Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
10307
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (10307 indexed)

high · tech · May 20, 2026

Microsoft DirectX

Microsoft DirectX NULL Byte Overwrite Vulnerability — Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to

View incident → Original disclosure Indexed 3 months, 1 week ago
high · tech · May 20, 2026

Adobe Acrobat and Reader

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability — Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted P

View incident → Original disclosure Indexed 3 months, 1 week ago
high · tech · May 20, 2026

Microsoft Internet Explorer

Microsoft Internet Explorer Use-After-Free Vulnerability — Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associate

View incident → Original disclosure Indexed 3 months, 1 week ago
medium · tech · May 19, 2026

CTT

468,124 records exposed — Email addresses, Names, Phone numbers

View incident → Indexed 3 months, 1 week ago
critical · finance · May 18, 2026

Addi

34,532,941 records exposed — Age groups, Credit scores, Device information, Email addresses and 9 more

View incident → Indexed 3 months, 1 week ago
high · tech · May 15, 2026

Microsoft Microsoft

Microsoft Exchange Server Cross-Site Scripting Vulnerability — Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditi

View incident → Original disclosure Indexed 3 months, 2 weeks ago
high · finance · May 14, 2026

Abrigo

711,099 records exposed — Email addresses, Employers, Job titles, Names and 2 more

View incident → Indexed 3 months, 2 weeks ago
high · tech · May 14, 2026

Cisco Catalyst SD-WAN

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass a

View incident → Original disclosure Indexed 3 months, 2 weeks ago
medium · government · May 12, 2026

Cushman & Wakefield

310,431 records exposed — Email addresses, Job titles, Names, Phone numbers and 2 more

View incident → Indexed 3 months, 2 weeks ago
medium · finance · May 8, 2026

Zara

197,376 records exposed — Email addresses, Geographic locations, Purchases, Support tickets

View incident → Indexed 3 months, 3 weeks ago
high · tech · May 8, 2026

BerriAI LiteLLM

BerriAI LiteLLM SQL Injection Vulnerability — BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized acces

View incident → Original disclosure Indexed 3 months, 3 weeks ago
medium · tech · May 7, 2026

Woflow

447,593 records exposed — Email addresses, Names, Phone numbers, Physical addresses

View incident → Indexed 3 months, 3 weeks ago
high · tech · May 6, 2026

Palo Alto Networks PAN-OS

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability — Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an un

View incident → Original disclosure Indexed 3 months, 3 weeks ago