Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
10274
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (10274 indexed)

high · tech · Jul 27, 2026

Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability — Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged intern

high · tech · Jul 27, 2026

Fortinet FortiOS

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability — Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote u

high · tech · Jul 25, 2026

Jessica Lyons

Jessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked

medium · other · Jul 25, 2026

ShinyHunters data

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

medium · finance · Jul 24, 2026

Roxanne Libatique

Roxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations

medium · other · Jul 24, 2026

OnTrac

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]

medium · education · Jul 24, 2026

Bob Chiarito

Bob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying

medium · tech · Jul 24, 2026

Chick-fil-A has

Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]