
Greenberg Traurig Documents Appear on the Dark Web
A limited number of Greenberg Traurig documents have appeared on the dark web after an unauthorized actor accessed them, the international law firm has said. Reuters reported on Sep. 10 that Greenberg Traurig had confirmed the unauthorized access and the dark web posting, with coverage following on Sep. 12, 2026 at 11:23 AM UTC.
The firm described the number of documents as limited. The account supplied does not identify what the documents contained or say how many people, if any, were affected.
Why the Disclosure Matters
The disclosure comes after other law firms reported unauthorized access to systems holding personal information. The incidents did not all involve the same type of data or the same method of attack, but several exposed records that firms kept for clients and for others who dealt with them.
Because the details released so far differ from case to case, the available information does not establish that the Greenberg Traurig documents contained the same kinds of information reported in the other incidents.
A Pattern of Law Firm Breach Reports
Several other firms have disclosed incidents involving client records, spread across 2025 and 2026.
- Taft Stettinius & Hollister: In March, the firm detected unusual activity on one of its systems, according to Reuters. The incident exposed client Social Security numbers.
- Herbert Smith Freehills Kramer: The London-based firm disclosed unauthorized access in May involving Social Security numbers, government identification numbers, and health records.
- WilmerHale: A separate alleged breach in May led to a proposed class action in July concerning the alleged exposure of information held by the firm. The filing of a proposed class action does not establish the allegations as fact.
- Goodwin Procter: Disclosed another incident on Aug. 7.
- Quinn Emanuel: Later that month, the firm said a social-engineering attack had compromised one account and exposed files stored in it.
Different Data, Different Attack Methods
In a social-engineering attack, the attacker uses deception to gain information or access, rather than necessarily breaking into a system through a software flaw. That distinction helps explain why the affected records differ from case to case. Greenberg Traurig has described documents posted on the dark web, while the reports about Taft and Herbert Smith Freehills Kramer identify particular categories of personal data. Quinn Emanuel’s disclosure concerns files accessible through a compromised account.
Cyber Incident Data Shows the Scale of the Problem
Reuters said BakerHostetler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost twice the number it handled in 2024. The figure describes matters handled by BakerHostetler, not a count of every breach at a law firm during either year.
In its report, BakerHostetler analyzed more than 1,250 data security incidents across industries in 2025. Phishing was the leading identified cause, accounting for 30% of incidents. The firm said outside vendors were the cause in 25% of the matters it analyzed.
BakerHostetler’s figures cover clients across several industries, so they should not be read as rates specific to law firms. Its report placed business and professional services behind health care and finance and insurance among the sectors represented in the incidents it handled.
Post-Disclosure Litigation Is Rising
The report also tracked what happened after incidents were disclosed. BakerHostetler said class actions were filed in 14% of incidents in 2025, up from 9% in 2024. Among the incidents in its dataset that were disclosed, lawsuits followed 68 of 482 in 2025, compared with 51 of 518 in the previous year.
Crypto Customer Data Exposed Through Service Providers
For U.S. crypto customers, a separate set of disclosures shows how personal details can be exposed even when a company says its users’ funds or wallet credentials were not accessed.
In May 2025, U.S. exchange Coinbase disclosed that criminals had bribed overseas support agents to obtain customer information. The breach affected 69,461 users and included names, addresses, phone numbers, and images of government IDs. Coinbase said passwords, private keys, and customer funds were not compromised. The exchange rejected a $20 million ransom demand and offered a reward of the same amount for information leading to the attackers’ arrest and conviction.
Hardware Wallet Makers and Their Vendors
- Ledger: In January, Ledger said unauthorized access to e-commerce partner Global-e had exposed order information belonging to some people who bought products through Ledger.com. A Ledger spokesperson told Decrypt that the accessed information was held in Global-e’s systems and included data related to purchases for which Global-e acted as the merchant of record.
- SafePal: In August, SafePal said a flaw in an order-tracking plug-in exposed information belonging to about 39,798 customers. The records included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said the incident did not affect wallet credentials or payment information, and that it had fixed the flaw and notified affected customers.
- Trezor: The wallet maker reported two distinct incidents involving outside providers. Information belonging to more than 80,000 customers was exposed through shipping provider ShipMonk. Trezor said its own systems, hardware wallets, private keys, and recovery phrases were not compromised. Its expanded disclosure included records belonging to about 67,000 additional U.S. customers who had placed orders between November 2019 and August 2021.
Phishing and Fake Notices Target Wallet Users
On Sep. 9, Trezor warned that an attacker had breached its third-party email provider and sent phishing messages posing as urgent security alerts. The emails falsely claimed that a hardware flaw put users’ recovery phrases at risk. Trezor said it had taken down the domain used in the attempt and was investigating. BitBox warned users the same day about emails impersonating its company and said its newsletter provider was likely compromised.
Earlier in 2026, scammers also sent physical letters posing as notices from Trezor and Ledger. The letters directed recipients to scan QR codes and enter their recovery phrases on malicious websites. Trezor and Ledger said they do not ask users to share recovery phrases through websites or other outside channels.




