September 22, 2026
For law firms, a cybersecurity incident does not necessarily end when access is restored; the affected account is secured, or the technical investigation is complete. The legal, financial, and reputational consequences can continue for months or even years.
That is the key lesson from proposed class actions filed against Greenberg Traurig following an August 2026 data incident.
Reuters reported on September 21 that the firm is facing two proposed class actions in the Southern District of New York. The complaints allege that sensitive personal information connected to the firm's legal work was exposed and that the firm failed to implement appropriate safeguards.
Greenberg Traurig has said that an unauthorized actor accessed a limited number of documents, that only a small number of clients were affected and that its systems were not compromised or breached. The firm also said its operations continued without disruption.
The lawsuits present a different perspective. Plaintiffs allege that the incident exposed information such as names, contact information, dates of birth, and Social Security numbers. They are seeking to represent others who may have been affected.
These are allegations. The cases are still active, no class has been certified, and the claims have not been adjudicated. Still, the filings demonstrate why law firms must consider more than whether their network remained operational.
Read the full article about the Greenberg Traurig lawsuits.
"Our Systems Were Not Breached" May Not End the Conversation
A law firm does not need to experience a complete network shut down for a cybersecurity incident to create serious consequences.
Unauthorized access to a document repository, email account, cloud platform or individual computer may expose confidential information even if the firm's central systems remain available. From the client's perspective, the distinction between a full network breach and access to a limited set of documents may matter less than what information was exposed.
The Greenberg Traurig incident is an important example. The firm reported limited document access and no disruption to its broader systems. Proposed class actions followed anyway.
This does not mean every cyber incident will result in litigation. It does mean law firms should be prepared for the possibility that affected individuals, clients, regulators, insurers or other parties may continue asking questions long after the initial technical response.
Law Firms Hold Information That Extends Beyond Their Clients
Law firms may store personal and confidential information belonging to clients, employees, opposing parties, witnesses, customers involved in litigation and other individuals who have never directly hired the firm.
Depending on the practice area, that information could include:
- Social Security numbers and dates of birth
- Financial and medical information
- Employment and personnel records
- Litigation documents and discovery materials
- Intellectual property and business plans
- Merger, acquisition and transaction records
- Attorney-client communications
- Login credentials or account information
That concentration of valuable information makes law firms attractive targets. It can also increase the number of people and organizations affected when even a limited collection of files is accessed.
Attackers Are Targeting People, Not Just Technology
Law firms also need to recognize that modern attacks do not always begin with a technical vulnerability.
In May 2026, the FBI warned that Silent Ransom Group had been targeting U.S. law firms through social engineering. Attackers posed as IT personnel and attempted to persuade employees to install remote-access software, provide access to their computers or allow someone claiming to be technical support into the workplace.
The group focuses on stealing data and threatening to publish or sell it, sometimes without encrypting the victim's systems. Because attackers may use legitimate remote access and cloud storage tools, traditional antivirus software may not immediately identify the activity. Read the FBI's warning to law firms.
This is why cybersecurity training must go beyond identifying suspicious email links. Attorneys and staff should know how legitimate IT support will contact them, how identities will be verified, and what to do when someone requests remote or physical access to a device.
Prepare for the Legal Aftermath Before an Incident
The technical response to a cyber incident is only one part of the process. A law firm may also need to preserve evidence, work with outside counsel, contact its cyber insurance carrier, evaluate notification requirements, communicate with clients, and respond to questions from regulators or affected individuals.
Those decisions are difficult to make under pressure if responsibilities have not been assigned in advance.
Law firms should consider taking the following steps:
- Know where sensitive information is stored. Identify the systems, cloud platforms, email accounts, and document repositories containing confidential or regulated information.
- Limit unnecessary access. Attorneys and employees should have access only to the information required for their roles. Former employees and unused accounts should be removed promptly.
- Strengthen identity protection. Use phishing-resistant multifactor authentication where possible, especially for email, document systems, remote access, and administrative accounts.
- Verify IT support requests. Create a documented process employees can use to confirm the identity of anyone requesting access to their computer, account or office.
- Maintain usable logs and records. Your firm may need to determine what was accessed, when it happened, and which individuals were affected. That becomes much harder without appropriate logging and retention.
- Test the incident response plan. Include leadership, IT, legal counsel, insurance contacts, communications staff and critical vendors in the exercise.
- Review vendors and cloud platforms. Understand which providers hold firm or client information, what security controls they use, and how they will assist during an investigation.
Cybersecurity Is Also Litigation Preparedness
The lasting takeaway is not that every law firm will experience a breach or face a class action. It is that the consequences of an incident may continue long after the immediate technology problem appears resolved.
A limited incident can still involve highly sensitive information. A firm can remain operational and still face notification responsibilities, client concerns, insurance questions and lawsuits. Technical recovery alone does not close the matter.
DigeTekS helps law firms strengthen cybersecurity, manage access, document critical systems, review backup and recovery processes, and prepare for technology disruptions. Our goal is to help your firm reduce risk before an incident and respond more confidently if one occurs.
How prepared is your firm for both the cyber incident and what comes afterward?
Schedule a free 15-minute discovery call with DigeTekS for a second look at your firm's cybersecurity readiness.