Legal — Cyber Threat Activity
Legal is a concentrated target that our incident log barely sees, holding one recorded claim against a sector where the actual exposure is severe. Law firms hold their clients' worst facts: litigation strategy, merger terms before announcement, regulatory investigation material, settlement positions and privileged communications, all assembled in one place and protected to a standard set by a partnership rather than by a regulator. That makes a firm a shortcut to information that would be far harder to take from the client directly. Our actor graph records 20 groups associated with the sector, including Medusa, RomCom, HAFNIUM, Everest, Silent Ransom Group and PEAR Team, with 15 malware families linked through those actors. The mix is instructive: extortion crews that specialise in data theft without encryption sit alongside state-sponsored operators, because for a law firm the threat of publication is leverage enough on its own and encryption adds nothing an attacker needs. State interest is documented as well, with espionage operators targeting firms advising on matters of geopolitical consequence; research on Chinese-linked maritime targeting found international law firms working on South China Sea disputes selected alongside shipbuilders and naval research centres. Legal is also structurally exposed through its own supply chain, since e-discovery platforms, transcription services and document management vendors concentrate privileged material across many firms at once. Read the near-empty incident count as an artefact of an industry with strong professional incentives not to disclose, and the actor associations as published research rather than attributions we have measured.
- Recorded incidents: 245
- Incidents, trailing 180 days: 23
- Tracked threat actors: 47
- Malware families: 24
Recent incidents
- singleton.com 2026-08-27
- Borchert & LaSpina 2026-08-18
- EvansPetree 2026-08-07
- Jakle & Alexander 2026-08-06
- Wacha Justen 2026-07-01
- https://sza.it/ 2026-06-30
- Berg Lilly 2026-06-18
- Greg Crosslin 2026-06-17
- Summa4 2026-06-15
- Plaxen & Adler 2026-06-10
- Iliff 2026-06-10
- Jeffrey Burr 2026-06-05
- Harrell Martin Peace 2026-06-04
- Peña & Bromberg 2026-05-28
- Vernon & Ginsburg 2026-05-21
- Blank Rome LLP 2026-05-21
- Hamer Childs 2026-05-20
- Louisiana Association for Justice 2026-05-15
- Mayer 2026-05-13
- Rivadeneyra Treviño 2026-05-12
Threat actors targeting Legal
- Qilin 54 incidents
- Akira 38 incidents
- INC Ransom 29 incidents
- SafePay 14 incidents
- Lynx Ransomware 13 incidents
- BianLian 12 incidents
- DragonForce 10 incidents
- Hunters International 9 incidents
- Cl0p 8 incidents
- Play Ransomware 8 incidents
- LockBit 7 incidents
- RansomHub 5 incidents
- Medusa Ransomware 4 incidents
- Sarcoma 4 incidents
- NightSpire 3 incidents
- Genesis 2 incidents
- Rhysida 2 incidents
- The Gentlemen 2 incidents
- BravoX 1 incident
- 8Base 1 incident
- ALPHV/BlackCat 1 incident
- Anubis 1 incident
- BlackSuit 1 incident
- Chaos 1 incident
Where these victims are
- United States 151
- Canada 13
- Germany 13
- Australia 5
- United Kingdom 5
- Brazil 4
- France 4
- Austria 3
- Italy 3
- Israel 2
- Singapore 2
- Turkey 2
Malware used against Legal
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PsExec Tool
- China Chopper Malware
- Empire Tool
- Havoc Malware
- Medusa Ransomware Malware
- NetSupport Manager Tool
- ProcDump Tool
- Rclone Tool
- Remcos Tool
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.