The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

200 threat reports
Page 1 of 17

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Legal Services Threat Reports

Showing 1–12 / 200 reports
ShinyHunters Hacks Clop Ransomware Gang: When Criminals Attack Criminals
Impact· CRITICAL

ShinyHunters Hacks Clop Ransomware Gang: When Criminals Attack Criminals

In September 2026, the ShinyHunters cybercrime group successfully breached rival ransomware gang Clop's dark web infrastructure by exploiting an unauthenticated file upload vulnerability in their Grav CMS leak site. ShinyHunters defaced Clop's site, claimed to have stolen source code, system logs, private keys, and potentially victim payment data, then demanded an eight-figure Bitcoin ransom while threatening to expose companies that previously paid Clop ransoms including payment amounts and Bitcoin addresses. This incident highlights the cascading risks faced by ransomware victims whose stolen data remains vulnerable on criminal infrastructure beyond their control, potentially subjecting them to renewed extortion attempts from rival threat actors even after initial ransom payments.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TASK#STOMP Campaign: How PowerShell Backdoors Steal Corporate Data
Impact· HIGH

TASK#STOMP Campaign: How PowerShell Backdoors Steal Corporate Data

The TASK#STOMP campaign represents a sophisticated PowerShell-based backdoor operation that combines multiple persistence mechanisms with comprehensive data theft capabilities. Attackers use VBScript orchestrators to establish scheduled tasks with legitimate-sounding names like 'Local Credential Manager' and 'Windows Display Manager' to blend in with normal system operations. The malware automatically harvests business documents, Wi-Fi passwords, clipboard contents, takes screenshots, and maintains redundant command-and-control channels through dual PowerShell modules that monitor each other's execution status. This incident highlights the growing trend of living-off-the-land attacks that abuse native Windows components to evade detection, representing a shift toward more subtle, persistent threats that prioritize long-term access over immediate disruption.

3 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ransomware Gang Warfare: ShinyHunters Breaches Clop's Infrastructure in Escalating Cyber Feud
Impact· MEDIUM

Ransomware Gang Warfare: ShinyHunters Breaches Clop's Infrastructure in Escalating Cyber Feud

In September 2026, the ShinyHunters extortion gang successfully breached the Clop ransomware operation's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. The attackers defaced the Tor site with their signature Umbreon logo, claimed to have stolen source code, system logs, and the private keys for Clop's onion service. This attack was reportedly retaliation for threats made by Clop representatives during an ongoing feud that began after ShinyHunters disrupted Clop's 2025 Oracle E-Business Suite data theft campaign involving CVE-2025-61882. This incident highlights the growing trend of cybercriminal groups turning against each other, creating additional chaos in an already volatile threat landscape. As ransomware operations become more territorial and competitive, these inter-gang conflicts expose critical infrastructure vulnerabilities and demonstrate how threat actors increasingly target each other's operational security.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Workspace Under Attack: How OAuth Abuse and Social Engineering Created a Perfect Storm in 2026
Impact· MEDIUM

Google Workspace Under Attack: How OAuth Abuse and Social Engineering Created a Perfect Storm in 2026

In 2026, multiple organizations experienced sophisticated Google Workspace breaches where threat actors combined social engineering tactics with malicious OAuth applications to gain unauthorized access to corporate environments. These attacks typically began with targeted phishing campaigns that tricked users into granting permissions to seemingly legitimate third-party applications, which then provided attackers with persistent access to email, documents, and other Google Workspace resources. The incidents highlighted critical gaps in OAuth security controls and user awareness training, resulting in data exposure, business disruption, and potential regulatory violations across affected organizations. These Google Workspace OAuth attacks represent a growing trend where cybercriminals exploit the trust users place in cloud-based productivity platforms and the complexity of modern application permission models to bypass traditional security controls.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Court Orders Transfer of Radaris Domains in Landmark Data Broker Privacy Case
Impact· HIGH

Court Orders Transfer of Radaris Domains in Landmark Data Broker Privacy Case

In August 2024, a New Jersey court ordered the transfer of radaris.com and over a dozen related data broker domains to Atlas Data Privacy Corp following a lawsuit under Daniel's Law. The case arose after Radaris, operated by Russian-born brothers Igor and Dmitry Lubarsky, repeatedly ignored removal requests from law enforcement officials and engaged in legal delay tactics including creating shell companies across multiple jurisdictions. The court found Radaris in default after the company failed to mount an adequate defense, resulting in the loss of domains generating approximately $42,000 monthly revenue for the primary site alone. This landmark case demonstrates how privacy laws with meaningful enforcement mechanisms can effectively shut down non-compliant data brokers who have historically operated with impunity by exploiting jurisdictional complexities and procedural delays.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CenterPoint Energy Breach Exposes 7.49M Records Through Unsecured API
Impact· HIGH

CenterPoint Energy Breach Exposes 7.49M Records Through Unsecured API

CenterPoint Energy, a Houston-based utility serving 7 million customers across Texas, Indiana, Minnesota, and Ohio, confirmed a significant data breach in September 2026 after a threat actor using the alias '4d722e4d656f77' stole 7.49 million customer records. The attacker exploited an unsecured public API lacking rate limiting and web application firewall protection, iterating through millions of customer IDs to extract names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers. When the company failed to respond to the threat actor's initial contact, the stolen data was publicly leaked, prompting multiple class-action lawsuits and SEC disclosure. This incident highlights the critical vulnerability of inadequately secured public APIs in utility infrastructure, occurring amid increased scrutiny of energy sector cybersecurity following recent attacks on critical infrastructure. The breach demonstrates how basic API security misconfigurations can lead to massive data exposure, emphasizing the urgent need for proper rate limiting, authentication, and monitoring on all external-facing systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iranian Intelligence Weaponizes Telegram in Global HEAVYGRAM Espionage Campaign
Impact· HIGH

Iranian Intelligence Weaponizes Telegram in Global HEAVYGRAM Espionage Campaign

Since autumn 2023, Iran's Ministry of Intelligence and Security (MOIS) has deployed sophisticated malware called HEAVYGRAM (FBI designation) or CHOSEN BRICK (UK NCSC designation) to conduct extensive cyber espionage operations targeting Iranian dissidents, journalists, and activists worldwide. The Windows-based malware uses Telegram messaging app for command and control, enabling attackers to steal emails, capture screenshots, record audio through microphones, and exfiltrate sensitive communications. Victims are initially compromised through social engineering tactics where attackers impersonate trusted contacts or technical support, delivering malicious files disguised as legitimate applications like Adobe Flash, Norton Antivirus, or even medical scan results. This campaign represents a significant escalation in state-sponsored surveillance capabilities, demonstrating how authoritarian regimes are weaponizing popular communication platforms for transnational repression. The targeting extends beyond digital espionage, with stolen personal information being published on Iranian leak sites to endanger victims' physical safety, highlighting the intersection of cyber operations with traditional intelligence gathering and intimidation tactics.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Telegram Desktop XSS Flaw Exposed Chat Exports to Hidden JavaScript Attacks
Impact· MEDIUM

Telegram Desktop XSS Flaw Exposed Chat Exports to Hidden JavaScript Attacks

In June 2026, security researchers ExPatch discovered a critical cross-site scripting (XSS) vulnerability in Telegram Desktop's HTML export feature that allowed malicious bots to embed hidden JavaScript code in chat messages. The flaw affected versions 4.15.1 through 6.9.3, spanning over two years from March 2024 to July 2026. Attackers could exploit this by creating bot messages with script tags in button text, which would execute when users opened exported HTML files in browsers, potentially exfiltrating entire chat histories to attacker-controlled servers or manipulating displayed content. This incident highlights the growing risk of supply chain vulnerabilities in popular communication platforms and the delayed disclosure challenges facing the cybersecurity community. As organizations increasingly rely on messaging platforms for business communications and data export features for compliance, such vulnerabilities expose sensitive corporate communications to potential theft and manipulation.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Florida DMV Breach Exposes Risks of Shared Government Database Access
Impact· HIGH

Florida DMV Breach Exposes Risks of Shared Government Database Access

In September 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that its DAVID driver database was breached by the ShinyHunters extortion group, who claimed to have stolen over 200,000 driver records. The attack was executed using compromised credentials from a Plant City Police Department employee that had been improperly stored on a personal device. The breach was discovered on September 4, 2026, and quickly mitigated, with FLHSMV working alongside state law enforcement agencies in their response. This incident highlights the growing trend of cybercriminals targeting government databases through compromised credentials and the critical importance of proper credential management across interconnected systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Storm-3032 and Storm-3121 Are Exploiting BYOD Policies to Breach Corporate Microsoft 365
Impact· HIGH

How Storm-3032 and Storm-3121 Are Exploiting BYOD Policies to Breach Corporate Microsoft 365

Since May 2026, Microsoft researchers have tracked threat actors Storm-3032 and Storm-3121 conducting sophisticated initial access campaigns targeting corporate executives through their personal devices. The attackers use voice calls and text messages impersonating IT helpdesks to trick employees into updating authentication credentials via phishing links. Once access is gained, the threat actors exploit Microsoft Graph API to enumerate corporate resources and exfiltrate sensitive data from SharePoint, OneDrive, and Exchange before potentially selling access to extortion groups like ShinyHunters. This campaign highlights the growing trend of attackers bypassing corporate security controls by targeting the weakest link - personal devices with minimal security protections. As organizations increasingly adopt BYOD policies and hybrid work models, identity-based attacks exploiting trusted communication channels represent a critical evolution in threat actor tactics.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
First Take It Down Act Conviction: James Strahler's AI Sextortion Campaign Exposes Deepfake Threat Landscape
Impact· HIGH

First Take It Down Act Conviction: James Strahler's AI Sextortion Campaign Exposes Deepfake Threat Landscape

Between December 2024 and June 2025, Ohio resident James Strahler II conducted an extensive AI-powered sextortion campaign targeting multiple women through cyberstalking, harassment, and the creation of non-consensual deepfake pornography. Using over 100 AI web-based models across 24 platforms, Strahler generated more than 700 sexually explicit images and videos of his victims, which he distributed to their workplaces and posted on child exploitation websites. His tactics included threatening victims and their families with public humiliation unless they provided additional explicit content, making rape threats referencing home addresses, and demanding compliance from victims' mothers. The case resulted in a 15-year federal prison sentence and marked the first conviction under the newly enacted Take It Down Act of 2025. This incident highlights the emerging threat landscape where readily accessible AI tools are being weaponized for sophisticated harassment campaigns, demonstrating how threat actors are adapting generative AI capabilities for malicious purposes at an unprecedented scale and sophistication level.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Grindr's £26 Million Settlement Exposes Critical Gaps in Dating App Data Privacy
Impact· HIGH

Grindr's £26 Million Settlement Exposes Critical Gaps in Dating App Data Privacy

In September 2026, Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. class action lawsuit involving over 10,000 users whose sensitive personal data, including HIV status, was shared with third-party advertising companies Apptimize and Localytics between 2018-2020. The incident, originally exposed by Norwegian research group SINTEF in April 2018, occurred while Grindr was owned by Chinese gaming company Kunlun, before its 2020 acquisition by San Vicente Acquisition LLC. The settlement covers historical data practices that violated U.K. privacy laws through unauthorized sharing of location data, sexual orientation, and medical information for commercial advertising purposes. This incident highlights the ongoing regulatory scrutiny of data privacy violations in dating apps and social platforms, particularly as GDPR enforcement intensifies and class action lawsuits become more prevalent in addressing historical privacy breaches involving sensitive personal information.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports