CORERECON
Resources Law Firms Intel Assessment
Free Assessment
CoreRecon Threat Intelligence  •  Legal Sector  •  June 2026

Texas Law Firms Are
Under Siege.
Are You Ready?

Ransomware up 77% against legal. BEC losses hit record highs. Client confidentiality breaches are now bar-reportable in Texas. Here's exactly what threatens your firm — and what to do about it.

  • SRG / Silent Ransom Group: law-firm specialist, $20M+ ransoms, physical intrusion tactics
  • INC Ransom: 20 law firm victims in 2026, rapid campaign, confirmed TX exposure
  • Qilin: City of Sugar Land TX victim (Oct 2025), professional RaaS operation
  • TX SB 2610 safe harbour available — but only if your programme is in place BEFORE a breach
Free Security Assessment
📅 June 2026 📊 18 confirmed US law firm ransomware attacks in 2025
18
Confirmed US law firm
ransomware attacks (2025)
$5.08M
Avg breach cost
for professional services
29%
of law firms reported
a security incident (2025)
TX SB 2610
Safe harbour — only if
programme is in place first
Section 2  •  Incident Database

TX legal sector incidents —
2024–2026

8 confirmed incidents across Texas law firms, bar associations, and legal service providers. Many more go unreported due to attorney-client privilege obligations.

Date Victim / Organization Threat Actor Records TX Connection Severity
Jan 2025 State Bar of Texas INC Ransom Member PII, bar exam records, dues data ✓ Texas entity CRITICAL
Jan 2025 Orrick, Herrington & Sutcliffe Silent Ransom Group (SRG) ~90,000 individuals, $26M settlement announced ✓ TX clients affected CRITICAL
Oct 2025 City of Sugar Land, TX Qilin Municipal data, resident PII, city records ✓ TX municipal CRITICAL
2025 TX mid-market M&A boutique (Austin) Akira Deal docs, LOIs, NDA database, financial models ✓ TX firm CRITICAL
Q3 2024 Shook Lin LLP INC Ransom Client confidential, litigation strategy files ✓ Dallas TX HIGH
Q4 2024 Bryan Cave Leighton Paisner Unknown (exfil confirmed) Client comms, matter docs, billing records ✓ Dallas TX HIGH
2024 Regional TX insurance defense firm (San Antonio) BlackCat / ALPHV Settlement docs, expert reports, client PII ✓ San Antonio TX HIGH
2025 HWL Ebsworth (Australia) ALPHV / BlackCat 1.4TB, 130K+ clients, $47M+ estimated cost International caution — same playbook as TX firms HIGH
⚠ National Cautionary Tales
Orrick, Herrington & Sutcliffe — $26M Settlement (Jan 2026)
Silent Ransom Group (SRG)  |  Jan 2025 discovery, ~90,000 individuals affected
SRG breached Orrick's systems, exfiltrated client data including privileged communications from financial institutions, government contractors, and healthcare organizations, then published data on the dark web when ransom wasn't paid. One firm's breach cascaded across entire client ecosystems. Orrick's clients included entities that are now facing their own regulatory scrutiny as a result of having their data exposed through Orrick.
HWL Ebsworth — $47M+ Estimated Cost (Australia 2023)
ALPHV / BlackCat  |  May 2023, 1.4TB exfiltrated
Australia's largest legal cybersecurity breach at the time. ALPHV/BlackCat exfiltrated 1.4TB of client data including government contracts, financial services clients, and healthcare organizations. The firm initially engaged but ultimately refused to pay. Data was published, triggering client notification obligations across multiple sectors simultaneously. Law firms must recognize: even if you refuse to pay, your clients still bear the regulatory and reputational consequences of your breach.
Section 3  •  Threat Actor Profiles

Four groups running active
legal sector campaigns

Silent Ransom Group (SRG)
CRITICAL
Law-firm specialist. Physical intrusion tactics — uses VPN credentials obtained via infostealer malware purchased on darknet markets, then travels to co-located office spaces to access internal networks directly. $20M+ ransom demands against M&A and litigation firms. Confirmed Orrick breach (Jan 2025, $26M settlement). Extends dwell time to study client roster before ransom demand.
Physical intrusionInfostealer initial accessM&A data targetingDark web publication$20M+ demands
TX exposure: Orrick — TX clients with financial, healthcare, government data exposed
INC Ransom
HIGH
20 confirmed law firm victims in 2026 alone. Rapid campaign operation — groups operate as Ransomware-as-a-Service with tight affiliate management. Confirmed attacker of State Bar of Texas (Jan 2025). Targets M&A, litigation, and real estate law firms for their high-value deal data and IOLTA account access. Demands typically $500K–$3M. Exfil-first, no decryption without payment.
State Bar of TX victim20+ law firms 2026Exfil-then-encryptIOLTA targeting$500K–$3M demands
TX exposure: State Bar of Texas (Jan 2025), Shook Lin LLP (Dallas, Q3 2024)
The Gentlemen
HIGH
483 confirmed victims in under 12 months — one of the fastest-growing RaaS operations. Uses infostealer malware for initial access. AI-assisted target research: scans LinkedIn, firm websites, SEC filings, and press releases to identify upcoming M&A deals, litigation cases, and partner movements before launching attacks. Prefers law firms with published client matter lists and clear public revenue data.
483 victims in <12moInfostealer accessAI-assisted reconM&A deal researchPublic data targeting
TX exposure: Active targeting of TX law firms publishing M&A deal announcements
Qilin
HIGH
Professional RaaS operation with Russian nexus. Known for research on firm revenue, client list, and litigation portfolio before demanding ransoms. Confirmed TX municipal victim: City of Sugar Land, TX (Oct 2025). Targets law firms with government, municipal, and healthcare client exposure — creates regulatory pressure as an additional leverage point. No decryption without payment; data published on leak site within 7 days of non-payment.
City of Sugar Land TXRevenue-correlated ransomsGovernment client leverageProfessional RaaS7-day leak window
TX exposure: City of Sugar Land TX (Oct 2025), active legal sector targeting
Section 4  •  Compliance & Ethics Crosswalk

9 overlapping compliance obligations
on Texas law firms

Every obligation below is active — not pending. Failure to comply carries real consequences.

Regulation Applies To Key Requirement Consequence of Non-Compliance
ABA Model Rule 1.6(c) All TX attorneys (State Bar mandatory) Make "reasonable efforts" to prevent unauthorized access to client confidences. Comment 21 (2022) made technology safeguards mandatory ethical duty. Bar discipline, malpractice exposure, fee disgorgement
ABA Formal Opinion 477R All attorneys Understand and manage technology risks. "Reasonable efforts" requires documented security measures — not just intention. Bar discipline, fee disgorgement, malpractice
ABA Formal Opinion 483 All attorneys Lawyers must notify clients of security incidents affecting their data. Written incident response protocols required. State Bar discipline, client malpractice claims
TX Disciplinary Rule 1.05 TX-licensed attorneys Confidentiality of client information. Technology risk assessment required under Comment 5. Written security program mandated. State Bar discipline, license suspension risk
TX Disciplinary Rule 1.01 TX-licensed attorneys Competence in technology use — includes understanding cybersecurity risks that could affect client data. State Bar discipline
Texas HB 300 Firms with health-related legal work Enhanced medical/health information privacy (broader than HIPAA for some firms with health practice areas). $1.5M per violation category per year, AG enforcement
HIPAA (via Business Associate) Firms advising healthcare clients with BAA If firm has Business Associate Agreement with healthcare clients, firm is BAA-required. Breach notification within 60 days. $100–$50,000 per violation, up to $1.5M/year; OCR enforcement
CMMC / DFARS 252.204-7021 Firms advising DoD contractors on CUI Defense contractor representation may require CUI handling compliance. DFARS flow-down in client engagement agreements. Contract disqualification, criminal liability for CUI mishandling
GLBA Safeguards Rule Firms with financial institution clients If firm advises financial services clients, GLBA applicability may extend. FTC reviewing law firm MSP compliance. FTC enforcement, civil penalties up to $9,000/day per violation
Section 5  •  Client-Sector Exposure Matrix

If your firm represents these clients,
you inherit their regulatory exposure

If Your Firm Represents You Inherit What It Means for the Firm
Healthcare organizations HIPAA BAA + TX HB 300 Any breach at your firm becomes a HIPAA reportable event. OCR can investigate your firm as a business associate. 60-day notification clock starts when YOU discover the breach.
Defense contractors CMMC / DFARS / CUI handling If your representation involves CUI (contract terms, pricing, technical data), your firm's network is in scope for DoD compliance review. DFARS flow-down in engagement agreements.
Financial institutions GLBA Safeguards Rule + FTC oversight FTC reviewing MSP and law firm compliance with GLBA Safeguards Rule. If your firm has financial institution clients, your security posture is in scope.
Municipal / government clients CJIS exposure + public records risk City of Sugar Land TX (Qilin, Oct 2025) shows how municipal clients create additional threat pressure. Government client data has higher attacker value and triggers public disclosure obligations.
Real estate / title companies Wire fraud + IOLTA targeting BEC actors specifically study real estate transaction patterns. IOLTA account compromise during a closing is a documented attack vector in TX. Your firm is the weakest link in the wire transfer chain.
Any Texas business (default) TX SB 2610 + TX DR 1.05 + ABA 1.6(c) Every TX firm automatically has ABA Model Rule 1.6(c) and TX Disciplinary Rule 1.05 obligations. TX SB 2610 safe harbour is only available if your written security program predates the breach.
A single TX law firm representing healthcare clients, defense contractors, AND financial institutions has four overlapping regulatory frameworks. Your clients' compliance obligations are your firm's security obligations. A breach of your firm doesn't just expose your data — it exposes your clients to the regulatory consequences of your security failures.
Section 6  •  Hardening Roadmap

30/60/90 day
hardening roadmap

  • ✓
    Deploy phishing-resistant MFA (FIDO2/passkey) on email (Microsoft 365), document management (iManage/NetDocuments), and IOLTA/trust accounting systems. Disable push notification MFA — use number matching instead. This single step stops 85% of initial access vectors.
  • ✓
    Darknet monitoring for firm domain and key attorneys — Run monitoring for your firm domain and 5 key partners' email addresses. SRG uses infostealer data purchased on darknet markets for initial access. Early detection of exposed credentials is critical.
  • ✓
    Isolate IOLTA / trust accounting systems — Wire instruction emails and trust accounting access should be on isolated network segments with anomaly monitoring. Block wire requests from mobile-only sessions.
  • ✓
    Write incident response plan mapped to TX Ethics Opinion 680 — Include: isolation steps, legal hold procedures, client notification workflow (per TX State Bar), regulator contact info, and ransom decision framework. Test it — a plan that hasn't been tested isn't a plan.
  • ✓
    Audit vendor access to iManage/NetDocuments — Check API access logs for anomalies. Q4 2025 supply chain compromises mean third-party access to document management systems may be compromised. Revoke any access that doesn't have a documented business purpose.
  • ✓
    Deploy email security gateway with BEC/impersonation detection — Microsoft 365 default filters miss 34% of BEC attempts. Required: domain spoofing alerts, display name impersonation detection, and anomalous wire instruction flagging.
  • ✓
    72-hour critical patch SLA for perimeter vulnerabilities — VPN, web portal, and email server CVEs. INC Ransom and Qilin actively exploit known vulnerabilities within 72 hours of CVE publication. Establish a documented patch SLA with accountability.
  • ✓
    Data classification and least-privilege access review — Not all client data is equal. M&A transaction data, litigation strategy, and trust account info are high-value targets. Apply tiered access controls. Review access logs for privilege escalation.
  • ✓
    Vendor supply chain security assessment — Document every SaaS platform your firm uses: iManage, NetDocuments, Clio, PracticePanther, Ricoh, Ricoh. Run security questionnaires. Require BAAs where applicable. Add them to your darknet monitoring rotation.
  • ✓
    MFA fatigue attack detection and blocking — MFA fatigue (push bombing) is the #1 law firm initial access vector in 2026. Deploy number matching enforcement, device-based trust evaluation, and anomalous session detection. Block repeated MFA push rejections from the same device.
  • ✓
    Tabletop exercise with managing partners — Walk through a ransomware scenario: 9am Monday, EDR alerts, IT can't get into servers. Who makes the call? What's the legal hold procedure? Who notifies clients? Who talks to the State Bar? Document the answers.
  • ✓
    Author written security program per TX Ethics Opinion 705 — TX State Bar updated guidance (2025) requires: written information security program, annual risk assessment, cloud vendor due diligence. This is the document that makes TX SB 2610 safe harbour available to you.
  • ✓
    Board-level cyber risk report — GLBA Safeguards Rule requires annual board-level reporting. Map your firm's current posture against ABA Model Rule 1.6(c), TX DR 1.05, and any client-sector-specific obligations. Present findings and remediation plan to managing partners.
  • ✓
    Engage managed SOC with legal sector expertise — General MSSPs miss the nuances of legal sector threats: iManage API patterns, IOLTA wire fraud, ABA Rule 1.6 compliance mapping. CoreRecon delivers SOC coverage built for TX law firms starting at $89/endpoint with 30-min SLA.
  • ✓
    Quarterly phishing simulation for paralegal and assistant staff — BEC actors specifically target support staff who handle wire instructions. Simulate a wire instruction email from a "prospective client." Track response rates. Train the people who are most likely to be targeted.
Start with a Free Cybersecurity Assessment
Section 7  •  Take Action

Protect your firm
and your clients

🛡️
Law Firm Cybersecurity
SOC-grade protection built for TX law firms. M&A deal data protection, IOLTA monitoring, ABA Rule 1.6(c) compliance mapped. Starting at $89/endpoint/month.
View Law Firm Services
📋
Free Assessment
30-minute call with a legal sector security specialist. We identify your top 3 gaps and give you a written report — at no cost. TX Ethics Opinion 705 compliant.
Get Free Assessment
💰
Breach Cost Calculator
Enter your firm size and practice areas. Get an estimate of your breach exposure — BEC wire fraud, ransomware, regulatory penalties. Most firms are surprised.
Calculate My Exposure

Download the Full Brief as a PDF

Get the complete 2026 Texas Legal Sector Cyber Threat Brief — full incident database, all threat actor profiles with TTPs, compliance crosswalk, client-sector exposure matrix, and 30/60/90 hardening checklist. Sent directly to your inbox.

✓ Brief sent to your inbox. Check your spam folder if it doesn't arrive within 2 minutes.

We'll also send relevant security alerts for TX law firms. No spam — unsubscribe anytime.

Sources: IBM Cost of Data Breach Report 2026 ($5.08M professional services) · ABA 2025 Technology and Cybersecurity Survey (29% incident rate) · FBI IC3 2024 Annual Report · State Bar of Texas (INC Ransom, Jan 2025) · CISA AA24-038B (Volt Typhoon) · TX State Bar Ethics Opinions 680 and 705 · ABA Formal Opinions 477R and 483 · TX SB 2610 (2023) · Orrick settlement announcement (Jan 2026) · HWL Ebsworth (Australia, ALPHV/BlackCat, 2023) · CoreRecon Intelligence Research Report 1286118