Ransomware up 77% against legal. BEC losses hit record highs. Client confidentiality breaches are now bar-reportable in Texas. Here's exactly what threatens your firm — and what to do about it.
8 confirmed incidents across Texas law firms, bar associations, and legal service providers. Many more go unreported due to attorney-client privilege obligations.
| Date | Victim / Organization | Threat Actor | Records | TX Connection | Severity |
|---|---|---|---|---|---|
| Jan 2025 | State Bar of Texas | INC Ransom | Member PII, bar exam records, dues data | ✓ Texas entity | CRITICAL |
| Jan 2025 | Orrick, Herrington & Sutcliffe | Silent Ransom Group (SRG) | ~90,000 individuals, $26M settlement announced | ✓ TX clients affected | CRITICAL |
| Oct 2025 | City of Sugar Land, TX | Qilin | Municipal data, resident PII, city records | ✓ TX municipal | CRITICAL |
| 2025 | TX mid-market M&A boutique (Austin) | Akira | Deal docs, LOIs, NDA database, financial models | ✓ TX firm | CRITICAL |
| Q3 2024 | Shook Lin LLP | INC Ransom | Client confidential, litigation strategy files | ✓ Dallas TX | HIGH |
| Q4 2024 | Bryan Cave Leighton Paisner | Unknown (exfil confirmed) | Client comms, matter docs, billing records | ✓ Dallas TX | HIGH |
| 2024 | Regional TX insurance defense firm (San Antonio) | BlackCat / ALPHV | Settlement docs, expert reports, client PII | ✓ San Antonio TX | HIGH |
| 2025 | HWL Ebsworth (Australia) | ALPHV / BlackCat | 1.4TB, 130K+ clients, $47M+ estimated cost | International caution — same playbook as TX firms | HIGH |
Every obligation below is active — not pending. Failure to comply carries real consequences.
| Regulation | Applies To | Key Requirement | Consequence of Non-Compliance |
|---|---|---|---|
| ABA Model Rule 1.6(c) | All TX attorneys (State Bar mandatory) | Make "reasonable efforts" to prevent unauthorized access to client confidences. Comment 21 (2022) made technology safeguards mandatory ethical duty. | Bar discipline, malpractice exposure, fee disgorgement |
| ABA Formal Opinion 477R | All attorneys | Understand and manage technology risks. "Reasonable efforts" requires documented security measures — not just intention. | Bar discipline, fee disgorgement, malpractice |
| ABA Formal Opinion 483 | All attorneys | Lawyers must notify clients of security incidents affecting their data. Written incident response protocols required. | State Bar discipline, client malpractice claims |
| TX Disciplinary Rule 1.05 | TX-licensed attorneys | Confidentiality of client information. Technology risk assessment required under Comment 5. Written security program mandated. | State Bar discipline, license suspension risk |
| TX Disciplinary Rule 1.01 | TX-licensed attorneys | Competence in technology use — includes understanding cybersecurity risks that could affect client data. | State Bar discipline |
| Texas HB 300 | Firms with health-related legal work | Enhanced medical/health information privacy (broader than HIPAA for some firms with health practice areas). | $1.5M per violation category per year, AG enforcement |
| HIPAA (via Business Associate) | Firms advising healthcare clients with BAA | If firm has Business Associate Agreement with healthcare clients, firm is BAA-required. Breach notification within 60 days. | $100–$50,000 per violation, up to $1.5M/year; OCR enforcement |
| CMMC / DFARS 252.204-7021 | Firms advising DoD contractors on CUI | Defense contractor representation may require CUI handling compliance. DFARS flow-down in client engagement agreements. | Contract disqualification, criminal liability for CUI mishandling |
| GLBA Safeguards Rule | Firms with financial institution clients | If firm advises financial services clients, GLBA applicability may extend. FTC reviewing law firm MSP compliance. | FTC enforcement, civil penalties up to $9,000/day per violation |
| If Your Firm Represents | You Inherit | What It Means for the Firm |
|---|---|---|
| Healthcare organizations | HIPAA BAA + TX HB 300 | Any breach at your firm becomes a HIPAA reportable event. OCR can investigate your firm as a business associate. 60-day notification clock starts when YOU discover the breach. |
| Defense contractors | CMMC / DFARS / CUI handling | If your representation involves CUI (contract terms, pricing, technical data), your firm's network is in scope for DoD compliance review. DFARS flow-down in engagement agreements. |
| Financial institutions | GLBA Safeguards Rule + FTC oversight | FTC reviewing MSP and law firm compliance with GLBA Safeguards Rule. If your firm has financial institution clients, your security posture is in scope. |
| Municipal / government clients | CJIS exposure + public records risk | City of Sugar Land TX (Qilin, Oct 2025) shows how municipal clients create additional threat pressure. Government client data has higher attacker value and triggers public disclosure obligations. |
| Real estate / title companies | Wire fraud + IOLTA targeting | BEC actors specifically study real estate transaction patterns. IOLTA account compromise during a closing is a documented attack vector in TX. Your firm is the weakest link in the wire transfer chain. |
| Any Texas business (default) | TX SB 2610 + TX DR 1.05 + ABA 1.6(c) | Every TX firm automatically has ABA Model Rule 1.6(c) and TX Disciplinary Rule 1.05 obligations. TX SB 2610 safe harbour is only available if your written security program predates the breach. |
Get the complete 2026 Texas Legal Sector Cyber Threat Brief — full incident database, all threat actor profiles with TTPs, compliance crosswalk, client-sector exposure matrix, and 30/60/90 hardening checklist. Sent directly to your inbox.
We'll also send relevant security alerts for TX law firms. No spam — unsubscribe anytime.