Law report No. GLW-9577 · filed October 2, 2026

Regulation & EnforcementReported case

Cyber Attacks on Law Firms Rose 77% in Past Year, Report Finds

Attacks on law firms climbed 77% in a year, Law Society Gazette figures show, putting regulatory and client-data obligations under growing pressure.

By Marcus Bennett1 min read257 words

Holding

  1. Cyber attacks on law firms increased by 77% over the past year
  2. Figures were reported by the Law Society Gazette
  3. The rise intensifies pressure on firms' data protection and regulatory compliance duties
Cyber attacks on law firms jumped by 77% over the past year - lawgazette.co.uk
PlateCyber attacks on law firms jumped by 77% over the past year - lawgazette.co.uk — AI-generated

Cyber attacks on law firms jumped by 77% over the past year, according to figures reported by the Law Society Gazette.

The steep rise signals a sharp deterioration in the security outlook for the legal profession, which holds sensitive client information, transactional data and confidential commercial material that attackers prize. Law firms have long been viewed as attractive targets precisely because of the volume of privileged and financial information they hold, often across complex chains of third-party relationships.

For practitioners, the figures carry practical weight. Firms face regulatory obligations to protect client data, and a successful breach can trigger reporting duties, regulatory scrutiny, claims from affected clients and reputational damage. Solicitors' regulators in England and Wales expect firms to maintain appropriate information governance, and a 77% year-on-year increase in attacks suggests that existing defences are coming under sustained pressure across the sector, from high-street practices to large City firms.

The upward trend also raises questions about cyber insurance pricing and coverage, supply-chain exposure, and the adequacy of employee training — with phishing and credential theft remaining the most common entry points for attackers targeting professional services. Firms that review incident response plans, tighten access controls and rehearse breach scenarios now are better placed to meet their regulatory obligations when, not if, an attack lands.

The reported figure underscores that cybersecurity is no longer a peripheral IT concern for the legal sector but a core risk management issue. Firms of every size should treat the 77% rise as a prompt to reassess their resilience.

via GN Law Society Gazette (Source)

Filed under

  • cybersecurity
  • law-firms
  • data-protection
  • regulatory-compliance
  • risk-management
Share this article:

More from Marcus Bennett

Marcus Bennett

Show full bio

Market editor covering marketplaces and e-commerce at Global Law Wire.

192 articles

Also before the court

« Previous articleNext article »