Cyber Threat Brief 2026
Executive Summary
Texas law firms are among the highest-value ransomware and BEC targets in the United States. The combination of attorney-client privileged communications, IOLTA trust account wire authority, M&A deal terms, and litigation strategy in a single environment creates a threat profile that few other sectors match. Ransomware groups have explicitly shifted to exfil-and-leak tactics precisely because privilege-protected data carries maximum extortion leverage.
Black Fog 2024 Annual Cybercrime Report. The legal sector surpassed healthcare as the most-targeted professional services sector for the first time. Texas mid-market firms (10–100 attorneys) are the primary target: large enough to pay a significant ransom, small enough to lack in-house SOC coverage.
Business Email Compromise targeting law firm partner accounts and IOLTA trust wires remains the fastest-growing attack category in the legal sector. The $2.77B figure represents reported losses — actual losses, including unreported incidents, are estimated at 3–4x that figure (FBI IC3 2024 Annual Report).
This brief covers six named incidents with dates, vectors, and losses; the full Texas regulatory stack (TX Bar Rule 5.03, ABA Formal Opinion 498, TDPSA, IRS Pub 4557, ABA 1.6(c), TX DR 1.05); top five attack vectors; top five controls; a 30/60/90 hardening roadmap; and five FAQ answers from real law firm partner conversations. All 35+ sources are cited.
Why Texas Law Firms Are Prime Targets
Privileged Data + Wire Transfer Authority = Maximum Leverage
No other professional sector combines all of the following in a single environment: attorney-client privileged communications (immune from most legal discovery), active litigation strategy, M&A deal terms, settlement negotiation positions, IOLTA trust account balances and wire transfer authority, and client PII. Attackers who gain access before encryption can exfiltrate files that destroy privilege, expose confidential M&A strategy, and redirect wires — without needing to detonate ransomware at all.
The exfil-and-leak playbook is now standard: (1) compromise VPN or Microsoft 365 account, (2) move laterally to iManage, NetDocuments, or Clio, (3) exfiltrate matter files over 30–207 days (average attacker dwell time), (4) deploy encryption, (5) threaten to publish on a dark web leak site. Standard EDR stops step 4. The damage from steps 1–3 is already done.
IOLTA Wire Fraud — The Fastest-Growing Loss Category
IOLTA trust accounts hold client funds in escrow during real estate closings, M&A transactions, and litigation settlements. The wire fraud playbook: compromise a partner's Microsoft 365 mailbox, monitor for wire instructions, intercept mid-transaction and redirect to attacker-controlled accounts. The average recovery rate for law firm BEC wire fraud after the wire clears: under 15%. The average single-event loss: $347,000 per FBI IC3 data. For real estate closing attorneys and M&A counsel, a single IOLTA intercept can wipe out a year of billings.
Practice Management SaaS as Attack Surface
Over 70% of Texas law firms with 10+ attorneys use cloud-based practice management: Clio, MyCase, iManage, NetDocuments, or Smokeball. These platforms are single points of failure: a compromised credential provides instant access to all client matter files across all matters, all attorneys, all years. Attackers specifically target practice management SaaS because the data is pre-organized by matter — eliminating the need to search through raw file shares.
6 Named Incidents — TX/Regional Law Firm Cyber Attacks
A Texas regional law firm was hit by ransomware targeting its document management environment. Client matter files, litigation strategy documents, and settlement communications were exfiltrated before encryption deployed. The attack affected clients in active litigation — privileged communications were at risk of exposure to opposing parties. The incident is representative of the TX mid-market firm pattern: firms under 100 attorneys with 20–60 endpoints, managing document systems without 24/7 SOC coverage. Source: TX bar disciplinary filings, ransomware.live (2024–2025).
Bryan Cave Leighton Paisner suffered a breach tied to a compromise of files related to its client Caesars Entertainment Group. Retail, financial services, and gaming sector client data was exposed — including privileged merger communications and regulatory correspondence. The breach confirmed the vendor/co-counsel supply chain as the #2 law firm attack vector. ABA Formal Opinion 483 requires due diligence on vendors, but most firms have no documented vendor security program. Source: SEC breach notification filings; ABA Formal Opinion 483 analysis, 2023.
INC Ransom group breached the State Bar of Texas in January 2025, exfiltrating attorney disciplinary files, bar examination records, and member PII. INC Ransom claimed access to confidential disciplinary proceedings and threatened publication on their leak site. The attack on the licensing body itself signals that the entire TX legal sector supply chain — bar databases, CLE providers, court filing systems, and practice management SaaS — is now in scope. Every attorney whose records were held by the State Bar is a potential identity theft victim. Source: Cybernews, January 2025; INC Ransom leak site analysis.
Orrick disclosed a breach affecting 638,000 individuals — clients, employees, and counterparties in healthcare, banking, and insurance matters. SSNs, medical records, financial account information, and privileged client data were exfiltrated. The resulting $8M class action settlement set a new professional liability precedent: law firm breaches are now treated as a direct client harm with quantifiable damages. Orrick's AmLaw 100 status provided no protection. The settlement established that firm size, revenue, and reputation do not substitute for SOC coverage. Source: HHS breach notification database; Orrick class action docket, 2024.
Gunster settled a class action for $8.5M following a breach that exposed client PII from healthcare, financial services, and real estate transactions. The Gunster settlement — paired with Orrick's $8M recovery — established that law firm breaches now carry class action risk commensurate with healthcare and financial institution breaches. Firms with healthcare, financial services, or defense contractor clients are particularly exposed because the underlying client data carries its own breach notification obligations (HIPAA, GLBA, DFARS). Source: Gunster class action docket; ABA Cybersecurity Legal Tech Resource Center, 2023.
DocketWise, an immigration law practice management SaaS platform used by thousands of US immigration attorneys, exposed 116,666 client records including visa applications, passport scans, biometric data, and privileged immigration communications. The breach originated at the vendor — not at any individual law firm. Under ABA Formal Opinion 483, every immigration firm using DocketWise at the time of the breach has vendor due diligence obligations that most could not satisfy. TX immigration attorneys with clients in USCIS proceedings were directly exposed. Source: DataBreaches.net; ABA Formal Opinion 483 vendor duty analysis, 2023.
Texas Regulatory Stack — What's Enforceable Now
The compliance stack for Texas law firms expanded significantly between 2021 and 2024. Four new mandates — ABA Formal Opinion 498, TDPSA, IRS Pub 4557 obligations, and Texas Bar Rule 5.03 supervisory interpretations — layer on top of the existing ABA 1.6(c) and TX DR 1.05 framework. Each creates independent enforcement exposure.
Texas Disciplinary Rule 5.03 holds partners and supervising attorneys responsible for the professional conduct of supervised lawyers and non-lawyer assistants — including the vendors and technology platforms they use. The State Bar's interpretation (consistent with ABA Model Rule 5.3) extends this to cloud vendors: if a law firm delegates document management to iManage or Clio without performing security due diligence, the supervising attorney cannot disclaim responsibility for a breach of that vendor's system. The Rule 5.03 exposure is personal — not just firm-level. Source: Texas TDRPC Rule 5.03; ABA Model Rule 5.3 commentary; ABA Formal Opinion 483 (2018).
ABA Formal Opinion 498 establishes that lawyers working in virtual or remote arrangements — which now includes hybrid and home-office setups ubiquitous post-COVID — must implement additional safeguards: encrypted home networks or VPN enforcement, documented device security policies, and explicit protocols for client communication security. Opinion 498 creates documented obligations for the remote-work arrangements that most Texas law firms now use without a written security policy. Malpractice insurers use Opinion 498 as the baseline underwriting standard for remote work coverage conditions. Source: ABA Formal Opinion 498 (May 2021).
Texas law firms holding consumer personal data are subject to TDPSA if annual revenue exceeds $25M or the firm processes data of 100,000+ Texas consumers. TDPSA requires privacy notices, consumer opt-out mechanisms for targeted advertising, data security requirements appropriate to the nature of the data, and a 30-day cure window after Texas AG notification. Law firms that handle employee PII, client consumer data, or HR records are in scope. Non-compliance is enforced by the Texas AG with civil penalties up to $7,500 per violation. TDPSA exposure may be discovered in opposing counsel's discovery requests in litigation. Source: Texas Business & Commerce Code Chapter 541; Texas AG TDPSA guidance (2024).
Law firms with tax practices — or serving as co-counsel on tax matters where they handle IRS Preparer Tax Identification Number (PTIN) holder obligations — must maintain a Written Information Security Plan (WISP) under IRS Pub 4557. The WISP requirement applies to any firm where attorneys review, prepare, or submit tax-related documents. The WISP must document: data inventory, access controls for tax data, incident response procedures, and vendor oversight. Enforcement comes via FTC Act Section 5 (unreasonable security practices) and IRS PTIN suspension risk. Source: IRS Publication 4557 (2023); FTC Act Section 5; GLBA Safeguards Rule 16 CFR Part 314.
ABA Model Rule 1.6(c) requires attorneys to make "reasonable efforts to prevent the inadvertent or unauthorized disclosure" of confidential client information. ABA Formal Opinion 477R (2017) applies this to electronic communications: attorneys must understand relevant technology, assess security risks, and implement safeguards commensurate with client sensitivity. In 2026, "reasonable efforts" means MFA on all email and practice management accounts, documented backup procedures, tested incident response, and vendor security due diligence — not optional best practices. Source: ABA Model Rule 1.6(c); ABA Formal Opinion 477R (May 2017); ABA Formal Opinion 483 (October 2018).
Texas DR 1.05 mirrors the ABA confidentiality framework with state-specific enforcement. Ethics Opinion 712 — the State Bar's controlling guidance — requires due diligence on cloud vendor security, reasonable safeguards on client data storage, and a documented plan for responding to a security incident. Absent documentation, a bar grievance following a breach has a clear path to a professional misconduct finding. Ethics Opinion 712 does not prohibit cloud use — it requires evidence of security controls. Source: Texas TDRPC Rule 1.05; Texas Bar Ethics Opinion 712 (2016).
Top 5 Attack Vectors — Texas Law Firms
1. BEC Wire Fraud — IOLTA Intercept & Partner Impersonation
Business Email Compromise targeting IOLTA accounts and partner wire instructions is the #1 financial loss vector. The sequence: compromise a partner's Microsoft 365 mailbox via credential phishing, monitor for wire instructions over days or weeks, intercept mid-transaction by sending a modified wire instruction from a typosquatted domain or the compromised mailbox itself. FBI IC3 2024: 21,442 BEC complaints, $2.77B losses, 12% attorney impersonation. Texas real estate closing attorneys and M&A counsel face the highest exposure. IOLTA wire fraud is not covered by standard cyber insurance without an explicit Social Engineering rider. Source: FBI IC3 2024 Annual Report.
2. Ransomware via RDP and VPN Credential Compromise
Exposed Remote Desktop Protocol (RDP) ports and VPN credential compromise are the two dominant initial access vectors for law firm ransomware. Attackers purchase stolen VPN credentials on dark web markets (often obtained through prior credential-stuffing attacks or phishing) and use them to authenticate directly to firm networks. Post-authentication lateral movement to document management systems takes under 60 minutes. The 207-day average attacker dwell time in professional services environments means exfiltration is complete long before encryption. Source: CISA Known Exploited Vulnerabilities; Mandiant M-Trends 2025; FBI Private Industry Notification (2024).
3. Third-Party Platform Compromise — NetDocuments, iManage, Clio Supply Chain
Practice management SaaS platforms are now targeted directly as a law firm supply chain attack vector. The DocketWise breach (116,666 records), the Cleo/Cl0p supply chain attack (October–December 2024), and iManage vulnerability disclosures demonstrate that firms that don't vet their vendor security inherit the vendor's exposure. ABA Formal Opinion 483 creates a documented vendor due diligence obligation — most firms have never conducted a vendor security review. Source: ABA Formal Opinion 483; DataBreaches.net; CISA supply chain advisories (2024).
4. Legal-Themed Phishing — Bar Association, Court Filing, and Deadline Impersonation
Legal-themed phishing exploits attorney urgency and bar compliance anxiety: fake court filing deadlines, fraudulent bar registration renewal emails, spoofed e-filing system notifications (PACER, Tyler Technologies TurboCourt, eFileTexas), and impersonated opposing counsel attachments. The effectiveness of legal-themed phishing is higher than generic corporate phishing because attorneys respond to legal deadlines under time pressure — security skepticism yields to urgency. Source: CISA Phishing Guidance (2024); ABA Cybersecurity Legal Tech Resource Center; Proofpoint Legal Sector Threat Report 2025.
5. Supply Chain via Vendor Counsel and Co-Counsel Access
Co-counsel arrangements and vendor access to shared document repositories create an extended perimeter. If a small plaintiff's firm acting as co-counsel on a large matter has compromised credentials, the attacker has access to all shared matter files on the lead firm's platform. Title companies, forensic accountants, expert witnesses, and court reporters with document portal access represent the same risk. Most outside counsel guidelines (OCGs) now require security questionnaire responses — but few firms verify the responses. Source: ABA Cybersecurity Legal Tech Resource Center; Ponemon/IBM CODB 2025 (third-party breach data).
Top 5 Controls — What Actually Stops Law Firm Attacks
Multi-factor authentication on Microsoft 365, Google Workspace, Clio, iManage, and NetDocuments is the single highest-ROI control for law firms. SMS-based MFA is better than nothing — phishing-resistant MFA (FIDO2/hardware keys or Microsoft Authenticator with number matching) eliminates credential phishing as an initial access vector. Most law firm BEC attacks exploit accounts without MFA or with SMS-based MFA that can be phished. Carriers including Chubb, Beazley, and At-Bay now condition coverage on documented MFA. Source: CISA MFA Guidance; ABA Formal Opinion 477R; Coalition Cyber Insurance (2024 underwriting criteria).
Every wire instruction for an IOLTA or trust account disbursement must be verified by a confirmed out-of-band phone call to a number independently sourced — not the number in the email. This is the single control that stops wire fraud cold. Banks cannot claw back funds once a wire clears. A $347,000 average loss is preventable with a 60-second phone call. The callback protocol must be a documented firm policy — not individual attorney discretion. Source: FinCEN FIN-2016-A003 (business email compromise advisory); FBI IC3 BEC guidance; ALTA Best Practices Pillar 3.
Attorney endpoints carry privileged documents and practice management credentials. Standard antivirus misses lateral movement and credential harvesting — the pre-exfiltration phase of ransomware attacks. EDR with behavioral analysis detects anomalous document access, mass file reads (indicative of exfiltration staging), and credential dumping before encryption deploys. BYOD attorney laptops must be enrolled in MDM with EDR deployed. Source: CISA EDR Guidance; NIST SP 800-207 (Zero Trust); FBI LockBit advisory (2024).
Shared IT admin accounts with persistent privilege are the primary lateral movement pivot in law firm ransomware attacks. A single compromised IT admin credential provides access to all document servers, email archives, backup systems, and practice management platforms. PAM vaulting with just-in-time access — where admin credentials are checked out per-session, session-recorded, and automatically revoked — eliminates persistent admin credential exposure. Source: CISA Known Exploited Vulnerabilities; NIST SP 800-53 AC-2 (Account Management); Verizon DBIR 2025.
Data Loss Prevention monitoring on document management systems detects anomalous mass downloads, USB transfers, or cloud sync of large volumes of client matter files — the staging phase of exfil-and-leak attacks. DLP configured to alert on unusual access patterns (a paralegal downloading 10,000 documents at 2am) creates the pre-encryption detection window that allows containment before privilege is destroyed. Combined with 24/7 SOC monitoring, DLP is the control that makes the exfil-and-leak playbook fail. Source: NIST SP 800-171 3.13.3; ABA Formal Opinion 483; Mandiant M-Trends 2025 (exfiltration detection).
30/60/90-Day Hardening Roadmap
- Deploy phishing-resistant MFA on all Microsoft 365 / Google Workspace accounts
- Enable MFA on Clio, iManage, and NetDocuments — disable legacy auth protocols
- Implement IOLTA callback verification protocol — document as firm policy
- Run DMARC/DKIM enforcement audit — stop partner impersonation spoofing
- Conduct dark web credential scan — identify compromised attorney accounts
- Disable RDP exposure on internet-facing systems — enforce VPN-only remote access
- Deploy EDR on all attorney endpoints — enroll BYOD devices in MDM
- Conduct vendor security review for practice management SaaS and co-counsel portals
- Author Ethics Opinion 712 / ABA 498 documented security program
- Complete TDPSA data mapping for consumer data holdings (if in scope)
- Draft IRS Pub 4557 WISP for tax practice attorneys (if applicable)
- Implement privileged access management — separate IT admin from daily-use accounts
- Run tabletop exercise — ransomware at 2am Saturday, trial Monday scenario
- Complete bar notification workflow — pre-draft client and AG notification templates
- Respond to corporate client BYOC questionnaires with documented controls evidence
- Conduct phishing simulation — measure attorney click rate, document results
- Prepare cyber insurance renewal package — map controls to carrier requirements
- Review co-counsel and vendor agreements — add security questionnaire requirements
FAQ — 5 Questions Law Firm Partners Actually Ask
Insurance is risk transfer, not risk reduction — and post-2021 coverage conditions have tightened dramatically. Most policies now require MFA documentation, verified backup architecture, tested IR plans, and vendor due diligence as coverage conditions, not just underwriting factors. A coverage denial post-breach because MFA wasn't deployed is a total loss. Wire fraud specifically requires a Social Engineering rider — most standard cyber policies exclude BEC IOLTA wire fraud without it. And a payout doesn't restore attorney-client privilege, recover exfiltrated M&A strategy, or satisfy ABA Rule 1.6(c). Source: Coalition Cyber Insurance (2024 underwriting requirements); Beazley Breach Response underwriting criteria.
ABA Formal Opinion 483 is explicit: attorneys must conduct due diligence on vendor security and act reasonably when a vendor breach occurs. Texas Bar Rule 5.03 extends supervisory responsibility to vendor-managed technology. The DocketWise breach (116,666 records) and Cleo/Cl0p supply chain attack both illustrate that vendor breaches create direct attorney liability. "The vendor was breached, not us" is not a defense under Ethics Opinion 712 or ABA Rule 1.6(c) — the firm's duty of confidentiality to clients doesn't pause because the breach originated upstream. Source: ABA Formal Opinion 483; Texas TDRPC Rule 5.03.
TDPSA applies to any entity that (a) conducts business in Texas or produces products or services consumed by Texas residents, (b) processes personal data of 100,000+ Texas consumers or 25,000+ consumers where the entity derives more than 25% of gross revenue from selling personal data, and (c) is not a small business as defined by the SBA. Most law firms are in scope for employee PII, client consumer data, and HR records. TDPSA does not have a blanket attorney-client privilege exemption. The Texas AG has civil penalty authority and the obligation to provide a 30-day cure window before enforcement — but the audit authority is real. Source: Texas Business & Commerce Code Chapter 541; Texas AG TDPSA FAQ (2024).
Texas Tex. Bus. & Com. Code §521.053 requires notification to affected individuals within 60 days of discovery, and to the Texas AG if the breach affects 250+ residents. The State Bar's independent obligation under ABA Rules 1.05 and 1.15 (safekeeping of client property) requires "prompt" notification when attorney-client privileged information or client funds are compromised — the State Bar has indicated 72 hours as the expected window for privilege-affecting breaches. These are two separate, independent notification obligations. Failing the AG notification also means potential civil penalties up to $500 per failure-to-notify. Source: Texas Bus. & Com. Code §521.053; State Bar of Texas disciplinary guidance; ABA Formal Opinion 483.
ABA Formal Opinion 498 (2021) requires that attorneys in virtual or remote practice environments use encrypted networks (home WiFi or VPN to firm network), documented device security policies (no personal use of work devices without controls), and explicit protocols for securing client communications in remote settings. The Opinion specifically calls out the risks of unsecured WiFi, shared devices, and video conference eavesdropping. In practice, this means: all remote attorney endpoints must have firm-managed security (MDM + EDR), VPN must be enforced for all document access, and the firm must have a documented remote work security policy. Carriers use Opinion 498 as the underwriting baseline for remote work coverage. Source: ABA Formal Opinion 498 (May 2021).
FBI IC3 2024 Annual Report (BEC, $2.77B, 21,442 complaints) • Black Fog 2024 Annual Cybercrime Report (45 law firm ransomware attacks) • ABA Model Rule 1.6(c) (2012 Ethics 20/20 amendment) • ABA Formal Opinion 477R (May 2017) • ABA Formal Opinion 483 (October 2018) • ABA Formal Opinion 498 (May 2021) • Texas TDRPC Rule 1.05 • Texas TDRPC Rule 5.03 • Texas Bar Ethics Opinion 712 (2016) • Texas Business & Commerce Code §521.053 • Texas Business & Commerce Code Chapter 541 (TDPSA) • Texas AG TDPSA guidance (2024) • IRS Publication 4557 (2023 rev.) • GLBA Safeguards Rule 16 CFR Part 314 • FTC Act Section 5 • NIST SP 800-171 Rev 2 • NIST SP 800-207 (Zero Trust) • CISA MFA Guidance (2024) • CISA Known Exploited Vulnerabilities Catalog • CISA Supply Chain Risk Management (2024) • CISA Phishing Guidance (2024) • FinCEN FIN-2016-A003 (BEC advisory) • FBI Private Industry Notification — Law Firm Ransomware (2024) • Mandiant M-Trends 2025 • Verizon DBIR 2025 • IBM Cost of a Data Breach 2025 (professional services $5.45M average) • Ponemon Institute Third-Party Risk (2025) • Coalition Cyber Insurance Underwriting Requirements (2024) • Beazley Breach Response underwriting criteria (2024) • Proofpoint Legal Sector Threat Report 2025 • ABA Cybersecurity Legal Tech Resource Center • NYC Bar Formal Opinion 2024-3 (vendor breach obligations) • HHS Breach Notification Database (Orrick, 638K individuals) • Orrick class action docket ($8M settlement, 2024) • Gunster class action docket ($8.5M settlement, 2023) • DataBreaches.net (DocketWise, 116,666 records) • Cybernews (State Bar of Texas / INC Ransom, January 2025) • INC Ransom leak site analysis (January 2025) • ransomware.live (Mossing & Navarre Toledo, 2024–2025) • ALTA Best Practices Pillar 3 (wire fraud verification)