A Canadian corporate law firm engaged LeakTrace to review its client portfolio exposure ahead of a scheduled merger with a comparable firm. The engagement identified the exposure conditions integration would need to address before client relationships transferred to the combined firm.
Engagement origin
The firm operates a mid-size corporate practice with approximately eighty lawyers and support staff at one Canadian location, serving corporate clients across multiple industries. The firm was preparing to merge with a comparable firm to create a combined practice with an expanded client roster. The managing partner engaged LeakTrace to review the exposure conditions across the firm's own posture and to inform the integration planning against the merger partner's posture, which would be reviewed separately.
Discovery scope
LeakTrace conducted an external attack surface audit against the firm's registered domain, partner and associate email patterns, the firm's public web presence, public directory records associated with the Law Society of Ontario registration, and vendor mapping.
Findings summary
- Partner-level credential exposure. Several senior partners had personal email addresses in monitored breach databases with reuse patterns extending into the firm's document management system and client portal.
- Document management platform version drift. The firm's document management system had received vendor security guidance in the prior quarter the firm had not applied.
- Business email authentication gap. The firm's Sender Policy Framework configuration would have permitted spoofing attempts against client-facing recipients, elevating client-directed wire and instruction fraud risk on active matters.
- Legacy system exposure. The firm operated a legacy client billing platform that had been superseded by the current vendor but retained for reference. The legacy platform's authentication configuration was materially below current baseline.
- Client-adjacent public disclosure. The firm's public directory referenced active matters at a level of detail that a targeting actor could use to construct client-directed pretexts.
Firm actions
The firm executed remediation across all identified conditions before the merger effective date. Partner credentials were rotated and multi-factor authentication was enforced. The document management vendor's guidance was applied. Sender Policy Framework and Domain-based Message Authentication configurations were revised. The legacy billing platform was decommissioned. Client-adjacent public disclosure was reviewed with the firm's marketing team.
Outcome
The merger closed on schedule. The combined firm's client onboarding to the merged infrastructure completed without cyber incident. The managing partner retained LeakTrace as a standing partner for ongoing exposure monitoring of the combined firm.
All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any client file, or any active matter. This case file documents the pattern of pre-merger cyber baseline engagements LeakTrace conducts with Canadian corporate law firms, and is not attributed to the specific firm, merger partner, or clients referenced.