A new wave of breaches suggests that the threat is a persistent one. But also, that the challenges facing the legal sector are not insurmountable.
Reports claim that at least 10 major US law firms have been hit so far in 2026. They include:
The focus for threat actors in 2026 has been US law firms, but their UK peers are equally exposed to the financial, reputational and regulatory fallout of breaches. Publicly available information on many of these incidents is scant. But where we do know how hackers accessed corporate networks, it’s via social engineering of a single account.
This tells us that identity compromise is still a common mechanism for gaining unauthorized access. At a bare minimum, security teams should therefore deploy phishing-resistant MFA and follow Zero Trust approaches based around: least privilege and conditional/just-in-time access; device checks; privileged access management (PAM); and network monitoring.
Security awareness training is also important, especially if threat actors use vishing techniques to target or impersonate IT helpdesks. Teams should establish robust processes for identity verification and put extra controls in place for high-risk request like password/MFA resets.
“Strong cyber protection is about getting the fundamentals right and being ready to respond. Firms should focus on handling data securely to make sure cybersecurity awareness is part of everyday decision-making,” Brett Dixon, The Law Society
Efforts to mitigate social engineering threats should go hand in hand with data governance. Law firms must know what they store, how sensitive the data is, and where it’s located if they are to segment and restrict access to it. This will also help to ensure that anything no longer needed is deleted in line with data minimisation best practices. Encryption of the most sensitive data and immutable backups should be a given.
Security leaders must also get a handle on third-party risk, which means understanding what data suppliers store, how it is governed, and what access rights they have. Regular reviews are necessary to check supplier security posture as the IT environment and threat landscape evolve.
Finally, if this year’s attacks have shown anything, it’s the importance of having an incident response plan ready to go when a breach happens. One that is tested regularly with input from stakeholders across the business, so that, when a worst-case scenario occurs, containment and recovery can begin immediately. If even the wealthiest legal practices can be breached, then the sector as a whole should be on notice.
Brett Dixon, vice president of the Law Society of England and Wales, tells Assured Intelligence that cyber resilience is vital to UK practices.
“Strong cyber protection is about getting the fundamentals right and being ready to respond. Firms should focus on handling data securely to make sure cybersecurity awareness is part of everyday decision-making,” he says. “Cybersecurity training should be mandatory for all staff as well as risk assessments, robust safeguards and response plans. Simple steps make a big difference.”
There’s no specific mention of AI in the reporting of recent legal sector breaches. But as more law firms adopt the technology, they should ensure it is also covered by third-party risk, access management and data governance policies. The latter are particularly important in light of the growing risk of data leakage via chatbots, highlighted in a recent notice from the Solicitors Regulation Authority.
However, a potentially bigger threat is the use of AI tools by malicious actors. As well as increasing the speed, scale and accuracy of social engineering and victim reconnaissance, AI models are helping hackers to exploit CVEs in record time. The result is a significantly diminished patch window.
AI-assisted patching tools can help here by prioritising and deploying updates more rapidly. But they should be used in a defence-in-depth approach which also includes compensating controls like network segmentation, firewalls, virtual patches, extended detection and response (XDR), and regular backups.
The Law Society recommends cyber certifications like ISO 27001 and Cyber Essentials as a useful way to improve security posture and meet regulatory requirements. It also urges law firms to purchase cyber insurance.
Assured senior cyber broker, Caspar Rogers, explains that policies can help law firms with the cost of incident response, data restoration and system recovery, business interruption, and regulatory investigations. Depending on the policy, they might also cover the fallout from a ransomware attack, client claims following a data breach/leak, and third-party liability “where compromise of the firm’s network causes malware or data loss affecting a client.”
“Law firms typically recognise their revenue on the P&L later than other businesses, so there can be a delay between the cyber incident and the actual impact on the P&L. Having an indemnity period written on a fixed basis for as many days as possible is crucia” Caspar Rogers, Assured
So what should law firms look for in a carrier? Some easy wins are to ensure their preferred incident response vendors are pre-approved by the insurer, and to ensure any policy covers confidential corporate information as well as PII. Also important is the business interruption indemnity period.
“Law firms typically recognise their revenue on the P&L later than other businesses, so there can be a delay between the cyber incident and the actual impact on the P&L,” Rogers explains. “Having an indemnity period written on a fixed basis for as many days as possible is crucial.”
Another crucial consideration involves social engineering or fund-transfer fraud, which is often covered under a commercial crime policy.
“It’s crucial that the overlap between any social engineering cover provided in the cyber policy and social engineering cover provided in the crime policy is analysed,” Rogers continues.
“If there is an ‘Other Insurance’ condition in both policies then you can run into a scenario where neither policy responds to the loss as both are saying ‘we will sit excess of any other similar insurance’.”
Finally, Rogers urges legal practices to consult their broker over the professional indemnity (PI) policy they currently have in place. “They can then see how the two policies will interact if there is a professional liability claim arising from a cyber incident,” he concludes. “Any scenarios the insured is worried about should then be put to the PI and cyber insurers ahead of renewal or putting the policy in place.”
Cyber insurance is not a silver bullet. But it can help to cover losses and provide support with essential resilience measures like incident response. As the Law Society explains, it should complement rather than replace sound cyber-risk management practices.
“You should think of it as another layer of protection in case things go wrong,” it notes.