Throughout 2025, law firm BakerHostetler handled nearly 60 cybersecurity incidents targeting law firms - a figure that nearly doubled from their caseload in 2024. Of the 1,250 cross-industry incidents managed by BakerHostetler that same year, phishing tactics dominated, accounting for 30% of all attacks.
Greenberg Traurig reported that an unauthorized actor breached its systems, accessed several internal documents, and posted them on the dark web. A security flaw also struck Taft Stettinius & Hollister in March 2026, resulting in the exposure of clients’ Social Security numbers. In May, Herbert Smith Freehills Kramer was breached, compromising sensitive data such as Social Security numbers, government IDs, and client medical records.
WilmerHale, which suffered a breach in the same month, is now facing a class action lawsuit over the security incident. The wave of attacks continued with Goodwin Procter on August 7, followed by Quinn Emanuel on August 14 through social engineering.
Third-Party Vectors Become the Weak Link
In May 2025, Coinbase lost data belonging to 69,461 users after a criminal group bribed its overseas customer support agents. The stolen data included customer names, addresses, phone numbers, and photos of government IDs. Coinbase responded by refusing the attackers’ $20 million ransom demand and offering a bounty of the same amount for valid information leading to the hackers’ identities.
Ledger suffered a breach in January 2026 following a hack at its e-commerce partner, Global-e, which exposed order details of Ledger.com customers. A similar incident hit SafePal in August 2026 when a vulnerability in an order-tracking plugin exposed the personal data of roughly 39,798 buyers. The leaked data included names, emails, shipping addresses, phone numbers, and purchase details, though SafePal confirmed that wallet credentials and payment information remained secure.
How Users Are Affected
Trezor joined the list of victims after hackers infiltrated its third-party email provider. The attackers used that access to distribute phishing emails disguised as fake security alerts regarding STM32 hardware vulnerabilities, though the malicious domain has since been taken down.
For crypto users and legal clients alike, exposed contact information virtually guarantees inboxes will remain targeted by phishing traps - proving that safeguarding assets now requires far more than just securing passwords.
Reported via Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




