CoreRecon Threat Intelligence • Legal Sector • June 2026
Texas Law Firms: Under Siege. 2026 Briefing
45 ransomware attacks on law firms in 2024 — a record. $2.77B in BEC losses targeting legal practices. ABA Rule 1.6(c) now makes cybersecurity a formal ethical obligation. Texas firms face mounting privilege erosion, vendor supply chain risk, and bar disciplinary exposure.
15 documented incidents: Orrick ($8M), Jones Day (Accellion), HWL Ebsworth (ALPHV), Gunster ($8.5M), Kirkland, HPMB ($200K NY AG fine)
5 threat actor profiles: ALPHV/BlackCat, LockBit, Cl0p, Silent Ransom Group (FBI IC3 warning), INC Ransom
ABA Model Rule 1.6(c) + Texas TDRPC Rule 1.05 + TX SB 2610 safe harbor obligations
Ransomware attacks on law firms 2024 (record high, Black Fog)
$2.77B
FBI IC3 BEC losses 2024 21,442 complaints
29%
Law firms with confirmed breach (ABA Tech Report 2023)
1.5M+
Records compromised via legal tech vendor breaches 2024
Section 1 • Executive Summary
The threat is accelerating, not plateauing
Texas hosts the fourth-largest legal market in the United States, anchored by major corporate practices in Dallas, Houston, Austin, and San Antonio. The concentration of financial services, energy, healthcare, and technology clients in Texas law firms creates a target-rich environment for threat actors who recognize the extraordinary value of privileged communications and client financial data. ABA Model Rule 1.6(c), Texas Disciplinary Rule of Professional Conduct (TDRPC) Rule 1.05, client contractual security requirements, and increasingly sophisticated threat actors all converge on the same firm infrastructure.
01
Ransomware: A Record Year
45 ransomware attacks targeted law firms in 2024 — the highest annual figure since Black Fog began tracking in 2020. The 2025 figure nearly doubled that number. Baker & Hostetler's 2026 Data Security Incident Report confirmed law firm incidents "nearly doubled" in 2025 vs. 2024. 1.5 million+ records were compromised via legal vendor breaches alone. See Fortress coverage →
02
BEC / Wire Fraud: The $2.9B+ Threat
FBI IC3 recorded $2.77 billion in BEC losses from 21,442 complaints in 2024. Attorney/law firm impersonation accounts for 12% of all BEC attack types. Average loss per incident exceeds $125,000. Real estate closings and settlement disbursements are the highest-value wire fraud targets. Calculate your wire fraud exposure →
03
ABA Rule 1.6(c): Ethical Obligation, Not IT Preference
"Reasonable efforts" now includes MFA, 24/7 monitoring, documented incident response, and vendor due diligence. ABA Formal Opinion 483 (2018) is the most-cited opinion in bar disciplinary proceedings and malpractice litigation. The Orrick $8M settlement and HPMB $200K NY AG fine are the leading precedents. See ABA/TDRPC compliance requirements →
04
TX SB 2610 Safe Harbor: Do This or Face Punitive Damages
Effective September 1, 2025, Texas SB 2610 creates an affirmative defense to punitive damages for Texas businesses — including law firms — that implement NIST CSF, CIS Controls, or ISO 27001 before a breach. Firms that don't qualify face uncapped punitive exposure. See TX SB 2610 safe harbor guide →
Section 2 • TX Legal Sector Incident Database
15 documented incidents — law firms and legal tech vendors
Entries drawn from SEC 8-K disclosures, state bar breach notifications, court filings, and confirmed media reports.
#
Firm / Organization
Date
Type
Impact
01
Orrick, Herrington & Sutcliffe LLP
Mar 2023 (disclosed 2024)
Ransomware
600,000+ individuals' data exfiltrated. $8M class action settlement (Oct 2024). Publicly Disclosed
02
Jones Day
May 2023
Ransomware (Accellion)
184,000 files exfiltrated via compromised Accellion FTA. Publicly Disclosed
03
HWL Ebsworth (Australia)
Apr 2023
ALPHV/BlackCat
1.45TB client data published on dark web leak site (June 2023). ANZ Bank, federal government among clients. Publicly Disclosed
114,000 client records exposed. NY AG fined firm $200,000 for "poor data security" (failure to apply available patch). Publicly Disclosed
06
Gunster Yoakley & Stewart (Florida)
2022 (settled 2024)
Data Breach
~10,000 individuals' data exposed. Class action settled for $8.5 million (2024). Publicly Disclosed
07
Taft Stettinius & Hollister
Oct 2023 (disclosed 2024)
Ransomware
Unauthorized access to secondary servers; client and personal data exposed. Ranked #83 Am Law 100. Publicly Disclosed
08
Kirkland & Ellis
2023 (class action Jun 2024)
Ransomware
Class action filed over 2023 ransomware attack. Largest law firm in the world by revenue. Publicly Disclosed
09
Fried Frank Harris Shriver & Jacobson
2025 (2nd class action 2026)
Data Breach (SRG)
Second class action filed; hack attributed to Silent Ransom Group. Publicly Disclosed
10
Thompson Coburn LLP
2024
Data Breach
Settlement reached in class action stemming from 2024 breach. Publicly Disclosed
11
Wood Smith Henning & Berman
2024
Silent Ransom Group
Named as Silent Ransom Group victim (insurance defense and professional liability). Publicly Disclosed
12
Grubman Shire Meiselas & Sacks
2020
Ransomware ($42M demand)
Entertainment law firm. $42M ransom demanded; celebrity client data exfiltrated. Prefigured BEC/ransomware convergence. Publicly Disclosed
13
Houser LLP
May 2023 (disclosed 2024)
Ransomware
Files encrypted; firm discovered May 2023. Part of 21 law firm data breaches recorded H1 2024. Partially Disclosed
14
DocketWise (legal immigration SaaS)
2024
Supply Chain
116,666 immigration records exposed via vendor security failure. Partially Disclosed
15
American Bar Association
Mar 2023
Account Compromise
1.5 million lawyers' login credentials potentially stolen from ABA website account database. Publicly Disclosed
Sources: Reuters (Orrick, Gunster); ABA Journal (Jones Day, Kirkland, HPMB); Arctic Wolf (HWL Ebsworth, Proskauer); The Record (HPMB NY AG fine); Above the Law (Kirkland class action); Law.com/American Lawyer (Fried Frank, Thompson Coburn); Baker & Hostetler DSIR 2026; ComplexDiscovery (DocketWise); SecurityWeek (ABA breach). Full sources at end of brief.
Section 3 • Threat Actor Profiles
Five groups with active legal sector campaigns
ALPHV / BlackCat
CRITICAL
RaaS · DarkSide/BlackMatter lineage · Financial · (Effectively discontinued late 2024; playbook persists via successors)
Rust-based cross-platform ransomware with VMware ESXi targeting, Cobalt Strike deployment, and double-extortion. Hit HWL Ebsworth (Australia, April 2023 — 1.45TB published on dark web leak site). The group specifically targeted organizations with high data sensitivity and limited security maturity: law firms fit both criteria.
T1486 Data Encrypted for ImpactT1484.002 Direct SyscallsT1048.003 Exfil to Cloud StorageT1021.007 RDP lateral movementT1114.002 OAuth token theft
TX exposure: ALPHV/BlackCat's playbook — exfil, then threaten client disclosure — is the template used by successor groups targeting TX firms. The HWL Ebsworth model (publish privileged client communications) is the ultimate coercion.
CoreRecon callout: CoreRecon's 30-minute IR SLA covers containment before exfil completes. ABA Formal Opinion 483 post-breach documentation is included in all tiers. See law firm coverage →
LockBit
CRITICAL
RaaS · Historical dominance · Financial · (Disrupted by law enforcement 2024; affiliate activity continues)
One of the most historically destructive ransomware groups in operation. Claimed responsibility for data breach at Allen & Overy (UK Magic Circle firm) in November 2023. The firm's M&A, private equity, and litigation workload data made it a maximally high-value target. LockBit's affiliate model means the group's playbook survives its disruption.
T1190 RDP/VPN exploitationT1078.004 Valid accountsT1048 Exfil via custom stagingT1486 Data Encrypted for ImpactT1083 File/Directory Discovery
TX exposure: LockBit's targeting of firms with M&A, private equity, and litigation workloads directly matches the profile of Texas major law firms in Dallas and Houston. The affiliate model means local TX actors may be running LockBit-variant attacks.
CoreRecon callout: CoreRecon's behavioral analytics detects LOLBin activity associated with LockBit's post-compromise playbook. Assess your vendor risk →
Cl0p (CLOP)
CRITICAL
RaaS · Supply chain specialist · File transfer exploitation
The group behind two of the most consequential supply chain attacks in legal sector history: the Fortra GoAnywhere MFT exploit (2023) and the Cleo file transfer exploit (late 2024). Cl0p specifically targets file transfer software because of the sensitive documents that flow through these platforms — exactly what law firms use to exchange privileged client materials.
CVE-2024-50623 Cleo zero-dayCVE-2024-55956 Cleo zero-dayT1190 Exploitation of MFT softwareT1048.003 Exfil to CloudT1027 Obfuscated Files
TX exposure: The Cleo exploit (Oct–Dec 2024) affected law firms using Cleo products for client document exchange. Hertz (whose legal department used Cleo) and Western Alliance Bank confirmed breaches via this vector. Texas firms that use Cleo for M&A or litigation document exchange are in direct scope.
CoreRecon callout: CoreRecon includes Cleo and file transfer software vendor monitoring in all tiers. See vendor supply chain coverage →
Silent Ransom Group (SRG)
CRITICAL
Pure data extortion · Conti diaspora · PRC-adjacent · Active since Mar 2022
Silent Ransom Group emerged in March 2022 following the Conti ransomware syndicate's collapse. Unlike traditional ransomware groups, SRG operates a pure data extortion model — no file encryption, only exfiltration and threat of public disclosure. This model is particularly dangerous for law firms because privileged communications being published is an extraordinary form of leverage.
T1566 Phishing campaignsT1105 Ingress tool transferT1048 Exfil only (no encryption)T1562.001 Disable security toolsNo ransomware payload
TX exposure: FBI IC3 issued Private Industry Notice CSA 2025/250523 warning that SRG has specifically targeted law firms since spring 2023. Fried Frank and Wood Smith Henning & Berman are confirmed SRG victims. TX firms with M&A, litigation, and regulatory practices are in direct scope.
CoreRecon callout: SRG's no-encryption model bypasses traditional ransomware-focused controls. CoreRecon's exfil detection (network egress monitoring, DNS tunneling analysis) catches SRG's footprint. Request exfil detection assessment →
INC Ransom is a RaaS group that uses double-extortion tactics and has specifically accelerated targeting of law firms in 2025–2026. Halcyon confirmed INC Ransom is actively running campaigns specifically targeting the legal sector. The group publishes victim listings on its dark web leak site when ransom demands are not met.
T1190 Exploitation of external remote servicesT1021.007 RDP lateral movementT1486 Data Encrypted for ImpactT1048 Exfil to dark web leak siteT1490 Inhibit System Recovery
TX exposure: Halcyon tracked 200+ ransomware incidents targeting law firms between 2025 and early 2026, with INC Ransom among the most active groups. TX firms that handle real estate closings, M&A, and litigation are in direct targeting scope.
CoreRecon callout: INC Ransom's dwell time is shorter than legacy groups — speed of containment matters. CoreRecon's 30-minute IR SLA is designed for groups like INC. See incident response capabilities →
Section 4 • ABA Model Rule 1.6(c) + Texas Disciplinary Rules
Cybersecurity is no longer an IT preference
ABA Model Rule 1.6(c) makes cybersecurity a formal ethical obligation — not an IT preference. Texas TDRPC Rule 1.05 mirrors the ABA standard. The consequences of failure include bar disciplinary proceedings, malpractice litigation, and client relationship damage that extends well beyond any regulatory fine.
⚖️
ABA Model Rule 1.6(c)
The National Standard
"A lawyer shall make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." Added in the 2012 Ethics 20/20 amendments — a categorical shift.
ABA Formal Opinion 477R (2017): Security of client communications — requires lawyers to understand the technology they use and assess risks to confidentiality
ABA Formal Opinion 483 (2018): Post-breach obligations — monitoring, stopping unauthorized access, remediation, affected client notification. Most cited in bar disciplinary proceedings
ABA Formal Opinion 498 (2021): Remote practice and cybersecurity when lawyers work outside the office
Rule 1.1 Comment [8]: Technology competence is part of the duty of competence
Texas has adopted the substance of ABA Model Rule 1.6(c) through Texas TDRPC Rule 1.05. Texas lawyers are subject to the same reasonable-efforts standard. Texas SB 2610 (89th Legislature, effective Sept 1, 2025) creates a safe harbor — implementing NIST CSF, CIS Controls, or ISO 27001 eliminates punitive damages in breach scenarios.
TDRPC Rule 5.1: Partners/managers have supervisory obligations over associates' technology practices — including IT vendors and cloud providers
TDRPC Rule 1.05: Mirrors ABA Model Rule 1.6(c) — reasonable efforts standard for protecting client information
Cost/difficulty factor: Comment [18] to Rule 1.6 — cost is a factor, not a blanket exemption. HPMB ($200K NY AG fine for failing to apply a patch) is the leading precedent
TX SB 2610 Safe Harbor — What You Need to Do: Firms with 20–99 employees need CIS Controls Implementation Group 1 (IG1) implementation. Firms with 100+ need full framework implementation with documented evidence. Firms under 20 employees need password policies and annual training. The deadline is immediate — the safe harbor only applies to programs already in place when a breach occurs. CoreRecon can help you build a documented cybersecurity program that qualifies for safe harbor. Request a TX SB 2610 compliance gap assessment →
📋
The Texas State Bar has issued guidance on technology obligations and the ABA's formal opinions have been cited in disciplinary proceedings. Firms should consult the State Bar of Texas cybersecurity resources and the Texas Bar Journal (January 2026) for current guidance on bar compliance obligations.
Section 5 • BEC and Wire Fraud in Legal Workflows
The $2.9B+ threat — law firms are the #1 BEC target
FBI IC3 2024 Annual Report: $2.77 billion in BEC losses from 21,442 complaints in 2024 alone. Attorney/law firm impersonation represents 12% of all BEC attack types. Average loss per incident exceeds $125,000. Texas real estate wire fraud alone reached $446 million in Q1 2026 — a 34% increase over Q1 2025. Wire transfers cannot be recalled once sent. FBI IC3 Recovery Asset Team (RAT) has a 66% freeze rate — but only when the victim reports within hours.
The BEC Attack Pattern — 4 Steps to Irreversible Loss
01
Email Compromise
Phishing or credential stuffing compromises a law firm employee's email — or spoofing of partner's email domain
At the exact moment a wire transfer is expected — real estate closing, settlement disbursement, retainer refund — fraudulent instructions sent
04
Irreversible Loss
Wire transfers cannot be recalled. Funds move through multiple accounts and leave the country. Firm bears liability to client.
Legal-Specific BEC Attack Vectors
🏠
Real Estate Closings
The "wire fraud kill zone" for Texas law firms. Texas real estate transactions are prime targets. FBI IC3 reported $446M in Q1 2026 alone. Attackers compromise title company or real estate agent email accounts, then send fraudulent wiring instructions to buyers expecting closing instructions.
⚖️
Settlement Disbursements
Settlement wires in litigation and M&A transactions move large sums with minimal verification. The "client" sends revised wiring instructions at the last moment — standard in major transactions, which is exactly what makes the attack so plausible.
👔
Attorney Impersonation
Crimson Kingsnake BEC group used 92 malicious domains targeting 19 law firms across the US, UK, and Australia. Fake invoices from impersonated attorneys induced accounting staff to pay fraudulent bills. Escalated by impersonating company executives to authorize payment.
📧
Spoofed Firm Email
Lookalike domains: @firmsname-law.com vs. @firmsname.com. Compromise of a paralegal/associate email, then instructions to a law clerk for a wire. Impersonation of opposing counsel in real estate and M&A transactions. "Urgent" requests from "senior partners" to junior staff for immediate transfers.
Section 6 • Client Confidentiality and Privilege Erosion
When ransomware means privilege dies
When ransomware operators exfiltrate client files — rather than simply encrypting them — the breach extends beyond operational disruption into attorney-client privilege and professional responsibility. The Orrick $8M settlement, HPMB $200K NY AG fine, and ABA Formal Opinion 483 have collectively defined what "reasonable efforts" looks like in 2026.
01
The HPMB Precedent
A law firm failed to install an available security patch. Ransomware followed. NY AG fined the firm $200,000 — not for the breach itself, but for the failure to implement reasonable security controls. The precedent is clear: a firm without basic patch management is not making "reasonable efforts" under Rule 1.6. See NY AG press release →
02
The Orrick Precedent
600,000 individuals' data exposed in the Orrick breach. $8M settlement, ongoing client relationship damage. Corporate clients whose M&A strategy and transaction details were exposed face regulatory and litigation exposure of their own. Embroker research: 40% of clients consider firing their firm after a security incident.
03
ABA Formal Opinion 483 — Post-Breach Obligations
After a breach, lawyers must evaluate whether disclosure to clients is required — and the duty is affirmative. In SEC v. Covington & Burling (D.D.C. 2023), the firm was ordered to disclose to the SEC the identities of seven clients whose files had been compromised, because the non-public information was material to securities transactions. See NYC Bar Formal Opinion 2024-3 →
04
Malpractice Exposure
Plaintiffs' attorneys now use ABA Formal Opinions as evidence of what "reasonable care" looks like — the bar has been raised by the opinions themselves. Exfiltrated M&A strategy, litigation positions, and settlement discussions reaching opposing parties creates malpractice exposure that extends well beyond the breach itself.
Section 7 • Vendor and Supply Chain Risk in Legal Tech
Your vendor's breach is your breach
ABA Formal Opinion 483 requires lawyers to conduct due diligence on their technology vendors' security controls. The DocketWise immigration breach (116,666 records), Clio/Cleo supply chain attack (Cl0p, Oct–Dec 2024), and iManage on-prem vulnerability (2024) all demonstrate: firms that didn't vet their vendors are exposed to the same consequences as firms that were directly hacked.
Vendor / Product
Type
Risk Description
TX Exposure
Cleo / Cleo Harmony
MFT / File Transfer
Cl0p zero-days CVE-2024-50623, CVE-2024-55956 exploited Oct–Dec 2024. Hertz legal dept and Western Alliance Bank (22,000 customers) confirmed breaches via this vector.
Critical
Accellion FTA
MFT / File Transfer
Jones Day (184,000 files) and multiple law firms compromised via Accellion zero-day exploitation 2020–2021. Accellion discontinued FTA in April 2021; legacy instances remain exposed.
High
iManage (on-prem)
Document Management
Critical data exfiltration vulnerability in on-premises Work Server versions 9.4, 9.5, and 10.x. Firms running Work without upgrading to version 10.2.2.260 or later were exposed.
High
DocketWise
Practice Management (Immigration)
116,666 immigration records exposed via security failure at legal immigration SaaS vendor. Client identities, case strategies, and sensitive immigration statuses publicly accessible.
Critical — immigration attorneys
Clio
Practice Management
Part of Clio/Cleo supply chain analysis. Cleo vulnerability affected Hertz legal department — firms using Cleo for document exchange with Clio-integrated workflows are exposed.
Moderate
NetDocuments
Document Management
NetDocuments UK ICO analysis found 39% increase in legal sector data breaches Q3 2023–Q2 2024, affecting 7.9 million people. Phishing (56%) and insider threats (50%) primary vectors.
High — all firms on NetDocs
Vendor Due Diligence Is Not Optional. ABA Formal Opinion 483 states that lawyers must vet third-party providers' security posture and include breach notification requirements in vendor contracts. The NYC Bar's Formal Opinion 2024-3 further clarifies that when a vendor-related incident occurs, the firm must act reasonably and promptly to mitigate damage — and the firm's ethical duty doesn't pause because the breach originated at a third party. Use the CoreRecon Vendor Risk Scorecard to assess your legal tech vendor security posture.
Section 8 • What a 30-Min SOC Catches
The gap that kills: no 24/7 monitoring
Most small and mid-size law firms in Texas lack 24/7 security monitoring. They rely on daytime IT support, consumer-grade antivirus, and the hope that nothing happens between 6 PM Friday and 9 AM Monday. The average ransomware dwell time — the period between initial access and detection — is 26 days across all industries. For law firms, which may have lower security maturity, dwell times can be significantly longer. A 24/7 SOC detects intrusions in minutes to hours — not weeks.
🛡️
Sentinel
Core monitoring + alerting + monthly reporting
Foundation SOC coverage for solo practitioners and small firms (1–10 attorneys) handling standard business transactions, real estate closings, and general civil matters.
Best for: Solo/small firms, low threat profile
Email security monitoring (BEC detection)
MFA enforcement across firm accounts
Monthly threat intelligence digest
Incident response procedure documentation
Vendor risk scorecard review
🏰
Fortress
Full SOC + endpoint protection + incident response
Complete security coverage for mid-size firms (10–100 attorneys) handling M&A, litigation, real estate transactions, regulatory matters, and client data that represents material non-public information.
Maximum coverage for large firms, multi-office practices, and firms with regulatory obligations (SEC, FINRA, state bar) and high-value client data requiring privileged communication protection.
Best for: Large firms, multi-office, high-value data
Everything in Fortress, plus:
Advanced exfil detection (SRG defense)
Continuous compliance monitoring (ABA 1.6, TDRPC 1.05)
Red team / penetration testing annually
Securities/regulatory incident coordination
Board-level incident reporting
Free Posture Assessment: Every CoreRecon engagement begins with a no-cost cybersecurity posture assessment that maps your current controls against ABA Rule 1.6 requirements, Texas TDRPC Rule 1.05, and applicable CIS Controls — giving you a documented record of your "reasonable efforts" baseline for TX SB 2610 safe harbor qualification. Request your free assessment →
Your Next Move
Start with your next move
🔒
Free Security Assessment
30-minute call with a CoreRecon security engineer. Map your exposure against the TX legal threat landscape — ABA 1.6(c), TDRPC 1.05, BEC wire fraud, and vendor supply chain risk.
Calculate your firm's wire fraud exposure by transaction volume, practice area, and Texas metro area. Benchmark against the $446M Q1 2026 TX real estate fraud figure.
Assess your legal tech vendor security posture — Clio, iManage, NetDocuments, Cleo, and more. 15-question assessment with vendor security benchmarking.
Yes — and the 'limited resources' argument is the most-cited but least-defended excuse in bar disciplinary proceedings. Comment [18] to Rule 1.6 makes clear that cost and difficulty are a factor, not a blanket exemption. Small firms with limited budgets must still implement basic controls: MFA on all accounts, tested backups, device encryption, and a documented incident response plan. The HPMB case ($200K NY AG fine for failure to apply an available security patch) is the leading precedent — the firm was small, not exempt.
Insurance is risk transfer, not risk reduction. Post-2021, cyber insurers have dramatically tightened underwriting — most policies now require MFA documentation, verified backup architecture, tested IR plans, and vendor due diligence as preconditions for ransomware coverage. A cyber insurance payout doesn't restore client privilege, recover exfiltrated M&A strategy, or satisfy your ABA Rule 1.6(c) duty of confidentiality. The Orrick $8M settlement and Gunster $8.5M settlement were both paid on top of whatever insurance recovery was available.
ABA Formal Opinion 483 says lawyers must evaluate whether disclosure to clients is required — and the duty is affirmative, not discretionary. In the context of BEC: if client funds were stolen via a compromised firm email account, the client's financial interest was directly affected. That's material. ABA Opinion 483 applies to any breach of 'information relating to the representation of a client' — which includes client financial data, privileged communications, and matter strategy. When in doubt, disclose. The liability for not disclosing a reportable incident far exceeds the client relationship risk of disclosure.
ABA Formal Opinion 483 requires lawyers to conduct due diligence on their technology vendors' security controls. This is not optional. The NYC Bar's Formal Opinion 2024-3 further clarifies that when a vendor-related incident occurs, the firm must act reasonably and promptly to mitigate damage — and the firm's ethical duty to clients doesn't pause because the breach originated at a third party. The DocketWise immigration breach (116,666 records) and the Clio/Cleo supply chain attack (Cl0p, Oct–Dec 2024) both demonstrate: firms that didn't vet their vendors are exposed to the same consequences as firms that were directly hacked.
In 2026, 'reasonable efforts' includes: MFA on all email, practice management, and file transfer accounts; 24/7 monitoring or managed detection; documented incident response plan tested at least annually; vendor security due diligence with attestations; tested offline backups; and breach notification procedures aligned with ABA Formal Opinion 483. ABA Formal Opinion 483's post-breach obligations are the most frequently cited in bar disciplinary proceedings and malpractice litigation.