Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
10310
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (10310 indexed)

high · tech · Apr 28, 2026

Microsoft Windows

Microsoft Windows Protection Mechanism Failure Vulnerability — Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

critical · tech · Apr 28, 2026

ConnectWise ScreenConnect

ConnectWise ScreenConnect Path Traversal Vulnerability — ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and cri

high · government · Apr 27, 2026

ADT

5,488,888 records exposed — Dates of birth, Email addresses, Names, Partial government issued IDs and 2 more

View incident → Indexed 4 months ago
high · tech · Apr 27, 2026

Pitney Bowes

8,243,989 records exposed — Email addresses, Job titles, Names, Phone numbers and 1 more

View incident → Indexed 4 months ago
high · finance · Apr 26, 2026

Udemy

1,401,259 records exposed — Email addresses, Employers, Job titles, Names and 3 more

View incident → Indexed 4 months ago
critical · tech · Apr 24, 2026

SimpleHelp SimpleHelp

SimpleHelp Missing Authorization Vulnerability — SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be

high · tech · Apr 24, 2026

D-Link DIR-823X

D-Link DIR-823X Command Injection Vulnerability — D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to