Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive databaseste data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
9672
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (9672 indexed)

critical · finance · Aug 18, 2026

A Heights Finance breach

A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal lo

high · tech · Aug 18, 2026

Broadcom VMware vCenter

Broadcom VMware vCenter Path Traversal Vulnerability — Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

high · tech · Aug 18, 2026

Apple macOS

Apple macOS Improper Authentication Vulnerability — Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

medium · other · Aug 18, 2026

SafePal has

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware w

medium · government · Aug 18, 2026

Security researchers are

Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyb

medium · tech · Aug 18, 2026

Tiffany Wang

Tiffany Wang reports: A prolific Russian-speaking extortion group known for supply-chain attacks claimed to have stolen data from more than 40 firms including heavyweight corporations such as oil giant Shell and manufact

high · tech · Aug 17, 2026

Ray-Project Ray

Ray-Project Ray Code Injection Vulnerability — Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerabili

View incident → Original disclosure Indexed 1 week, 1 day ago