The Containment Era is here. →Explore

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

163 threat reports
Page 11 of 14

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Legal Services Threat Reports

Showing 121132 / 163 reports
Resecurity 2025: How a Cybersecurity Firm Turned an Alleged Breach Into a Threat Intelligence Win
Impact· high

Resecurity 2025: How a Cybersecurity Firm Turned an Alleged Breach Into a Threat Intelligence Win

In December 2025, threat actors identifying as the 'Scattered Lapsus$ Hunters' claimed they had breached systems belonging to cybersecurity firm Resecurity, stealing employee data, internal communications, threat intelligence reports, and client information. The attackers published screenshots to support their claims, including evidence of access to collaboration platforms. However, Resecurity quickly countered the claims, explaining that the compromised environment was actually a carefully monitored honeypot populated with synthetic datasets and fake credentials, intentionally designed to attract cybercriminals for research purposes. The company monitored and logged the attackers’ behaviors, collected valuable intelligence—including reconnaissance, OPSEC failures, and the use of residential proxy infrastructure—and shared key data with law enforcement. No real customer data or production systems were at risk during the incident, according to Resecurity. This case highlights the growing trend of cyber attackers targeting security firms as retaliation for investigations, as well as the strategic use of deceptive honeypots to gather adversary intelligence. The incident underlines the importance of controlled cyber deception, advanced detection, and proactive threat intelligence amid an escalating environment of data theft claims and public leak extortion tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures
Impact· medium

US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures

In December 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) removed three individuals previously sanctioned for their involvement with Intellexa and its Predator commercial spyware from the Specially Designated Nationals (SDN) list. The individuals—Merom Harpaz, Andrea Nicola Constantino Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou—were linked to leadership and distribution roles within the Intellexa Consortium. Their removal followed a petition and OFAC’s evaluation that they had separated themselves from the Intellexa ecosystem, but no underlying details or independent confirmation were disclosed. The original sanctions stemmed from their roles in developing, distributing, and enabling Predator software, a tool implicated in high-profile surveillance of civil society figures, including journalists and activists, through stealth zero-day and social engineering attacks. This case underscores the continued risks posed by commercial spyware vendors and associated compliance exposures. Ongoing public reporting highlights Predator’s persistent activity despite regulatory efforts, as well as geopolitical pressures that drive international balkanization and new attack trends targeting sensitive sectors. With regulatory frameworks evolving and threat actors shifting tactics, the risk of spyware misuse for human rights abuses and espionage remains acute.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
DarkSpectre Espionage Wave: 8.8 Million Impacted by Malicious Browser Extensions
Impact· high

DarkSpectre Espionage Wave: 8.8 Million Impacted by Malicious Browser Extensions

Between 2018 and 2025, a sophisticated Chinese threat actor known as DarkSpectre orchestrated a series of malicious browser extension campaigns that compromised over 8.8 million users globally across Google Chrome, Microsoft Edge, Mozilla Firefox, and Opera. The group leveraged deceptive add-ons disguised as productivity, conferencing, and media tools to harvest sensitive data, hijack web sessions, and facilitate massive corporate espionage. Through delayed activation tactics and compromised legitimate extensions, attackers exfiltrated confidential meeting details, user credentials, and organizational intelligence in real time. Much of the operation leveraged trusted marketplaces, building user bases over years before weaponizing extensions via silent code updates. The scale, persistence, and supply-chain focus of this campaign highlight a shift toward data-centric, espionage-motivated browser attacks. As hybrid work and cloud platforms proliferate, organizations face heightened supply chain and insider risk pressure—and regulators increasingly expect stringent controls on extension governance and data privacy.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
OpenAI Battles Prompt Injection Risk in ChatGPT Atlas Browser Agent (2024)
Impact· medium

OpenAI Battles Prompt Injection Risk in ChatGPT Atlas Browser Agent (2024)

In mid-2024, OpenAI reported a significant security challenge involving prompt injection attacks targeting its ChatGPT Atlas browser agent. Internal automated red teaming uncovered advanced prompt injection techniques that manipulated the agent into executing unauthorized actions when it encountered maliciously crafted content, such as emails or web pages. The incident highlighted the potential for agents with access to sensitive workflows—like email or documents—to become high-value targets, with attackers abusing their autonomous capabilities to exfiltrate data or perform unintended tasks. OpenAI responded by updating the agent with an adversarially trained model and enhanced safeguards. This incident draws attention to the growing security risks associated with AI/ML agents operating within user workflows, as such attacks are becoming increasingly sophisticated and persistent. The event underscores a broader pattern of rising concern from regulators and security agencies regarding AI-driven exploits, especially as generative AI becomes deeply integrated into enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Operation Sentinel: Global Crackdown on African Cybercrime Syndicates in 2024
Impact· high

Operation Sentinel: Global Crackdown on African Cybercrime Syndicates in 2024

In June 2024, Operation Sentinel saw a sweeping law enforcement crackdown on African-based cybercrime syndicates, with authorities across 19 countries arresting 574 individuals and recovering over $3 million in illicit funds. The syndicates, operating throughout sub-Saharan Africa, orchestrated widespread business email compromise (BEC), digital extortion, and ransomware attacks. The multi-vector threat campaign exploited unencrypted traffic, lateral movement within networks, and common gaps in segmentation and egress controls. The collective action disrupted dozens of criminal infrastructures, protected strategic sectors, and exposed critical weaknesses across hybrid and cloud-connected environments. This operation underscores the growing collaboration between threat actors spanning continents, the use of sophisticated tactics like lateral movement, and heightened regulatory scrutiny. As hybrid work and cloud adoption accelerate, organizations face increasing risks from financially motivated cybercriminals exploiting east-west security gaps and insufficient threat detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urban VPN Proxy Secretly Harvests AI Chat Data in Major 2025 Breach
Impact· high

Urban VPN Proxy Secretly Harvests AI Chat Data in Major 2025 Breach

In December 2025, security researchers revealed that Urban VPN, a widely used proxy extension, was surreptitiously intercepting conversations across multiple major AI platforms including ChatGPT, Claude, Gemini, and others. The extension embedded specialized scripts to harvest every prompt, response, and session identifier, regardless of VPN connectivity, compromising the privacy of millions of users. This covert data collection occurred without user awareness or consent, and the only available mitigation was uninstalling the extension altogether. Widespread harvesting of AI chat data raised severe concerns over data confidentiality and regulatory non-compliance. This incident underscores the increasing exploitation of browser extensions as attack vectors, especially as user reliance on generative AI tools for sensitive communications grows. The lack of transparency and opt-out mechanisms amplifies exposure to data-harvesting malware and highlights urgent needs for enhanced supply-chain vetting and detective controls in both enterprise and consumer environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
8 Million Users' AI Conversations Exposed: Urban VPN Browser Extension's Hidden Data Harvest
Impact· high

8 Million Users' AI Conversations Exposed: Urban VPN Browser Extension's Hidden Data Harvest

In December 2025, security researchers exposed that the popular Urban VPN Proxy browser extension—marketed for privacy—was actively harvesting and exfiltrating sensitive conversation data from over eight million users interacting with leading AI chatbot platforms such as ChatGPT, Claude, Gemini, and Copilot. The malicious behavior was introduced in versions released after July 2025, with the extension injecting scripts into browser sessions to intercept, package, and transmit users’ chatbot prompts, responses, and session metadata to servers operated by Urban VPN’s parent, BiScience, a known data broker. Users were not offered any meaningful way to disable this data collection besides uninstalling the extension, and the privacy disclosure was deeply buried within the setup process, leaving the majority unaware. This incident underscores the growing risk posed by privacy-violating browser extensions, especially those with elevated reputations and millions of installations. As AI assistants become repositories for sensitive personal and corporate data, the implications of such data leaks—from regulatory compliance to business confidentiality—are amplified, driving urgent reassessment of browser extension governance and AI data security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Phantom Stealer Phishing: 2025 Attack Hits Russian Finance via ISO Emails
Impact· medium

Phantom Stealer Phishing: 2025 Attack Hits Russian Finance via ISO Emails

In late 2025, an active phishing campaign dubbed "Operation MoneyMount-ISO" began targeting the Russian financial sector and related industries, with threat actors distributing phishing emails containing malicious ISO disk image attachments. Once opened, these ISO files delivered the Phantom Stealer malware, enabling attackers to exfiltrate sensitive data from finance, accounting, procurement, legal, and payroll departments. The malware operated covertly, seeking credentials and financial information, leading to notable data exposure risks and potential regulatory disruptions for victim organizations. This campaign highlights the increasing sophistication of phishing operations leveraging disk image formats for initial access and the persistent targeting of high-value sectors with advanced infostealer malware. Financial and critical infrastructure organizations face heightened pressure to improve detection and segmentation as threat actors continually refine their social engineering tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Urban VPN Chrome Extension Found Harvesting AI Chat Prompts from Millions
Impact· high

Urban VPN Chrome Extension Found Harvesting AI Chat Prompts from Millions

In late 2025, the "Urban VPN Proxy" Chrome extension—prominently labeled 'Featured' in the Chrome Web Store and boasting over six million users—was discovered silently harvesting all prompts users entered into popular AI chatbots such as ChatGPT, Anthropic Claude, Microsoft Copilot, Google Gemini, and others. Security researchers found the extension covertly intercepted and exfiltrated sensitive data in real time, leveraging its widespread user base and the inherent trust of its browser privileges. The extension’s activity amounted to a massive privacy breach, putting both individuals and enterprises at risk of data exposure. This breach highlights a surge in supply chain and third-party risks posed by browser extensions in the modern SaaS ecosystem. Enterprise security teams face heightened challenges as unregulated extensions become vectors for data harvesting, especially as reliance on AI tools increases. Privacy expectations, compliance obligations, and trust in official app marketplaces are now under renewed scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UK Slaps LastPass with £1.2M Fine for 2022 Data Breach Exposing Encrypted Vaults
Impact· high

UK Slaps LastPass with £1.2M Fine for 2022 Data Breach Exposing Encrypted Vaults

In August 2022, password management provider LastPass suffered a sophisticated data breach in which attackers exploited a compromised developer account. The breach led to the exfiltration of source code, proprietary data, and encrypted password vaults for approximately 1.6 million UK users. Investigation revealed gaps in LastPass’s internal security controls and multi-factor authentication implementation, enabling lateral movement and access to critical storage environments storing user vault backups. The breach resulted in substantial reputational and regulatory consequences for LastPass, including a £1.2 million fine from the UK Information Commissioner’s Office (ICO). This incident remains significant as it highlights persistent weaknesses in cloud application security, data vault encryption, and the growing focus of regulators on consumer data privacy practices. Increased cybercriminal targeting of password management services underscores an urgent need for robust internal segmentation and encryption at all stages.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Gladinet CentreStack 2024: RCE Attacks via Cryptographic Vulnerability
Impact· medium

Gladinet CentreStack 2024: RCE Attacks via Cryptographic Vulnerability

In early June 2024, threat actors began exploiting a previously unknown cryptographic implementation flaw in Gladinet's CentreStack and Triofox products, enabling them to remotely execute code on vulnerable servers. By leveraging crafted payloads targeting insecure cryptographic validation, attackers bypassed authentication mechanisms and gained unauthorized access to sensitive file sharing environments. This led to potential exposure of confidential data, lateral movement, and service disruption for affected organizations, particularly those relying on CentreStack for enterprise file sharing and remote access. This incident highlights the risks of cryptographic implementation errors and the urgent need for patch management, especially for third-party cloud and SaaS solutions. As attackers increasingly weaponize zero-day flaws in commonly used remote file access platforms, enterprises must prioritize robust monitoring and rapid response strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gemini Enterprise No-Click Vulnerability: A Wake-Up Call for AI/ML Security
Impact· medium

Gemini Enterprise No-Click Vulnerability: A Wake-Up Call for AI/ML Security

In early 2024, Google addressed a severe vulnerability in its Gemini Enterprise AI platform that allowed attackers to craft common business documents containing malicious prompt injections. These attacks did not require any user interaction; simply opening or syncing affected documents enabled adversaries to exfiltrate sensitive organizational data, bypassing usual security controls. The flaw exploited Gemini’s integration with widely used Google Workspace applications. Attackers leveraged this vulnerability to gain unintended access to confidential files, customer data, and internal communications, posing material risks to business operations and reputation. This vulnerability exemplifies emerging no-click threats in AI-integrated enterprise ecosystems, where conventional perimeter defenses and user-awareness controls are ineffective. The incident underscores the urgency for organizations to review AI/ML security posture as attackers rapidly adapt to take advantage of new AI-powered workflows.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports