Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
9972
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (9972 indexed)

high · tech · Aug 4, 2026

N-able N-central

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability — N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

View incident → Original disclosure Indexed 3 weeks, 1 day ago
high · tech · Aug 4, 2026

IBM Langflow

IBM Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

View incident → Original disclosure Indexed 3 weeks, 1 day ago
high · tech · Aug 4, 2026

Apache Tomcat

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability — Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

View incident → Original disclosure Indexed 3 weeks, 1 day ago