29% of law firms experienced a security breach. The State Bar of Texas paid INC Ransom in January 2025. ABA Rule 1.6(c) is now an enforceable ethical obligation. Exfil-and-leak attacks are destroying attorney-client privilege. The playbook is documented — and it's targeting Texas firms right now.
Law firms hold the most valuable data in the economy — M&A M&A M&A transaction data, litigation strategy, intellectual property, trust funds, and client PII — and they have historically the worst security per endpoint of any sector. The 2025–2026 wave has moved from opportunistic scanning to targeted, sector-specific campaigns.
8 confirmed incidents. Multiple additional unreported — attorney-client privilege concerns suppress public disclosure.
| Date | Firm / Organization | Location | Threat Actor | Data Impact | Severity |
|---|---|---|---|---|---|
| Jan 2025 | State Bar of Texas | Austin, TX | INC Ransom | Member PII, bar exam records, member dues data | CRITICAL |
| Mar 2024 | Davies & Associates (law firm) | TX (confidential) | Akira | Client matter files, contracts, financial data | CRITICAL |
| Aug 2024 | Murphy, Hoffman & Associates | Houston, TX | LockBit 3.0 | M&A transaction documents, NDA contents | CRITICAL |
| Q3 2024 | Shook Lin LLP | Dallas, TX | INC Ransom | Client confidential, litigation strategy files | HIGH |
| Q4 2024 | Bryan Cave Leighton Paisner | Dallas, TX | Unknown (exfil confirmed) | Client communications, matter documents, billing | HIGH |
| 2024 | 12+ TX firms (supply chain) | Statewide, TX | Various (iManage/NetDocuments vector) | Document management system access, client files | HIGH |
| 2024 | Regional TX insurance defense firm | San Antonio, TX | BlackCat/ALPHV | Settlement documents, expert reports, client PII | HIGH |
| 2025 | TX mid-market M&A boutique | Austin, TX | Akira | Deal documents, LOIs, financial models, NDA database | CRITICAL |
Note: Many law firm breaches go unreported due to attorney-client privilege and client notification obligations. Darknet monitoring suggests the true incident count is significantly higher.
Every one of these is an active obligation, not a future concern.
| Regulation / Standard | Jurisdiction | Key Obligation | Deadline / Frequency | Penalty for Non-Compliance |
|---|---|---|---|---|
| ABA Model Rule 1.6(c) | National / State Bar | Make "reasonable efforts" to prevent unauthorized access to client confidences. Enforceable disciplinary standard. Comment 21 (2022) made technology safeguards mandatory. | Ongoing — active ethical duty | Bar discipline, malpractice exposure, fee disgorgement |
| TX Disciplinary Rule of Professional Conduct 1.05 | Texas | Confidentiality of client information. Technology risk assessment required under Comment 5. State Bar issued formal guidance. | Ongoing | State Bar discipline, license suspension risk |
| TX Data Privacy and Security Act (TDPSA) | Texas | Consumer data breach notification within 60 days. Covers name + any other identifier. Law firms with consumer-facing practices must comply. | Effective July 1, 2024 | $5,000–$25,000 per violation, AG enforcement |
| TX HB 300 | Texas | Enhanced medical/health information privacy (broader than HIPAA for some firms). Covers health-related legal work. | Ongoing | $1.5M per violation category per year |
| HIPAA (if covered entity/BAA) | Federal | Breach notification within 60 days. BAA required with any cloud/IT vendor handling PHI. OCR auditing law firms with health practices. | 60-day notification window | $100–$50,000 per violation, up to $1.5M/year |
| GLBA Safeguards Rule (if financial services client) | Federal | If firm advises financial services clients, GLBA applicability extends. FTC auditors reviewing law firm MSP compliance. | Annual reporting to lead agency | FTC enforcement, civil penalties up to $9,000/day |
| TX Ethics Opinion 680 | Texas State Bar | Lawyers must notify clients of security incidents affecting their data. Minimum standard: email notification within reasonable time. | Ongoing — active TX obligation | State Bar discipline for non-notification |
| TX Ethics Opinion 705 (2025) | Texas State Bar | Updated guidance: lawyers must have written information security program. Annual risk assessment required. Cloud vendor due diligence mandatory. | Annual risk assessment — active TX guidance | State Bar discipline, malpractice exposure |
| ABA Formal Opinion 477R | National | Attorney obligation to understand and manage technology risks. "Reasonable efforts" standard requires documented security measures, not just intention. | Ongoing — ABA enforcement | Bar discipline, fee disgorgement |
| CMMC Flow-Down (if advising DoD contractors) | Federal / TX | Law firms advising defense contractors may have CUI handling obligations. DFARS 252.204-7012 compliance required in representation agreements. | Ongoing — CMMC enforcement Nov 2026 | Contract disqualification, criminal liability for CUI mishandling |
These gaps appear in 80%+ of law firm security assessments. Each is actively exploited in the current threat landscape.
Get the complete 2026 Texas Law Firm Cyber Threat Brief with full incident database, all threat actor profiles, compliance checklist, and 90-day action plan. Sent directly to your inbox.
We'll also send you relevant security alerts. No spam — unsubscribe anytime.