The Containment Era is here. →Explore

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

156 threat reports
Page 1 of 13

Explore Other Sectors

Accounting
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Legal Services Threat Reports

Showing 112 / 156 reports
Ernst & Young Data Breach Exposes Client Tax Information in 2026
Impact· HIGH

Ernst & Young Data Breach Exposes Client Tax Information in 2026

In April 2026, Ernst & Young (EY) identified unauthorized access to a third-party IT service management platform used for client tax services. The breach occurred between March 28 and April 12, 2026, during which attackers downloaded documents containing personal and financial information used in tax filings. EY promptly secured the affected systems, notified federal law enforcement, and offered 24 months of identity monitoring services to impacted clients. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/?utm_source=openai)) This incident underscores the critical need for robust third-party risk management, especially as organizations increasingly rely on external platforms for sensitive operations. The breach highlights the importance of continuous monitoring and rapid response strategies to mitigate potential damages from such compromises.

1 day ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ACR Stealer's ClickFix Campaign: A Wake-Up Call for Cybersecurity
Impact· HIGH

ACR Stealer's ClickFix Campaign: A Wake-Up Call for Cybersecurity

In mid-2026, the ACR Stealer malware exploited ClickFix social engineering tactics to infiltrate enterprise networks. By deceiving users into executing commands via fake verification prompts, attackers deployed two primary infection chains: one utilizing WebDAV and PowerShell scripts, and another employing mshta.exe with obfuscated PowerShell. Both methods aimed to exfiltrate browser-stored credentials, session tokens, and sensitive Microsoft 365 documents, including files from OneDrive and SharePoint. This incident underscores a significant shift towards sophisticated social engineering attacks that bypass traditional security measures. The reliance on user interaction highlights the critical need for enhanced user awareness and robust endpoint protection strategies to mitigate such threats.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Claude Chrome Extension Exposes User Data
Impact· MEDIUM

Critical Vulnerability in Claude Chrome Extension Exposes User Data

In July 2026, a critical vulnerability was discovered in Anthropic's Claude for Chrome browser extension. This flaw allowed malicious extensions to simulate user interactions, triggering predefined AI actions without user consent. Exploiting this, attackers could access connected services such as Gmail, Google Docs, Google Calendar, and Salesforce, leading to unauthorized data access and potential data exfiltration. The vulnerability stemmed from the extension's failure to verify the origin of click events, accepting synthetic events generated by other extensions as legitimate user actions. This incident underscores the growing risks associated with browser extensions and their integration with AI-powered services. As organizations increasingly adopt such tools to enhance productivity, ensuring robust security measures and thorough validation of user interactions becomes imperative to prevent unauthorized access and data breaches.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Zoom Addresses Critical Windows Vulnerability CVE-2026-53412
Impact· HIGH

Zoom Addresses Critical Windows Vulnerability CVE-2026-53412

In July 2026, Zoom addressed a critical vulnerability (CVE-2026-53412) in its Windows clients, including Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK. This flaw, stemming from improper input validation, could allow unauthenticated attackers to take over user accounts via network access. The vulnerability received a CVSS score of 9.8, indicating its severity. Users are urged to update to the latest versions to mitigate this risk. The incident underscores the importance of timely software updates and robust input validation practices. With the increasing reliance on virtual communication platforms, such vulnerabilities pose significant risks to user security and privacy. Organizations must remain vigilant and proactive in applying security patches to prevent potential exploits.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Emerging Phishing Kits Bypass MFA to Compromise Microsoft 365 Accounts
Impact· HIGH

Emerging Phishing Kits Bypass MFA to Compromise Microsoft 365 Accounts

In July 2026, cybersecurity researchers identified two sophisticated phishing kits, Jalisco and OmegaLord, targeting Microsoft 365 accounts. Jalisco employs device-code phishing by generating real-time OAuth device codes, tricking users into authorizing attacker-controlled devices. OmegaLord masquerades as a PDF reader to harvest login credentials and phone numbers, potentially intercepting MFA codes. Both methods effectively bypass multi-factor authentication, granting attackers unauthorized access to sensitive data stored in services like SharePoint and other SaaS platforms. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/?utm_source=openai)) This incident underscores the evolving nature of phishing attacks, highlighting the need for organizations to reassess and strengthen their authentication mechanisms. The emergence of such advanced phishing kits indicates a trend towards more sophisticated social engineering tactics capable of circumventing traditional security measures.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026
Impact· HIGH

Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026

In July 2026, a sophisticated phishing campaign targeted users of LastPass and Bitwarden, two prominent password management services. Attackers sent emails from addresses like 'hello@lastpassnewsletter.com' and 'hello@bitwardennewsletter.com', falsely notifying recipients of updated security policies. These emails directed users to fraudulent websites impersonating DocuSign, prompting them to download malicious files purportedly compatible with both Windows and macOS systems. The domains used, such as 'lastpasscompliance[.]com' and 'bitwardencompliance[.]com', were flagged as malicious by security services. LastPass confirmed that its systems remained uncompromised and that the phishing emails did not originate from its infrastructure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=openai)) This incident underscores a growing trend of cybercriminals targeting password manager users through sophisticated phishing tactics. The use of legitimate-looking emails and websites to deceive users highlights the need for heightened vigilance and robust security measures. Organizations and individuals must remain alert to such evolving threats to safeguard sensitive information.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Zero-Day Vulnerability in Progress ShareFile: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

Critical Zero-Day Vulnerability in Progress ShareFile: A Wake-Up Call for Cybersecurity

In July 2026, Progress Software identified a high-severity zero-day vulnerability in its ShareFile Storage Zone Controllers, affecting versions 5.x and 6.x. This path traversal flaw allowed authenticated administrative users to read arbitrary files, write malicious content to directories, and enumerate the server's filesystem layout. Upon discovery, Progress promptly released patched versions 5.12.5 and 6.0.2 to mitigate the issue. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/?utm_source=openai)) This incident underscores the critical importance of timely patch management and proactive vulnerability assessments. Organizations are reminded to regularly update their systems and monitor for emerging threats to safeguard sensitive data and maintain operational integrity.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Vulnerability in 'Claude for Chrome' Exposes User Data
Impact· MEDIUM

Critical Vulnerability in 'Claude for Chrome' Exposes User Data

In July 2026, security researchers identified a critical vulnerability in Anthropic's 'Claude for Chrome' extension, allowing malicious browser extensions to exploit Claude's automation capabilities. This flaw enables unauthorized access to sensitive user data, including Gmail, Google Docs, and Calendar, by triggering tasks without user consent. Despite previous mitigation efforts, the vulnerability persists in version 1.0.80, posing significant security risks to users. The incident underscores the growing threat of prompt injection attacks targeting AI-powered browser extensions. As AI tools become more integrated into daily workflows, ensuring robust security measures and user awareness is paramount to prevent unauthorized data access and maintain user trust.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Forg365 PhaaS: A New Threat to Microsoft 365 Security
Impact· HIGH

Forg365 PhaaS: A New Threat to Microsoft 365 Security

In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts. Forg365 employs a combination of device code phishing, adversary-in-the-middle (AiTM) tactics, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram, the service costs $400 per month or $3,800 annually. Attackers utilize legitimate email delivery services like Amazon SES and Twilio SendGrid to craft convincing phishing emails, leading victims to Forg365-controlled domains. The platform's operator panel offers features such as AI-generated phishing emails, campaign management, and a browser extension named ForgCookie, which maintains persistent access to compromised accounts by refreshing Microsoft single sign-on cookies. The emergence of Forg365 underscores the increasing sophistication and accessibility of phishing tools, enabling even low-skilled threat actors to execute complex attacks. This trend highlights the urgent need for organizations to enhance their email security measures, implement robust multi-factor authentication, and educate users about evolving phishing tactics to mitigate the risk of account compromise.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
MemGhost Attack: A New Threat to AI Assistant Security
Impact· HIGH

MemGhost Attack: A New Threat to AI Assistant Security

In July 2026, cybersecurity researchers identified a novel attack vector named 'MemGhost,' which exploits AI assistants equipped with persistent memory. By sending a single, specially crafted email, attackers can implant false information into the assistant's memory without user detection. This manipulation allows the AI to provide altered responses in future interactions, potentially leading to misinformation or unauthorized actions. The attack leverages the assistant's ability to autonomously process emails and update its knowledge base, making it particularly insidious. The MemGhost attack underscores the emerging vulnerabilities associated with AI systems that maintain long-term user data. As AI assistants become more integrated into daily workflows, the potential for such memory poisoning attacks increases, highlighting the need for robust security measures to protect against unauthorized data manipulation.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Insider Threats: Cybersecurity Experts Turned Cybercriminals
Impact· CRITICAL

Insider Threats: Cybersecurity Experts Turned Cybercriminals

In 2023, three U.S. cybersecurity professionals—Ryan Goldberg, Kevin Martin, and Angelo Martino—exploited their insider knowledge to conduct ransomware attacks using the ALPHV/BlackCat variant. Operating between April and December, they targeted multiple organizations, including a medical device company, a pharmaceutical firm, and a drone manufacturer. The trio encrypted victims' data and demanded substantial cryptocurrency ransoms, successfully extorting approximately $1.2 million from one victim. Their actions culminated in guilty pleas and subsequent prison sentences of four years each. ([justice.gov](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced?utm_source=openai)) This case underscores a disturbing trend where trusted insiders leverage their positions for malicious gain, highlighting the critical need for robust internal security measures and continuous monitoring to detect and prevent such insider threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Progress ShareFile SZC Vulnerabilities: A 2026 Security Wake-Up Call
Impact· CRITICAL

Progress ShareFile SZC Vulnerabilities: A 2026 Security Wake-Up Call

In April 2026, critical vulnerabilities were discovered in Progress Software's ShareFile Storage Zones Controller (SZC), specifically CVE-2026-2699 and CVE-2026-2701. These flaws allowed unauthenticated attackers to access restricted configuration pages and execute arbitrary code on affected systems. Despite the release of patches in March 2026, by July 2026, credible external threats targeting unpatched SZC instances prompted Progress to advise customers to immediately shut down their servers to prevent potential data breaches. This incident underscores the persistent risks associated with unpatched software vulnerabilities, especially in widely used enterprise solutions. Organizations are reminded of the importance of timely patch management and proactive security measures to mitigate evolving cyber threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports