Greenberg Traurig law firm documents were illegally accessed and appeared on the dark web.
Greenberg Traurig, an international law firm, said a limited number of documents appeared on the dark web after an unauthorized person accessed its system.
According to a Reuters report on September 10, Greenberg Trauig has confirmed that an unauthorized access occurred and that some documents have been posted to the dark web. The law firm emphasized that the number of documents involved was limited. The disclosure did not explain the specific content of these documents, nor did it mention whether anyone was affected.
The incident occurred after several other law firms reported illegal access to their systems where personal information was stored. Although the types of data involved in these incidents vary and attack methods, multiple cases have exposed records maintained by law firms for clients and other interested parties.
Law firm leak reports include identity and health records
Taft Stettinius & Hollister's law firm reportedly detected unusual activity in one of its systems in March, resulting in the disclosure of clients 'social security numbers. In May of that year, London-based law firm Herbert Smith Freehills Kramer also disclosed an unauthorized access involving social security numbers, government ID numbers and health records.
In addition, another alleged violation by Wilmer Hale in May led to a class-action proposal filed in July. The lawsuit focuses on the alleged disclosure of information held by the law firm; it should be pointed out that filing a class action motion does not mean that the accusation is substantiated.
Another incident was disclosed by the law firm Goodwin Procter on August 7. Later that month, the law firm Quinn Emanuel said a social engineering attack resulted in the breach of an account and the exposure of documents stored therein. In social engineering attacks, an attacker obtains information or access through deception rather than necessarily invading the system through software vulnerabilities.
The records affected vary by case. Greenberg Trauig disclosed documents posted on the dark web, while reports on Taft and Herbert Smith Freedelshards Cramer pointed to specific categories of personal data. Quinn Eman's disclosure involved documents accessible through compromised accounts. Available details do not confirm that Greenberg Trauig's files contain the same type of information reported in other incidents.
Cybersecurity incident data reveals scale of problem
Reuters reported that the law firm Baker Hosttler handled nearly 60 cybersecurity incidents involving law firms in 2025, almost double the number it handled in 2024. It should be noted that this number refers to matters handled by Beck Hostler, not the total number of violations that occurred at each law firm in a given year.
In his 2026 Incident Response Report, Beck Hostler analyzed more than 1,250 data security incidents across industries in 2025. Phishing was the main cause identified, accounting for 30% of incidents. The law firm said 25% of the matters it analyzes were caused by external suppliers.
The report also tracks the follow-up to the incident after it was disclosed. Beck Hostler pointed out that 14% of incidents in 2025 triggered class actions, up from 9% in 2024. Of the incidents disclosed in its data collection, 68 were subsequently sued in 2025, compared with 51 of 518 cases the previous year.
Beck Hostler's data covers clients in multiple industries, so it should not be interpreted as a ratio specific to law firms. Its report places the business and professional services industries after the medical, finance and insurance industries, among the industries it handles.
Cryptocurrency customer data is also exposed through service providers
For U.S. cryptocurrency users, another set of disclosure cases demonstrates the risk that personal details may be exposed even if the company claims that a user's funds or wallet credentials have not been accessed.
In May 2025, American exchange Coinbase disclosed that criminals bribed overseas support personnel to obtain customer information. The breach affected 69,461 users, including names, addresses, phone numbers and government ID images. Coinbase said passwords, private keys and customer funds were not compromised. The exchange rejected a $20 million ransom request from hackers and offered a reward of the same amount for information that could help arrest and convict the attacker.
Hardware wallet companies have also reported incidents involving companies that process orders or send customer messages. In January, Ledger said unauthorized access to its e-commerce partner Global-e exposed order information for some customers who purchased products through Ledger.com. A Ledger spokesperson told Decrypt that the information accessed is stored in Global-e's system, including Global-e as a record of data related to purchases made by merchants.
In August, SafePal said a vulnerability in an order-tracking plug-in exposed information about 39,798 customers. Records include names, email addresses, shipping addresses, phone numbers and purchase details. SafePal said the incident did not affect wallet credentials or payment information; it also said it had fixed the vulnerability and notified affected customers.
Trezor reported two separate incidents involving external providers. Previous reports pointed out that the wallet manufacturer said that the information of more than 80,000 customers was exposed through transportation provider ShipMonk. Trezor said its own systems, hardware wallets, private keys and mnemonics were not compromised. Its expanded disclosure also includes records for approximately 67,000 additional U.S. customers who placed orders between November 2019 and August 2021.
On September 9, Trezor warned that attackers had hacked into its third-party email provider and sent phishing emails disguised as emergency security alerts. The emails falsely claimed a hardware vulnerability that put users 'mnemonic words at risk. Trezor said it had removed the domain name used for the trial and investigated it. On the same day, BitBox warned users about emails that impersonated its company and said its newsletter provider may have been compromised.
As early as early as 2026, scammers also sent physical letters disguised as Trezor and Ledger notifications. These wallet phishing letters instruct recipients to scan QR codes and enter their mnemonic words on malicious websites. Trezor and Ledger said they do not require users to share mnemonic words through websites or other external channels.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH