Last month, Seyfarth Shaw LLP disclosed, through notices filed in Texas and California, a data breach from the summer in which over 300 people's names and Social Security numbers were exposed.
Also in September, the California Attorney General's Office disclosed a letter from Tarter Krinsky & Drogin LLP detailing a cyberattack on the firm from September 2025 that may have compromised patient health information stemming from the firm's representation of a healthcare provider.
Firms including Blank Rome LLP, Fox Rothschild LLP and WilmerHale were hit with class actions from clients alleging damages due to cyberattacks over the summer.
The recent increase has been fueled in part by AI tools that have made it easier for hackers to pursue attacks based on social engineering, or play on psychological weaknesses to pressure people into giving away confidential information.
"It's the Wild West out there," said Scott Bailey, managing partner at the digital forensics firm N1 Discovery, adding that AI is helping threat actors move at "light speed."
In the Seyfarth Shaw attack, for instance, a hacker impersonated the firm's information technology help desk and tricked a firm employee into emailing client documents to an outside email account, according to the firm's account of the attack.
Seyfarth Shaw did not respond to requests for comment for this article. Tarter Krinsky reiterated a previous statement about its attack, stating that it became aware of a breach, investigated the matter with the help of external cybersecurity experts, and notified affected individuals and clients.
Cyberattacks in general are increasing — Law360 Pulse identified over 200 data breaches at law firms in 2025, the last year with complete data, which was the highest yearly total since 2020. Law firms are attractive targets because of the density of sensitive information they hold on a range of clients, and for years law has been within the top five industries to be hit with these kinds of attacks, according to Bailey.
Social engineering attacks used to be easier to spot over email, with characteristics like poor grammar or suspicious email addresses. Threat actors can now easily generate realistic-looking logos, or copy the exact wording or terminology of a firm's IT staff in a way that makes it harder to differentiate fakes from real communications, according to Megan Silverman, vice president of cyber solutions at legal services provider Integreon.
"AI makes it easier for a hacker in another country to sound like they're the lawyer two floors down from you, or a client asking for information," said Rebecca Rakoski, co-founder and managing partner at XPAN Law Partners, a cybersecurity and data privacy law firm.
AI makes other processes easier for threat actors, too, such as looking around in a firm or corporation's data. Scanning a hacked mailbox for valuable information used to be a time-consuming process assigned to a junior member of a threat actor organization, Bailey said.
"Now they just download the mailbox, they point AI at it and say, 'analyze this mailbox and tell me some attack vectors,' and 10 minutes later, or 10 seconds later, depending on how big the mailbox is, they've got an attack already lined up," he said.
In addition to the growing threat from AI, the nature of work in the legal industry in general continues to make law firms relatively attractive targets, security leaders said. Threat actors are generally moving "downstream" from corporations that have already been hit by cyberattacks and beefed up their defenses, Bailey said.
Law firms are organizations with a high density of sensitive client information, like litigation strategies and insight into possible transactions.
The nature of legal work — with lawyers frequently communicating with opposing counsel, new clients, vendors and witnesses over email under tight deadline pressure — creates conditions where social engineering attacks can succeed. Frank Gillman, principal at Vertex Advisors, said in an email that people often question how lawyers could fall for social engineering schemes, but they fail to understand that the schemes prey on the human side of business.
"Social engineering doesn't exploit stupidity," Gillman said. "What it exploits is trust, urgency and authority. Each of those things are normal human behaviors."
Rakoski and others stressed that being hit with a cyberattack doesn't necessarily mean a firm or corporation's security measures were deficient. Threat actors are constantly improving their tactics, leaving those on the defense with a daunting task to catch up.
"We have to be right 100% of the time," Rakoski said. "Employees have to be right 100% of the time; IT, security has to be right 100% of the time; but the threat actor only has to be right once."
--Editing by Robert Rudinger.
For a reprint of this article, please contact reprints@law360.com.