uncapped punitive exposure in breach litigation. The safe harbor only applies to programs already in place when the breach occurs — there is no grace period.
Your Vendor's Breach Is Your Breach
ABA Formal Opinion 483 requires lawyers to conduct due diligence on their technology vendors' security controls. This is not optional, and the consequences of ignoring it are real. The DocketWise breach exposed 116,666 immigration records at a legal SaaS vendor. The Clio/Cleo supply chain attack (Cl0p, Oct–Dec 2024) compromised firms that used Cleo for document exchange. iManage on-prem vulnerabilities left firms running outdated versions exposed to data exfiltration.
When a vendor is breached, the firm's ethical duty to clients does not pause while they determine the vendor's liability. The firm must act reasonably and promptly to mitigate the damage — and "we didn't know our file transfer vendor was unpatched" is not a defense under ABA Opinion 483.
- Cleo / Cleo Harmony — Critical. Cl0p zero-days (CVE-2024-50623, CVE-2024-55956). Exploited Oct–Dec 2024.
- Accellion FTA — High. Jones Day (184,000 files), multiple law firms compromised 2020–2021.
- iManage (on-prem) — High. Data exfiltration vulnerability in versions 9.4, 9.5, 10.x prior to 10.2.2.260.
- DocketWise — Critical. 116,666 immigration records exposed.
- NetDocuments — High. 39% increase in legal sector data breaches Q3 2023–Q2 2024, affecting 7.9 million people.
Why Traditional IT Fails Law Firms
Most small and mid-size law firms in Texas rely on daytime IT support — a managed services provider (MSP) that handles helpdesk, network maintenance, and server management. This model works perfectly for keeping the lights on. It is catastrophically inadequate for security operations.
The gap is not about quality of IT staff. It is about fundamentally different disciplines. IT operations is about maintaining uptime and solving user problems. Security operations is about detecting the presence of an adversary who is actively working to remain undetected.
The average ransomware dwell time — the period between initial access and detection — is 26 days across all industries. For law firms, which often have lower security maturity and less security tooling, dwell times can be significantly longer. A firm that relies on its daytime IT provider to notice a compromise will typically detect the breach at step 4 of the ransomware playbook — when the ransom note appears, not when the exfiltration begins.
A 24/7 security operations center detects intrusions in minutes to hours — not weeks. The 30-minute SLA that CoreRecon offers is specifically designed for the legal sector: when a firm discovers a breach Saturday night before a Monday trial date, the response time is not next business day — it is 30 minutes.
12 Steps Every Texas Law Firm Should Take Now
The 12-Step Action Checklist
See Your Firm's Actual Exposure
30-minute call. Map your attack surface against ABA 1.6(c), TDRPC 1.05, BEC wire fraud risk, and vendor supply chain exposure. Free partner-ready report in 14 days.
Book Free Assessment →No credit card · No commitment · SDVOSB-certified team