The digital age has brought countless benefits to the legal industry, but it has also opened the door to significant cybersecurity risks. Law firms are increasingly becoming prime targets for cybercriminals due to the sensitive and valuable data they handle. The statistics are alarming:
- The average ransom demand for legal organizations in 2023 was approximately $1 million USD.
- Only 26% of law firms believe their firm is “very prepared” to respond to cyber incidents.
- 60% of firms identified the sophistication level of threats and attacks as the biggest challenge they face in reducing cyber risk.
The Types of Cyber-Threats Law Firms Face
Law firms are up against a variety of cyber threats, each with the potential to cause significant damage. Some of the most common include:
- Ransomware: Malicious software that locks a firm’s data and demands payment for its release. It can paralyze operations and lead to substantial financial losses.
- Phishing: Deceptive emails designed to trick recipients into revealing sensitive information or downloading harmful software. These attacks are becoming increasingly sophisticated and hard to identify.
- Data Breaches: Unauthorized access to confidential information. This can result in the exposure of client data, leading to a loss of trust and potential legal consequences.
High-Profile Law Firm Cyber-Attacks in Recent Years
Cyberattacks on law firms are not hypothetical scenarios—they are real and happen with increasing frequency. Several high-profile incidents illustrate the severity and sophistication of these attacks.
Orrick, Herrington & Sutcliffe
Between February 28 and March 13, 2023, Orrick, Herrington & Sutcliffe in San Francisco suffered a data breach that affected over 637,000 individuals’ personal and health information. Hackers accessed names, addresses, dates of birth, and Social Security numbers. The firm did not disclose whether it paid a ransom; however, it agreed to an $8 million settlement.
While the exact methods used by the hackers to evade detection are not specified, it’s common for sophisticated attackers to use various techniques to maintain stealth, such as:
- Exploiting zero-day vulnerabilities
- Using advanced persistent threat (APT) tactics
- Employing malware designed to evade security software
- Mimicking normal network traffic patterns
Cravath Swaine & Moore and Weil Gotshal & Manges (New York):
Cravath Swaine & Moore and Weil Gotshal & Manges, two prominent New York-based law firms, were targeted by Chinese nationals in a significant cyber attack aimed at obtaining insider information for financial gain. The attackers breached the email accounts of senior lawyers at both firms, gaining unauthorized access to sensitive client information. Using this stolen information, the hackers engaged in insider trading, earning over $4 million in illicit profits.
This breach was part of a larger hacking campaign that targeted at least seven major international law firms, including Cleary Gottlieb, Mayer Brown, Latham & Watkins, Covington & Burling, and Davis Polk & Wardell.
Manitoba Law Firms:
Two law firms in Manitoba were hit by a ransomware attack known as MAZE, which locked their entire computer systems. The Law Society of Manitoba reported that the ransomware infection likely occurred when someone at the firms clicked on a malicious link or attachment in an email, which was disguised as COVID-19-related information. As a result, the firms lost access to their email systems, word-processing software, and accounting software.
Unable to access client files, emails, and financial information, these firms were forced to negotiate with cybercriminals. According to Chris Morales, head of security analytics at Vectra, MAZE has posted alleged stolen data from victim organizations, including multiple legal professional service providers, on their “Mazenews” site.