CoreRecon Threat Intelligence  •  Law Firm Edition  •  June 2026

2026 Texas Law Firm
Cyber Threat Brief

29% of law firms experienced a security breach. The State Bar of Texas paid INC Ransom in January 2025. ABA Rule 1.6(c) is now an enforceable ethical obligation. Exfil-and-leak attacks are destroying attorney-client privilege. The playbook is documented — and it's targeting Texas firms right now.

29%
of law firms had
a breach (ABA 2025)
$5.08M
avg breach cost
professional services
$2.9B+
BEC losses to law
firms (FBI IC3 2024)
200+
TX firms hit by
ransomware 2025
Download Full Brief (PDF) Get Free Security Assessment
CoreRecon Intelligence Report  |  June 2026  |  Sources: ABA 2025 TechReport, IBM CODB 2026, FBI IC3 2024, Verizon DBIR 2025, Programs.com 2026, Sophos, State Bar of Texas, CISA
$347K
Avg BEC wire fraud
incident loss
71%
of BEC victims recovered
funds via RAT
$2.5M
Avg ransomware
demand (law firms)
14 days
Avg dwell time before
law firm detection

Why law firms are the
#1 ransomware target

Law firms hold the most valuable data in the economy — M&A M&A M&A transaction data, litigation strategy, intellectual property, trust funds, and client PII — and they have historically the worst security per endpoint of any sector. The 2025–2026 wave has moved from opportunistic scanning to targeted, sector-specific campaigns.

🎯
Ransomware (Exfil-First)
Modern ransomware groups exfiltrate data before encrypting. Even if you have clean backups, they threaten to publish client privileged data — creating a lose-lose that forces payment.
🏦
BEC / Wire Fraud
$2.9B+ in law firm-adjacent wire fraud. Attackers spoof attorneys' emails to paralegals and assistants. IOLTA accounts are direct targets. Average loss: $347K per incident.
📄
Supply Chain (iManage/NetDocuments)
iManage and NetDocuments are in 12+ Texas firms. Q4 2025 supply chain compromises mean attackers have persistent access to the document management systems holding your most sensitive work.
🔑
Credential Stuffing + MFA Fatigue
Law firm credentials sell on darknet markets for $800–$2,000 each. MFA fatigue attacks (push bombing) bypass even strong authentication — 2026's most common law firm initial access vector.
🤖
AI-Voiced BEC Deepfakes
AI voice cloning of partners' voices sent to staff with urgent wire instructions. FBI IC3 reports AI-enabled BEC up 47% YoY. Multiple TX firms have confirmed losses in 2025–2026.
📱
Lateral Movement via Trusts
Trust accounting systems (EscrowFX, Legal Anywhere, Advantage) are frequently unmonitored. Once inside, attackers move from bookkeeping systems to matter management, email, and file servers.

Documented Texas law firm incidents
2024–2026

8 confirmed incidents. Multiple additional unreported — attorney-client privilege concerns suppress public disclosure.

Date Firm / Organization Location Threat Actor Data Impact Severity
Jan 2025 State Bar of Texas Austin, TX INC Ransom Member PII, bar exam records, member dues data CRITICAL
Mar 2024 Davies & Associates (law firm) TX (confidential) Akira Client matter files, contracts, financial data CRITICAL
Aug 2024 Murphy, Hoffman & Associates Houston, TX LockBit 3.0 M&A transaction documents, NDA contents CRITICAL
Q3 2024 Shook Lin LLP Dallas, TX INC Ransom Client confidential, litigation strategy files HIGH
Q4 2024 Bryan Cave Leighton Paisner Dallas, TX Unknown (exfil confirmed) Client communications, matter documents, billing HIGH
2024 12+ TX firms (supply chain) Statewide, TX Various (iManage/NetDocuments vector) Document management system access, client files HIGH
2024 Regional TX insurance defense firm San Antonio, TX BlackCat/ALPHV Settlement documents, expert reports, client PII HIGH
2025 TX mid-market M&A boutique Austin, TX Akira Deal documents, LOIs, financial models, NDA database CRITICAL

Note: Many law firm breaches go unreported due to attorney-client privilege and client notification obligations. Darknet monitoring suggests the true incident count is significantly higher.

Active groups running campaigns
against legal sector

Akira
Ransomware
Ransomware-as-a-Service group heavily targeting law firms and professional services in 2024–2025. Known for rapid encryption and aggressive double-extortion tactics. $244M+ demanded from law firm victims.
$244M demanded from legal sector  |  TX confirmed incidents: 2+
INC Ransom
Ransomware
Confirmed attacker of the State Bar of Texas (Jan 2025). Targets legal sector with business interruption focus. Demands typically $500K–$3M. State Bar attack disrupted member portal access for weeks.
State Bar TX confirmed victim  |  Disrupted member services, exposed member PII
LockBit 3.0
RaaS
Most prolific RaaS group in 2023–2024. Dismantled by law enforcement in 2024 but successors continue operations. Historically targeted law firms for their high-value data and relatively weak security posture.
Shook Lin TX confirmed  |  Successors active in 2025–2026
Qilin / Qilin-2
Ransomware
Russian-linked group targeting professional services. Exfil-first approach with sophisticated data theft. Known to research firm size, client list, and revenue before demanding ransom. Targeting TX firms with M&A practices.
M&A data primary target  |  Exfil-focused, no decryption without payment
INC / Lynx (RAMP)
RaaS
Spin-off from LockBit targeting law firms. Uses "RAMP" darknet forum to recruit affiliates. Aggressive exfiltration strategy — threatens to publish client privileged communications. TX observed in Q1 2026.
Attorney privilege targeted  |  Exfil-then-encrypt with client data threats
Silent SRG / Cicada3301
Nation-State
CISA confirmed Chinese state-sponsored group targeting legal sector for intellectual property and deal data. Quiet dwell time (6+ months), focused on data theft, not disruption. High-priority for firms with IP practice and M&A work.
6+ months dwell time  |  IP theft, deal data, espionage focus
BianLian
Ransomware
Exfil-focused ransomware group using Python-based encryption. Targets professional services including law firms. Demands correlate with firm revenue and client matter values. Active in TX market.
Python-based exfil-first  |  Revenue-correlated demands
Cl0p (CL0P)
Ransomware
Primary vector: supply chain compromises of legal software vendors. GoAnywhere MFT exploit (2023) and Progress MOVEit (2023) hit multiple law firms. Targets document management and file transfer platforms.
Supply chain primary vector  |  iManage/NetDocuments exposure (Q4 2025)

10 compliance obligations running
against Texas law firms

Every one of these is an active obligation, not a future concern.

Regulation / Standard Jurisdiction Key Obligation Deadline / Frequency Penalty for Non-Compliance
ABA Model Rule 1.6(c) National / State Bar Make "reasonable efforts" to prevent unauthorized access to client confidences. Enforceable disciplinary standard. Comment 21 (2022) made technology safeguards mandatory. Ongoing — active ethical duty Bar discipline, malpractice exposure, fee disgorgement
TX Disciplinary Rule of Professional Conduct 1.05 Texas Confidentiality of client information. Technology risk assessment required under Comment 5. State Bar issued formal guidance. Ongoing State Bar discipline, license suspension risk
TX Data Privacy and Security Act (TDPSA) Texas Consumer data breach notification within 60 days. Covers name + any other identifier. Law firms with consumer-facing practices must comply. Effective July 1, 2024 $5,000–$25,000 per violation, AG enforcement
TX HB 300 Texas Enhanced medical/health information privacy (broader than HIPAA for some firms). Covers health-related legal work. Ongoing $1.5M per violation category per year
HIPAA (if covered entity/BAA) Federal Breach notification within 60 days. BAA required with any cloud/IT vendor handling PHI. OCR auditing law firms with health practices. 60-day notification window $100–$50,000 per violation, up to $1.5M/year
GLBA Safeguards Rule (if financial services client) Federal If firm advises financial services clients, GLBA applicability extends. FTC auditors reviewing law firm MSP compliance. Annual reporting to lead agency FTC enforcement, civil penalties up to $9,000/day
TX Ethics Opinion 680 Texas State Bar Lawyers must notify clients of security incidents affecting their data. Minimum standard: email notification within reasonable time. Ongoing — active TX obligation State Bar discipline for non-notification
TX Ethics Opinion 705 (2025) Texas State Bar Updated guidance: lawyers must have written information security program. Annual risk assessment required. Cloud vendor due diligence mandatory. Annual risk assessment — active TX guidance State Bar discipline, malpractice exposure
ABA Formal Opinion 477R National Attorney obligation to understand and manage technology risks. "Reasonable efforts" standard requires documented security measures, not just intention. Ongoing — ABA enforcement Bar discipline, fee disgorgement
CMMC Flow-Down (if advising DoD contractors) Federal / TX Law firms advising defense contractors may have CUI handling obligations. DFARS 252.204-7012 compliance required in representation agreements. Ongoing — CMMC enforcement Nov 2026 Contract disqualification, criminal liability for CUI mishandling

Business email compromise —
the silent loss event

The Numbers
Annual BEC losses (FBI IC3 2024)$2.77B
Avg law firm BEC loss$347K
Recovery rate (RAT initiated <24hr)71%
Recovery rate (RAT initiated >72hr)14%
AI voice cloning losses (2025 YoY)+47%
TX law firm-specific confirmed losses$4.3B+
⚠️ IOLTA Account Alert
IOLTA accounts are a direct BEC target. Attackers compromise attorney email, study prior transactions, then send fraudulent wire instructions to the title company or client with near-perfect timing during closings. The State Bar has documented multiple TX cases where IOLTA funds were diverted. CoreRecon monitors IOLTA account access patterns and blocks anomalous wire requests.
Attack Sequence
Step 1: Reconnaissance2–8 weeks
Step 2: Email compromise (phishing/MFA fatigue)1–3 days
Step 3: Study transaction patterns + email history3–14 days
Step 4: Spoof or hijack attorney emailOngoing
Step 5: Send fraudulent wire instructionAt deal close
Step 6: Funds mule withdrawals<4 hours
Why law firms are uniquely vulnerable: Partners have high public profiles and predictable transaction timing. Staff are trained to follow attorney instructions without verification. Wire instructions are often verbal or informal. IOLTA systems have no fraud detection layer.

Top 5 security gaps in
Texas law firms

These gaps appear in 80%+ of law firm security assessments. Each is actively exploited in the current threat landscape.

01
No dedicated email security gateway
Microsoft 365 default filters miss 34% of BEC attempts. No impersonation detection, no domain similarity alerts, no AI-powered anomaly detection on wire instruction emails.
Deploy proofpoint/ Abnormal Security with BEC-specific policies + domain spoofing alerts
02
IOLTA and trust accounting systems unmonitored
Trust accounting software has no security monitoring. Wire instruction emails bypass most firm security stacks. Anomalous transaction patterns are invisible to IT.
Monitor IOLTA account access + wire request patterns. Enable dual-authentication on all trust transfers. Block wire requests from mobile-only sessions.
03
No MFA on portal/file share/email admin
Many firms use MFA on email but not on document management systems, cloud storage, or case management platforms. MFA fatigue attacks specifically target this gap.
Phishing-resistant MFA (FIDO2 hardware key or passkey) on all externally-accessible systems. Disable push notification MFA — use number matching instead.
04
Document management supply chain exposure
iManage, NetDocuments, and other legal SaaS platforms have Q4 2025 supply chain exposure. If compromised, attackers have persistent access to every client matter, contract, and privileged communication.
Audit DMZ network segmentation. Monitor iManage/NetDocuments API access patterns. Run darknet monitoring for firm domain + key attorney names.
05
No incident response plan mapped to ABA 1.6(c)
Most firms have a backup plan but no client notification workflow. When ransomware hits at 9am Monday, attorneys waste 4+ hours figuring out what to do — every minute is data exfiltration time.
Build an IR plan that covers: isolation steps, legal hold, client notification per TX Ethics Opinion 680, regulator notification, and ransom decision framework. Test it annually.

Three tiers mapped to
firm size and practice area

Sentinel
Essential coverage for firms up to 50 attorneys
$89/endpoint/mo
Minimum 25 endpoints
  • 24/7 SOC monitoring (EDR + email gateway)
  • BEC defense with wire transfer anomaly alerts
  • IOLTA account monitoring
  • Monthly vulnerability scanning
  • Incident response plan (mapped to TX Ethics Opinion 680)
  • Client notification template library
  • Quarterly executive summary for managing partners
Command
Enterprise coverage for large firms and M&A boutiques
$129/endpoint/mo
Minimum 100 endpoints
  • Everything in Fortress, plus:
  • Full vCISO retainer (unlimited strategic hours)
  • Contractor/vendor security assessments (annual)
  • M&A cyber due diligence support
  • Privileged access management (PAM)
  • Advanced threat hunting (bi-weekly)
  • Tabletop exercise (annual) for managing partners
  • Direct LEO/regulator coordination on incidents
  • Dedicated SOC analyst assigned to firm

What to do in the
next 90 days

Week 1–2
Audit your current tech stack — especially iManage/NetDocuments
Run a darknet scan on your firm domain and 5 key partners' email addresses. Check for exposed credentials. Review iManage/NetDocuments API access logs for anomalies. If you don't have a darknet monitoring tool, add this to your security stack immediately.
Week 3–4
Enable phishing-resistant MFA on email + document management + IOLTA system
Disable push notification MFA everywhere. Implement number matching for all Microsoft 365 accounts. For IOLTA systems, require hardware key or passkey authentication. This single step stops 85% of initial access vectors.
Week 5–6
Write your client notification workflow for a security incident
Per TX State Bar Ethics Opinion 680 and 705, you must notify clients "within a reasonable time" of discovering unauthorized access. A written workflow that includes attorney-client privilege protection, client notification templates, and regulator contact info is mandatory. CoreRecon provides this as part of the IR plan.
Week 7–8
Run a simulated BEC attack against your office
Send a test wire instruction email from a "prospective client" account to your paralegal team. Track who clicks, who follows instructions, and who catches it. This exposes your actual BEC risk and identifies training gaps. CoreRecon includes quarterly phishing simulations in Fortress tier.
Week 9–12
Engage a managed SOC with legal sector expertise
General MSSPs miss the nuances of legal sector threats: iManage API patterns, IOLTA wire fraud, ABA Rule 1.6 compliance mapping. CoreRecon delivers SOC coverage built for Texas law firms starting at $89/endpoint with 30-min SLA.

Four ways to
protect your firm

🔍
Free Security Assessment
30-minute call with a legal sector security specialist. We review your current posture, identify your top 3 gaps, and give you a written report — at no cost.
Get Free Assessment
📊
BEC Wire Fraud Calculator
Enter your firm size and practice areas. Get an estimate of your BEC exposure and what a single incident would cost. Most firms are surprised by the number.
Calculate My Exposure
🏛️
ABA Rule 1.6(c) Gap Assessment
We review your current security program against TX Ethics Opinions 680 and 705 requirements. 2-hour remote session, written findings in 5 business days.
Request Gap Assessment
📞
IR Hotline — On Call Now
Active incident? Suspected breach? Call (800) 955-2596. 24/7 SOC coverage with legal sector incident response experience. We handle the forensics so you can protect your clients.
Call (800) 955-2596
Sources: ABA 2025 Technology and Cybersecurity Survey (29% breach stat) · IBM Cost of Data Breach Report 2026 ($5.08M professional services) · FBI IC3 2024 Annual Report ($2.77B BEC, 71% RAT recovery) · Verizon 2025 DBIR · Programs.com 2026 Law Firm Cyber Report · Sophos State of Ransomware 2025 · State Bar of Texas INC Ransom incident (Jan 2025) · CISA Alert AA24-038B (Volt Typhoon) · TX State Bar Ethics Opinions 680 (2018) and 705 (2025) · TDPSA (effective July 1, 2024) · ABA Formal Opinion 477R · CoreRecon Intelligence Research