✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Law Practice/Law Firms
Breach intelligence, attack campaigns, and threat reports targeting the Law Practice/Law Firms sector.
Explore Other Sectors
Law Practice/Law Firms Threat Reports
Intellexa Predator Spyware Strikes Pakistani Civil Society via WhatsApp (2025)
In June 2025, a human rights lawyer based in Balochistan, Pakistan, was targeted by Intellexa's highly advanced Predator spyware via a malicious WhatsApp link, according to Amnesty International. This marks the first documented case of a civil society member in Pakistan being targeted by this tool. The attacker, likely operating with government-grade resources, used zero-day exploits and an advertising-based infection vector to bypass conventional defenses, aiming to infiltrate the lawyer's mobile device and access sensitive communications. This incident underscores the growing sophistication of spyware campaigns and the expansion of mercenary surveillance tools targeting individuals beyond political figures or journalists. It highlights the urgent need for robust communication security and regulatory scrutiny of commercial spyware vendors.
6 months ago
Kill Chain
BRG Ransomware Breach: How a 2025 Attack Unveiled Legal Sector’s Vendor Risk
In March 2025, Berkeley Research Group (BRG), a prominent consulting and legal advisory firm, suffered a devastating ransomware attack attributed to the RansomHub cybercriminal group. Attackers leveraged persistent dwell time to infiltrate BRG’s network, exfiltrated sensitive data including M&A intelligence and confidential client materials, and encrypted key systems. The breach occurred during BRG's $700 million buyout by TowerBrook Capital Partners, amplifying the incident’s impact and resulting in exposure of information related to hundreds of active deals and thousands of individuals. The attackers’ extortion included threats of blackmail and public data leaks, leveraging their knowledge of both firm structure and sensitive client engagements. This attack spotlights a surge in professional services sector targeting—especially legal and advisory firms—by highly organized ransomware groups in 2024–2025. Threat actors like RansomHub have adopted prolonged infiltration tactics, optimized affiliate compensation, and leveraged industrialized extortion, mirroring broader ransomware trends and underscoring urgent vendor risk management needs.
6 months ago
Kill Chain
How Attackers Used LastPass Inheritance Phishing to Breach Vaults in 2024
In June 2024, LastPass disclosed a targeted phishing campaign in which attackers sent fraudulent emails to customers, falsely claiming an access request to password vaults as part of a legacy inheritance process. These sophisticated phishing emails leveraged urgent social engineering tactics, such as fake death notifications, aiming to trick users into divulging their master passwords or clicking malicious links. Attackers subsequently attempted unauthorized access to vaults, raising concerns about potential credential compromise and data theft. This incident underscores the evolving threat landscape, where social engineering techniques and highly tailored phishing campaigns are targeting password managers and identity-centric security controls. As threat actors continue to exploit trust and human error, organizations must strengthen user awareness, enhance detection of inbound phishing, and revisit identity-based access protections.
6 months ago
Kill Chain
Iranian Nation-State Hackers Target John Bolton’s Email in 2021 Security Breach
In July 2021, former U.S. National Security Adviser John Bolton's personal email account was compromised by cyber actors believed to be linked to the Islamic Republic of Iran. The attackers gained unlawful access, extracted emails containing potentially sensitive information, and leveraged these materials to threaten and attempt to coerce Bolton, including by referencing classified content and threatening public disclosure. The FBI became aware when Bolton’s representative reported the intrusion and subsequent extortion attempts, with the threat actor referencing previous high-profile leaks to amplify pressure. It remains unclear if any sensitive materials were publicly disseminated, but the incident elevated concerns around the exposure of classified or sensitive government information through personal communication channels. This incident highlights a persistent risk from nation-state actors targeting senior government officials, leveraging cyber-intrusions for espionage and psychological operations. With the proliferation of similar tactics against political, governmental, and critical infrastructure targets globally, this attack reflects an urgent need for heightened security controls on personal communications of high-profile public figures.
6 months ago
Kill Chain
SEO Spam Surge: How Hidden Links Threaten Your Website's Reputation in 2025
In September 2025, numerous legitimate websites were compromised through the injection of hidden HTML blocks containing SEO spam links, primarily directing to pornographic and gambling domains. Attackers leveraged a variety of entry vectors, including exploited CMS vulnerabilities, compromised administrator credentials, outdated plugins, and insecure website templates, to insert invisible links that manipulated search engine rankings. The result was immediate: affected sites suffered sharp declines in search visibility, loss of reputation, visitor complaints, and in many cases, were misclassified as “Adult content” or “Gambling” by filtering systems. This exposed organizations to both operational and reputational damage, and in some circumstances, to regulatory or legal risks. The attack highlights an ongoing surge in web application compromise driven by automated tools and AI, accelerating the spread and sophistication of black hat SEO tactics. As search engines enhance their detection, attackers are turning to increasingly evasive techniques, stressing the urgent need for organizations to secure website platforms and adopt robust monitoring against such silent intrusions.
6 months ago
Kill Chain
RedNovember: Chinese State-Sponsored Espionage Campaign Hits Global Defense and Tech Sectors
Between June 2024 and July 2025, the Chinese state-sponsored threat group RedNovember (overlapping with Storm-2077 and formerly tagged as TAG-100) orchestrated a far-reaching cyber-espionage campaign targeting government, defense, and technology organizations globally. Leveraging weaponized perimeter device exploits and open-source tools like Pantegana and Cobalt Strike, the group gained initial access via widely used firewalls and VPNs, including SonicWall, Fortinet, Palo Alto, and Ivanti Connect Secure. Victims included ministries, intergovernmental bodies, US defense contractors, European manufacturers, and space organizations. The campaign’s impact highlights persistent perimeter vulnerabilities and demonstrated operational scale and stealth through commodity tooling and strategic timing near geopolitical events. This incident underscores the shift toward exploiting edge devices and open-source frameworks for stealth, scalable compromise by advanced actors. The trend signals urgent challenges for organizations relying on perimeter appliances and highlights the need to strengthen monitoring, zero trust segmentation, and compliance-driven security controls across hybrid and multicloud environments.
6 months ago
Kill Chain
UNC5221 Breach: BRICKSTORM Backdoor Hits U.S. Legal & Tech Sectors (2025)
In September 2025, a sophisticated cyber espionage operation targeting U.S.-based legal services, SaaS providers, BPOs, and technology firms was attributed to UNC5221, a suspected China-nexus threat actor. The attackers leveraged the BRICKSTORM backdoor as their primary access mechanism, gaining initial entry through spear-phishing campaigns and exploiting software vulnerabilities. Once inside, they focused on lateral movement, data gathering, and exfiltration, leveraging encrypted channels to avoid detection. The incident resulted in exposure of sensitive legal documents, business data, and intellectual property, highlighting the advanced TTPs of nation-state actors targeting critical professional sectors. This breach exemplifies the growing prevalence of targeted espionage campaigns against high-value service and technology industries. It underscores the urgency for organizations to adopt advanced threat detection, zero trust segmentation, and strong encrypted communication controls in the face of persistent, well-resourced adversaries and heightened regulatory scrutiny.
6 months ago
Kill Chain
Apple 2025 Spyware Surge: Targeted Zero-Day Attacks Threaten High-Profile Users
In 2025, Apple issued multiple urgent notifications to users after detecting a series of targeted spyware attacks leveraging zero-day vulnerabilities on iOS devices. According to French CERT-FR, at least four documented incidents since the beginning of the year involved highly sophisticated, zero-click exploits that required no user interaction. Victims included journalists, politicians, lawyers, activists, and executives in sensitive sectors. Attackers used a combination of a patched Apple zero-day (CVE-2025-43300) and a WhatsApp vulnerability (CVE-2025-55177) to compromise devices, potentially granting remote access to communications and sensitive data. Apple recommended enabling Lockdown Mode and soliciting help from digital security hotlines, but did not attribute the attacks to a specific group or region. This incident underscores increasing use of mercenary spyware and zero-day exploits for high-profile targeting, reflecting the growing challenges of defending against advanced persistent threats. The case highlights the urgency for rapid patching, proactive security postures, and global awareness of targeted surveillance campaigns in both the public and private sectors.
6 months ago
Kill Chain
APT28 Exploits Microsoft Outlook: Inside the 2024 NotDoor Backdoor Attack
In 2024, the Russian state-sponsored group APT28 (also known as Fancy Bear) leveraged a new backdoor called "NotDoor" to infiltrate targeted organizations via Microsoft Outlook. Researchers from Lab52 revealed that attackers delivered NotDoor using DLL sideloading through OneDrive.exe, enabling them to bypass Outlook's macro security and gain persistent access. Once deployed, NotDoor monitored incoming Outlook emails for specific trigger words, allowing APT28 to exfiltrate sensitive data, upload malicious files, and execute remote commands without detection. Outlook's native functions were abused to provide covert communications and stealthy data transfers, making detection difficult. This incident illustrates the continued evolution of state-sponsored attack methods, especially the abuse of ubiquitous business software like Microsoft Outlook for stealthy, command-and-control operations. Organizations face mounting pressure to address advanced persistent threats exploiting native application behaviors and to enhance email and endpoint security in response to these sophisticated tactics.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports