Home Blog TX Law Firms Under Siege 2026

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →

The Houston attorney had been practicing for 22 years. He had a corner office, a solid book of clients, and a reputation for closing complicated deals on time. On a Tuesday in February 2026, he lost $2.4 million in a single wire transfer — because someone spoofed the title company's email address six hours before a commercial real estate closing. The funds went to a mules account in Eastern Europe. He never saw a dime back. FBI IC3 Recovery Asset Team moved on the case within 90 minutes of the report. They froze 38% of the transfer. The remaining $1.5 million was gone.

$2.77B
FBI IC3 2024: BEC losses from 21,442 complaints. Law firms are the #1 BEC target by client value per incident.

The Threat Is Accelerating, Not Plateauing

Texas hosts the fourth-largest legal market in the United States. The concentration of M&A, energy, healthcare, and financial services clients in Dallas, Houston, Austin, and San Antonio law firms makes the sector a preferred target for threat actors who understand the extraordinary value of privileged communications and client financial data.

The 2026 threat landscape has three distinct layers — and most Texas firms are exposed on all three simultaneously.

Layer 1: Ransomware — Exfiltrate First, Encrypt Second

The ransomware playbook for law firms has fundamentally changed. Modern groups don't just encrypt your files — they exfiltrate the highest-value client data first, then threaten to publish it on a dark web leak site. Attorney-client privilege, once considered an impenetrable shield, is gone the moment privileged files appear on an extortion site.

Baker & Hostetler's 2026 Data Security Incident Report confirmed law firm incidents "nearly doubled" in 2025 vs. 2024. The groups active in the legal sector are not opportunistic — they are deliberate:

Layer 2: Business Email Compromise — The $2.9B Threat

FBI IC3 recorded $2.77 billion in BEC losses from 21,442 complaints in 2024. Attorney and law firm impersonation accounts for 12% of all BEC attack types — even though attorneys represent a small fraction of overall business recipients.

The math is stark: law firms move large wire transfers (closings, settlements, escrow) on predictable schedules, and they have institutional trust relationships that make impersonation plausible. A real estate closing with a $2.4M wire is the ideal BEC target — high value, predictable timing, institutional trust, and near-zero recovery once the funds leave the firm account.

The BEC Kill Zone — 4 Steps to Irreversible Loss

01
Email Compromise or Spoof Phishing or credential stuffing compromises a law firm email — or attackers register a lookalike domain (@firmsname-law.com vs. @firmsname.com). Crimson Kingsnake BEC group used 92 malicious domains to target 19 law firms across the US, UK, and Australia.
02
Silent Monitoring Attackers read email for weeks, understanding transaction timelines, client relationships, payment expectations, and who has wire authority. They know your closing schedule before you do.
03
Strike at Closing At the exact moment a wire transfer is expected — real estate closing, settlement disbursement, M&A escrow — fraudulent instructions arrive from what appears to be the trusted counterparty.
04
Irreversible Loss Wire transfers cannot be recalled. Funds move through multiple mule accounts and leave the country. The firm bears liability to the client. FBI IC3 RAT has a 66% freeze rate — but only when the victim reports within hours.

Layer 3: E-Discovery Exfiltration — The Hidden Risk

Law firms handling significant litigation or regulatory investigations are targets for e-discovery exfiltration. Attackers recognize that litigation holds and discovery productions create extended network access windows — and that the data within those windows is extraordinarily valuable.

The 2023 breach at a major international firm where opposing counsel's strategy was accessed via a compromised firm email before a critical deposition is now a recurring pattern, not an outlier.

The Regulatory Exposure Is Real and Growing

Cybersecurity is no longer an IT preference — it is a formal ethical obligation under ABA Model Rule 1.6(c) and Texas Disciplinary Rule of Professional Conduct 1.05. The consequences of non-compliance have teeth.

ABA Model Rule 1.6(c) — "A lawyer shall make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." This is not aspirational. It is enforceable. Comment [18] explicitly states that cost is a factor, not a blanket exemption.

Orrick ($8M), HPMB ($200K), Gunster ($8.5M)

These are not edge cases. They are the leading precedents that bar discipline counsel and plaintiff's attorneys now cite as the definition of "reasonable efforts" in 2026. The HPMB case is particularly important for smaller firms: the NY AG fined the firm $200,000 — not for the breach itself, but for failing to apply an available security patch. The size of the firm didn't matter. The absence of basic controls did.

ABA Formal Opinion 483 establishes post-breach obligations that most firms have never documented: monitoring for continued unauthorized access, stopping the breach, remediating the vulnerability, and notifying affected clients. When a firm discovers it has been breached and has no documented procedure for any of those steps, the clock starts ticking on a professional responsibility violation.

HIPAA: When Legal Work Crosses Into PHI

Firms handling healthcare litigation, insurance disputes, employment matters involving medical records, or elder law cases often process Protected Health Information (PHI). HIPAA applies to any entity that "transmits, maintains, or receives" PHI — including law firms acting as business associates of covered entities. A breach involving unencrypted attorney work product containing PHI is both a HIPAA breach notification event and a state bar disciplinary matter.

TX SB 2610 Safe Harbor — Do This or Face Punitive Damages

Effective September 1, 2025, Texas SB 2610 creates an affirmative defense to punitive damages for Texas businesses that implement NIST CSF, CIS Controls, or ISO 27001 before a breach. Firms that don't qualify for safe harbor face uncapped punitive exposure in breach litigation. The safe harbor only applies to programs already in place when the breach occurs — there is no grace period.

Your Vendor's Breach Is Your Breach

ABA Formal Opinion 483 requires lawyers to conduct due diligence on their technology vendors' security controls. This is not optional, and the consequences of ignoring it are real. The DocketWise breach exposed 116,666 immigration records at a legal SaaS vendor. The Clio/Cleo supply chain attack (Cl0p, Oct–Dec 2024) compromised firms that used Cleo for document exchange. iManage on-prem vulnerabilities left firms running outdated versions exposed to data exfiltration.

When a vendor is breached, the firm's ethical duty to clients does not pause while they determine the vendor's liability. The firm must act reasonably and promptly to mitigate the damage — and "we didn't know our file transfer vendor was unpatched" is not a defense under ABA Opinion 483.

Why Traditional IT Fails Law Firms

Most small and mid-size law firms in Texas rely on daytime IT support — a managed services provider (MSP) that handles helpdesk, network maintenance, and server management. This model works perfectly for keeping the lights on. It is catastrophically inadequate for security operations.

The gap is not about quality of IT staff. It is about fundamentally different disciplines. IT operations is about maintaining uptime and solving user problems. Security operations is about detecting the presence of an adversary who is actively working to remain undetected.

The average ransomware dwell time — the period between initial access and detection — is 26 days across all industries. For law firms, which often have lower security maturity and less security tooling, dwell times can be significantly longer. A firm that relies on its daytime IT provider to notice a compromise will typically detect the breach at step 4 of the ransomware playbook — when the ransom note appears, not when the exfiltration begins.

A 24/7 security operations center detects intrusions in minutes to hours — not weeks. The 30-minute SLA that CoreRecon offers is specifically designed for the legal sector: when a firm discovers a breach Saturday night before a Monday trial date, the response time is not next business day — it is 30 minutes.

12 Steps Every Texas Law Firm Should Take Now

The 12-Step Action Checklist

Multi-factor authentication on all email, practice management, and file transfer accounts
Email security platform with BEC impersonation detection and DMARC/DKIM enforcement
Endpoint detection and response (EDR) on all attorney and staff devices
Immutable encrypted offsite backups with tested restore procedures
Documented incident response plan reviewed at least annually
24/7 monitoring or managed detection service — not just daytime coverage
Dark web monitoring for firm credentials and client data
Annual security awareness training with documented completion records
Network segmentation — attorney workstations separated from file servers
Vendor security due diligence for Clio, iManage, NetDocuments, Cleo, and any SaaS with client data
Written wire transfer confirmation policy — verbal verification for any transfer over $10K
Pre-engaged incident response retainer — not "call someone if it happens"

See Your Firm's Actual Exposure

30-minute call. Map your attack surface against ABA 1.6(c), TDRPC 1.05, BEC wire fraud risk, and vendor supply chain exposure. Free partner-ready report in 14 days.

Book Free Assessment →

No credit card  ·  No commitment  ·  SDVOSB-certified team