The Containment Era is here. →Explore

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

162 threat reports
Page 4 of 14

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Legal Services Threat Reports

Showing 3748 / 162 reports
Coupang Data Breach 2025: A Wake-Up Call for E-Commerce Security
Impact· CRITICAL

Coupang Data Breach 2025: A Wake-Up Call for E-Commerce Security

In June 2025, Coupang, South Korea's leading e-commerce platform, experienced a significant data breach that went undetected until November 2025. The breach compromised personal information of approximately 37.55 million customers, including names, email addresses, phone numbers, delivery addresses, and order histories. Investigations revealed that the breach resulted from inadequate security practices, such as poor authentication key management and insufficient access controls. This incident underscores the critical importance of robust cybersecurity measures in protecting sensitive customer data. The substantial fine imposed by South Korean authorities highlights the growing regulatory focus on data protection and the severe consequences of security lapses for organizations handling large volumes of personal information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
FROST Attack: A New Threat to User Privacy via SSD Timing
Impact· MEDIUM

FROST Attack: A New Threat to User Privacy via SSD Timing

In June 2026, researchers from Graz University of Technology unveiled a novel side-channel attack named FROST (Fingerprinting Remotely using OPFS-based SSD Timing). This attack enables malicious websites to infer users' browsing habits and application usage by exploiting SSD access time variations through JavaScript, without requiring native code execution or user permissions. By leveraging the Origin Private File System (OPFS) API, attackers can create large files that induce measurable SSD latency changes when other applications or websites are accessed, allowing them to identify specific user activities with high accuracy. ([tugraz.elsevierpure.com](https://tugraz.elsevierpure.com/de/publications/frost-fingerprinting-remotely-using-opfs-based-ssd-timing/?utm_source=openai)) The FROST attack underscores the evolving landscape of web-based privacy threats, highlighting the potential for sophisticated side-channel attacks that operate entirely within the browser environment. As web applications become more complex and integrated with local system resources, the need for robust security measures to mitigate such vulnerabilities becomes increasingly critical.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UNC3753's 2026 Data Theft Campaign: A Blend of Vishing and Physical Intrusions
Impact· HIGH

UNC3753's 2026 Data Theft Campaign: A Blend of Vishing and Physical Intrusions

Between January and May 2026, the threat actor UNC3753, also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG), targeted numerous U.S. organizations in the professional, legal, and financial sectors. Utilizing voice phishing (vishing) and social engineering tactics, they impersonated IT support to gain remote access via screen-sharing sessions and remote monitoring tools. In some cases, attackers physically infiltrated offices, posing as IT technicians to exfiltrate data using USB devices. Stolen information included proprietary legal agreements, personally identifiable information (PII), and financial records. The group rapidly demanded ransoms, threatening to publish the stolen data if payments were not made promptly. This incident underscores the evolving tactics of cybercriminals, combining traditional social engineering with physical intrusion methods. The rapid execution of these attacks, often completed within a single business day, highlights the need for organizations to enhance their security awareness training and implement robust verification processes for IT support interactions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UNC5221's Prolonged Cyber-Espionage via Brickstorm Malware
Impact· CRITICAL

UNC5221's Prolonged Cyber-Espionage via Brickstorm Malware

In June 2026, the Chinese state-sponsored group UNC5221, also known as VerdantBamboo, was found to have infiltrated U.S. organizations using the Brickstorm backdoor and newly identified malware variants, Plenet and AgentPSD. The attackers maintained undetected access for over 18 months, compromising Microsoft 365 environments and managed service providers. Their tactics included exploiting zero-day vulnerabilities in edge devices and deploying advanced malware implants written in Golang and Rust. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/amp/?utm_source=openai)) This incident underscores the evolving sophistication of state-sponsored cyber-espionage campaigns, highlighting the need for organizations to enhance their detection capabilities, particularly in monitoring network appliances and implementing robust access controls to prevent prolonged unauthorized access.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft 365 Android Apps Vulnerability Exposes User Tokens
Impact· MEDIUM

Microsoft 365 Android Apps Vulnerability Exposes User Tokens

In June 2026, a significant security vulnerability was discovered in several Microsoft 365 Android applications, including Word, Excel, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot. Researchers at Enclave identified that a debug setting, intended for testing purposes, was inadvertently left enabled in production versions of these apps. This oversight disabled critical security controls, allowing any app on the same device to request and receive Microsoft authentication tokens without proper authorization checks. Consequently, malicious applications could gain unauthorized access to user accounts, potentially compromising emails, files, and other sensitive data. Microsoft promptly addressed the issue by releasing updates and assigning CVEs such as CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, and CVE-2026-42832 to track the vulnerabilities. This incident underscores the critical importance of rigorous security practices in software development, particularly in managing authentication tokens. The exposure highlights the potential risks associated with residual debug settings in production environments, emphasizing the need for comprehensive code reviews and security audits to prevent similar vulnerabilities in the future.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerability in Microsoft 365 Android Apps Exposes User Tokens
Impact· MEDIUM

Critical Vulnerability in Microsoft 365 Android Apps Exposes User Tokens

In May 2026, a critical vulnerability was discovered in several Microsoft 365 Android applications, including Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote. A development flag, 'IsDebugMode', was inadvertently left enabled in production builds, disabling the security check that restricts account-token sharing to trusted Microsoft apps. This oversight allowed any app on the same device to request and obtain the signed-in user's Microsoft account tokens without requiring a password, login screen, or permission prompt. Consequently, unauthorized applications could access emails, files, calendars, and send messages as the user, posing significant security risks. ([securityweek.com](https://www.securityweek.com/exclusive-how-one-line-of-code-put-billions-of-microsoft-android-app-downloads-at-risk/amp/?utm_source=openai)) This incident underscores the critical importance of rigorous security checks in the software development lifecycle, especially in mobile applications that handle sensitive user data. The ease with which a single misconfiguration can lead to widespread security breaches highlights the need for continuous monitoring and auditing of application settings. Organizations must prioritize updating affected applications and implementing robust security practices to prevent similar vulnerabilities in the future.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Carnival Corporation's 2026 Data Breach: A ShinyHunters Operation
Impact· HIGH

Carnival Corporation's 2026 Data Breach: A ShinyHunters Operation

In April 2026, Carnival Corporation, the world's largest cruise operator, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers employed social engineering tactics to deceive an employee, gaining unauthorized access to the company's IT systems. This intrusion led to the exfiltration of personal data belonging to nearly 6 million individuals, including names, birthdates, genders, and loyalty program details. The breach was publicly disclosed on May 27, 2026, over a month after the initial compromise. ([prnewswire.com](https://www.prnewswire.com/news-releases/carnival-corporation-notice-of-data-breach-302783524.html?utm_source=openai)) This incident underscores the persistent threat posed by sophisticated cybercriminal groups like ShinyHunters, who have been linked to multiple high-profile data breaches in 2026. The delay in disclosure highlights the challenges organizations face in promptly notifying affected individuals, emphasizing the need for robust cybersecurity measures and transparent communication strategies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ChatGPhish: Unveiling the New Phishing Threat in AI Systems
Impact· MEDIUM

ChatGPhish: Unveiling the New Phishing Threat in AI Systems

In May 2026, cybersecurity researchers at Permiso Security identified a vulnerability in OpenAI's ChatGPT, termed 'ChatGPhish'. This flaw exploits ChatGPT's handling of Markdown links and images within web summaries, allowing attackers to inject malicious content. By embedding harmful payloads in web pages that users prompt ChatGPT to summarize, adversaries can cause the AI to render phishing links, deceptive system alerts, and QR codes directly within its trusted interface. This method can lead to unauthorized data exposure, including users' IP addresses and browser details, and potentially trick users into engaging with malicious content. The ChatGPhish vulnerability underscores the evolving threat landscape where AI tools become vectors for sophisticated phishing attacks. As organizations increasingly rely on AI for information processing, this incident highlights the critical need for robust security measures in AI systems to prevent exploitation through indirect prompt injections and ensure user trust.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
California Attorney General Sues 23andMe Over 2023 Data Breach
Impact· CRITICAL

California Attorney General Sues 23andMe Over 2023 Data Breach

In October 2023, genetic testing company 23andMe experienced a significant data breach affecting approximately 6.9 million users, including 855,541 Californians. Attackers exploited reused passwords through a credential-stuffing attack, initially compromising around 14,000 accounts. Due to the interconnected nature of 23andMe's 'DNA Relatives' feature, the breach expanded, exposing sensitive genetic and personal information such as ancestry reports, health predispositions, and DNA matches. The company faced multiple lawsuits and regulatory fines, ultimately filing for bankruptcy in March 2025. In May 2026, California Attorney General Rob Bonta filed a lawsuit against 23andMe, now known as Chrome Holding Co., alleging failure to implement reasonable safeguards against credential-stuffing attacks and misleading public statements regarding the breach. This incident underscores the critical importance of robust cybersecurity measures, especially in handling sensitive genetic data. The rise in credential-stuffing attacks highlights the need for organizations to enforce strong password policies and multi-factor authentication to protect user information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Silent Ransom Group's In-Person Data Extortion Tactics Target U.S. Law Firms
Impact· HIGH

Silent Ransom Group's In-Person Data Extortion Tactics Target U.S. Law Firms

In May 2026, the Silent Ransom Group (SRG), also known as Luna Moth or Chatty Spider, escalated their cyber extortion tactics by physically infiltrating U.S. law firms. Posing as IT support personnel, SRG operatives gained unauthorized access to sensitive data by inserting malicious devices into firm computers. This method allowed them to exfiltrate confidential information without deploying traditional ransomware, subsequently threatening to publish the stolen data unless ransoms were paid. The FBI has confirmed that SRG has already leaked data from over 38 law firms on their public site, with total attacks exceeding 100 since early 2026. ([techtimes.com](https://www.techtimes.com/articles/317293/20260527/silent-ransom-group-sends-operatives-law-firm-offices-38-firms-already-leaked.htm?utm_source=openai)) This incident underscores a significant shift in cybercriminal strategies, combining social engineering with physical intrusion to bypass digital defenses. The legal sector, handling highly sensitive client information, is particularly vulnerable to such attacks. Organizations must enhance both digital and physical security measures to mitigate these evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
Impact· HIGH

FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics

In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), a Russia-linked data extortion gang targeting U.S. law firms. SRG employs a combination of social engineering tactics, including phone calls and phishing emails, to impersonate IT support staff. If these remote attempts fail, the group escalates to in-person visits, where operatives physically access computers to steal sensitive data using external storage devices. This method has led to the compromise of over 100 law firms, with data from more than 38 firms publicly leaked. The group's focus on law firms is strategic, exploiting the highly sensitive nature of legal data to exert pressure for ransom payments. SRG's unique approach, combining remote social engineering with physical intrusion, underscores the evolving threat landscape and the need for robust security measures in the legal sector.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Microsoft Exchange Zero-Day CVE-2026-42897 Exploited in the Wild
Impact· MEDIUM

Critical Microsoft Exchange Zero-Day CVE-2026-42897 Exploited in the Wild

In May 2026, Microsoft disclosed a zero-day vulnerability, CVE-2026-42897, affecting on-premises versions of Exchange Server 2016, 2019, and Subscription Edition. This cross-site scripting (XSS) flaw allows attackers to execute arbitrary JavaScript in a user's browser by sending a specially crafted email, which, when opened in Outlook Web Access (OWA), triggers the exploit. The vulnerability has been actively exploited in the wild, leading to potential unauthorized access to users' mailboxes and session tokens. Microsoft has provided temporary mitigations through the Exchange Emergency Mitigation Service (EEMS) and manual scripts, but a permanent patch is still pending. ([notebookcheck.net](https://www.notebookcheck.net/Microsoft-Exchange-Server-zero-day-exploited-via-crafted-email.1298885.0.html?utm_source=openai)) The exploitation of CVE-2026-42897 underscores the persistent threat posed by XSS vulnerabilities, even in widely used enterprise applications. Organizations relying on on-premises Exchange Servers must remain vigilant, apply available mitigations promptly, and monitor for any signs of compromise to protect sensitive information and maintain operational integrity.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports