Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
10294
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (10294 indexed)

medium · other · Jul 21, 2026

Seo Ji-Eun

Seo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cy

medium · other · Jul 21, 2026

The website was

The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the rans

critical · government · Jul 21, 2026

Kim Eun-bi

Kim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public b

high · tech · Jul 21, 2026

WordPress Core

WordPress Core Interpretation Conflict Vulnerability — WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulner

high · tech · Jul 21, 2026

Langflow Langflow

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitr

high · tech · Jul 21, 2026

DD-WRT DD-WRT

DD-WRT Stack-Based Buffer Overflow Vulnerability — DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code e

high · tech · Jul 21, 2026

WordPress Core

WordPress Core SQL Injection Vulnerability — WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to

critical · government · Jul 21, 2026

Colin Wood

Colin Wood reports: At least one municipal government was among those to see their internet service disrupted after a cyberattack against a Maine telecommunications firm Sunday caused an outage affecting 23 towns along t

critical · finance · Jul 20, 2026

Suno

55,282,226 records exposed — Email addresses, Names, Partial credit card data, Phone numbers and 2 more

View incident → Indexed 1 month, 1 week ago
medium · other · Jul 20, 2026

India

Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.

View incident → Original disclosure Indexed 1 month, 1 week ago
medium · other · Jul 20, 2026

Hugging Face

The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]

View incident → Original disclosure Indexed 1 month, 1 week ago