Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
10649
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (10649 indexed)

high · tech · Mar 18, 2026

Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

View incident → Original disclosure Indexed 5 months, 1 week ago
high · tech · Mar 13, 2026

Google Skia

Google Skia Out-of-Bounds Write Vulnerability — Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerabil

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Mar 13, 2026

Google Chromium V8

Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability — Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerabil

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Mar 11, 2026

n8n n8n

n8n Improper Control of Dynamically-Managed Code Resources Vulnerability — n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Mar 9, 2026

Omnissa Workspace One UEM

Omnissa Workspace ONE Server-Side Request Forgery — Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Mar 9, 2026

Ivanti Endpoint Manager (EPM)

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability — Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticat

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Mar 9, 2026

SolarWinds Web Help Desk

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability — SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on t

View incident → Original disclosure Indexed 5 months, 2 weeks ago
high · tech · Mar 5, 2026

Hikvision Multiple Products

Hikvision Multiple Products Improper Authentication Vulnerability — Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and

View incident → Original disclosure Indexed 5 months, 3 weeks ago
high · tech · Mar 3, 2026

Provecho

712,904 records exposed — Email addresses, Usernames

View incident → Indexed 5 months, 3 weeks ago
high · tech · Mar 2, 2026

KomikoAI

1,060,191 records exposed — AI prompts, Email addresses, Forum posts, Names

View incident → Indexed 5 months, 3 weeks ago
medium · tech · Mar 2, 2026

Quitbro

22,874 records exposed — Email addresses, Partial dates of birth, Usernames

View incident → Indexed 5 months, 3 weeks ago
medium · tech · Mar 2, 2026

Lovora

495,556 records exposed — Display names, Email addresses, Profile photos

View incident → Indexed 5 months, 3 weeks ago