Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
10298
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (10298 indexed)

medium · healthcare · Jul 7, 2026

KIRO7

KIRO7 reports: The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600 people. An int

View incident → Original disclosure Indexed 1 month, 3 weeks ago
high · tech · Jul 7, 2026

Adobe ColdFusion

Adobe ColdFusion Path Traversal Vulnerability — Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

View incident → Original disclosure Indexed 1 month, 3 weeks ago
high · tech · Jul 7, 2026

Langflow Langflow

Langflow Authorization Bypass Through User-Controlled Key Vulnerability — Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow bel

View incident → Original disclosure Indexed 1 month, 3 weeks ago
high · tech · Jul 7, 2026

Joomlack Page Builder

Joomlack Page Builder Improper Access Control Vulnerability — Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

View incident → Original disclosure Indexed 1 month, 3 weeks ago
medium · other · Jul 7, 2026

Accenture

IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]

View incident → Original disclosure Indexed 1 month, 3 weeks ago
high · tech · Jul 7, 2026

JoomShaper SP Page Builder

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability — JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated

View incident → Original disclosure Indexed 1 month, 3 weeks ago
critical · legal · Jul 6, 2026

Carrie Tait

Carrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the

View incident → Original disclosure Indexed 1 month, 3 weeks ago
critical · other · Jul 6, 2026

JadePuffer

An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.

View incident → Original disclosure Indexed 1 month, 3 weeks ago
high · healthcare · Jul 4, 2026

AdaptHealth

Connor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclo

View incident → Original disclosure Indexed 1 month, 3 weeks ago