Greenberg Traurig’s disclosure that a limited number of documents were posted on the dark web lands in a wider mess: law firms and crypto companies keep getting clipped through vendors, support channels, and phishing, not just by some cinematic smash-and-grab on core systems.
- Dark web exposure: Reuters reported on Sept. 10 that Greenberg Traurig confirmed unauthorized access and said a limited number of documents were posted online.
- Weak links win: BakerHostetler’s 2026 report found phishing led 30% of incidents, while vendors were involved in 25% of matters analyzed.
- Crypto is vulnerable too: Recent disclosures from Coinbase, Ledger, SafePal, and Trezor show how attackers abuse support staff, shipping partners, email providers, and other outside services.
- No keys, still pain: Even when passwords, private keys, and funds are not compromised, stolen personal data can still fuel fraud and identity abuse.
Reuters reported that Greenberg Traurig confirmed unauthorized access after a limited number of documents were posted on the dark web. The firm did not identify what the documents contained, and it did not say how many people, if any, were affected.
That missing detail matters, but not because it makes the incident small. It usually means the scope is still being sorted out, or the firm is being careful about what it says publicly. Either way, “limited number of documents” does not automatically mean limited damage. One privileged file can be enough to create a very expensive headache.
The broader pattern is the part worth paying attention to.
BakerHostetler said it handled nearly 60 cybersecurity incidents involving law firms in 2025, almost twice the number it handled in 2024. In its 2026 incident-response report, the firm said it analyzed more than 1, 250 data security incidents across industries in 2025. Phishing was the leading identified cause at 30%, and outside vendors were involved in 25% of the matters analyzed.
That is the real story here: attackers keep finding the soft spots around the perimeter. Not always the vault. Often the people, the vendors, the inboxes, and the outsourced workflows no one thinks about until something goes sideways.
Phishing is the classic fake message designed to steal credentials or sensitive information. Social engineering is the broader con, tricking people into handing over access, data, or trust. It works because humans are, inconveniently, human. A firewall can’t stop someone from believing an email that looks urgent enough to panic them into clicking.
Law firms are obvious targets because they sit on a mountain of sensitive material: client records, litigation strategy, merger documents, personal data, financial information, and sometimes health records. Even a “limited” document dump can be serious if it contains privileged or confidential material. Attackers do not need every file; they just need the right one.
The same ugly lesson keeps showing up in crypto.
In May 2025, Coinbase disclosed that criminals bribed overseas support agents to obtain customer information. Coinbase said 69, 461 users were affected. The exposed data reportedly included names, addresses, phone numbers, and images of government IDs. Coinbase also said passwords, private keys, and customer funds were not compromised.
That distinction is crucial. If private keys stay safe, the exchange’s core custody systems were not directly popped. But exposed personal data is still useful to scammers. It can feed phishing, SIM swaps, identity theft, and account takeover attempts. Losing a wallet seed phrase is catastrophic; losing an ID scan and phone number is a very nice starter kit for the next scammer in line.
Coinbase said it rejected a $20 million ransom demand and offered the same amount as a reward for information leading to the attackers’ arrest and conviction. That is the right instinct more often than not. Paying criminals encourages more extortion. It does not guarantee safety anyway, and it certainly does not buy dignity.
Other crypto firms have been forced to explain similar weak-link failures.
In January, Ledger said unauthorized access to its e-commerce partner Global-e exposed order information for some people who bought products through Ledger.com. A Ledger spokesperson told Decrypt that the accessed data was held in Global-e’s systems and related to purchases for which Global-e acted as the merchant of record. In plain English: Ledger’s own hardware wallets were not the issue. The exposure came through the company handling the sale data.
In August, SafePal said a flaw in an order-tracking plug-in exposed information belonging to about 39, 798 customers. The exposed records included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal said the incident did not affect wallet credentials or payment information. It also said it fixed the flaw and notified affected customers.
Trezor reported two separate third-party problems as well. First, it said information belonging to more than 80, 000 customers was exposed through shipping provider ShipMonk. Trezor said its own systems, hardware wallets, private keys, and recovery phrases were not compromised. It later expanded that disclosure to include records belonging to about 67, 000 additional U.S. customers who had placed orders between November 2019 and August 2021.
Then came the phishing push. On Sept. 9, Trezor warned that an attacker had breached its third-party email provider and sent messages posing as urgent security alerts. Those emails falsely claimed a hardware flaw put users’ recovery phrases at risk. Trezor said it had taken down the domain used in the attempt and was investigating. BitBox warned users the same day about emails impersonating its company and said its newsletter provider was likely compromised.
For newer readers: a recovery phrase is the backup set of words that can restore access to a self-custody wallet. In most cases, anyone with that phrase can restore the wallet and move the funds. Private keys are the cryptographic secrets that authorize transactions. If those leak, funds can be stolen quickly. That is why legitimate wallet companies do not ask users to type recovery phrases into websites or hand them over through email, DMs, or any other outside channel. If someone asks for it, assume scam first and ask questions later.
The legal fallout is climbing too. BakerHostetler said class actions were filed in 14% of incidents in 2025, up from 9% in 2024. Among disclosed incidents in its dataset, lawsuits followed 68 of 482 in 2025, compared with 51 of 518 in the prior year. In other words, a breach is not just an IT problem anymore. It is often a legal, reputational, and operational mess from day one.
There is a useful devil’s-advocate point here. Companies love to say “passwords, private keys, and customer funds were not compromised, ” and yes, that is better than the nightmare version. But it is not the same as harmless. Names, addresses, phone numbers, government IDs, order histories, and access to inboxes can still be weaponized. Attackers do not need the whole vault if they already stole the keys to the side door.
The pattern is simple, even if the fallout is not:
law firms sit on sensitive records attackers want;
crypto companies rely on vendors and support layers that can be abused;
and the most common failure mode is still not some Hollywood zero-day, but ordinary human trust being milked for all it is worth.
Key questions and takeaways
-
Why are law firms such attractive targets?
They store highly sensitive client material, including privileged documents and personal records. Even a small leak can cause serious legal, financial, and reputational damage. -
What does BakerHostetler’s data actually show?
In its dataset of more than 1, 250 incidents across industries, phishing was the leading identified cause at 30%, and vendors were involved in 25% of matters analyzed. That points to people and third parties as major weak spots. -
Does a crypto breach always mean funds were stolen?
No. Several of the disclosures here involved customer data exposure without passwords, private keys, or wallet funds being compromised. But stolen personal data can still be used for fraud and phishing. -
Why are recovery phrases so sensitive?
A recovery phrase can restore access to a self-custody wallet. If an attacker gets it, they may be able to control the wallet and move the assets. -
What is the common thread across these incidents?
Third-party risk, phishing, and social engineering. Email providers, shipping firms, support agents, and order processors keep showing up as the weak links attackers love to abuse. -
Why does “no private keys compromised” still matter?
It means the direct route to the funds was not breached, which is good news. But exposed personal data can still lead to identity theft, phishing, SIM swaps, and other follow-on attacks.
The ugly truth is that a lot of cyber risk now looks less like a fortress being cracked and more like a chain of handoffs where one weak link ruins the whole thing. That is true in law, in crypto, and in any business that outsources something important and assumes the vendors will behave like adults.
Further reading
A few more angles on the same weak-link problem, from cyberattacks to exchange strategy.
- Law firm documents appear on dark web as cyberattacks rise
- Verification Successful: Waiting for Response from Coinbase
- Why Cybersecurity and Third-Party Risk Need to Be Aligned
- Third-party management
- Law firm documents appear on dark web as cyberattacks rise
- Coinbase Overhauls Advanced Trading to Chase Global Crypto
- Coinbase Eyes Tokenized Stocks for Non-U.S. Users as Wall
- Coinbase CEO Brian Armstrong Says Bitcoin Is Still Bullish