Most visitors decide in 5 seconds whether they understand what you do. Ours is a free, no-pressure look at your site.

Data BreachWar StoriesSecurityInsider Threat

What Happens When a Law Firm Gets Hacked — A Real Story

Patryk Stanczak, Founder & CEOFebruary 24, 20268 min read
GH

Geek Heros War Stories

It Started With a Netflix Password

The senior partner at a 15-attorney litigation firm used the same password for everything. His Netflix account. His personal email. His Amazon account. And his work email.

He'd been using this password — a combination of his daughter's name and birth year — for over a decade. He knew he shouldn't. He'd heard the advice about unique passwords dozens of times. But he was busy, he had dozens of accounts, and remembering different passwords for each one felt impossible.

In September 2025, Netflix experienced a data breach that exposed user credentials. The partner's email and password appeared in the breach data within hours. Within days, that data was available on dark web marketplaces for pennies.

An attacker — likely an automated system scanning breach data against corporate email domains — tried the exposed password against the partner's work email. It worked. No MFA. No conditional access policies. No alert triggered. The attacker was in.

47 Days of Silent Access

What happened next is what security professionals call "dwell time" — the period between initial compromise and detection. The average dwell time for a data breach is 204 days. This firm discovered the breach after 47 days, which is actually faster than average. It still wasn't fast enough.

During those 47 days, the attacker:

Read email. Every email in the partner's inbox, sent folder, and archive. This partner was the lead attorney on several high-value commercial litigation matters. His email contained privileged case strategies, settlement discussions, client financial information, and confidential communications with opposing counsel.

Set up a forwarding rule. All incoming email was silently forwarded to an external address controlled by the attacker. Even after the password was eventually changed, the forwarding rule continued to operate — sending copies of every new email to the attacker.

Accessed shared drives. Using the partner's credentials, the attacker accessed the firm's shared network drives, which contained client files dating back years. The drives had no access logging enabled, so we could never determine exactly which files were accessed or exfiltrated.

Sent emails. On three occasions, the attacker sent emails from the partner's account to clients, requesting wire transfers for "settlement payments." Two clients recognized the requests as unusual and called the firm to verify. One did not. That client wired $47,000 to an account controlled by the attacker. The money was never recovered.

Discovery

The breach was discovered when the firm's accounting manager noticed a discrepancy in the client trust account. A client had claimed to have wired a settlement payment, but the funds never arrived in the firm's trust account. The accounting manager called the client, who provided a wire confirmation to an account number that didn't match the firm's accounts.

That triggered an internal investigation, which led to the discovery of the email forwarding rule, which led to the discovery of the full scope of the compromise. The firm called us at that point.

The Aftermath

What followed was months of damage control, at enormous financial and reputational cost:

Forensic investigation: $85,000. We engaged a certified forensic investigation firm to determine the full scope of the breach — what was accessed, what was exfiltrated, and how long the attacker had been inside. The investigation took six weeks.

Client notification: $35,000. The firm was legally required to notify every client whose data may have been exposed. This included drafting notification letters, setting up a dedicated phone line for client inquiries, and providing credit monitoring services to affected individuals. Over 200 clients were notified.

Legal defense: $120,000. The firm faced two malpractice claims from clients whose confidential information was exposed, a bar complaint from a client whose litigation strategy was compromised, and a demand from the client who lost $47,000 in the wire fraud scheme. Outside counsel was retained to manage all four matters.

Systems remediation: $45,000. Complete security overhaul — MFA deployment, password policy enforcement, email security configuration, access logging implementation, conditional access policies, endpoint protection, and security awareness training for all staff.

Increased insurance premiums: $15,000/year. The firm's cyber insurance premiums increased by approximately $15,000 annually at the next renewal, and the carrier imposed additional security requirements as a condition of continued coverage.

Lost clients: Incalculable. Within six months of the breach notification, four clients — including the firm's largest corporate client — moved their business to other firms. The managing partner estimated the lost revenue at over $400,000 annually.

Total quantifiable costs: approximately $340,000 — not including lost revenue from departed clients.

The Bar Complaint

One of the most painful consequences was the bar complaint. A client whose litigation strategy was compromised — the opposing party seemed to suddenly know exactly what motions and arguments the firm was planning — filed a complaint alleging that the firm failed to meet its ethical obligation to protect client confidentiality under Rule 1.6.

The disciplinary review found that the firm's security practices at the time of the breach fell below the standard of "reasonable efforts" required by the rule. Specifically, the committee cited the absence of MFA, the failure to implement unique password requirements, the lack of email security monitoring, and the absence of access logging on file systems containing client data.

The partner received a private reprimand. The firm was required to implement specific security measures and submit a compliance report. The managing partner described the experience as "professionally humiliating."

100% Preventable

Every element of this breach — from the initial compromise to the 47-day dwell time to the wire fraud — was preventable with basic security controls:

Unique passwords would have prevented the credential stuffing attack that used the Netflix breach data. A password manager makes this trivial.

MFA would have blocked the attacker from logging in even with the correct password. A simple authenticator app on the partner's phone would have stopped the entire attack chain.

Email security rules that alert on new forwarding rules would have detected the attacker's persistence mechanism within hours instead of weeks.

Access logging on shared drives would have created a record of which files were accessed and when, reducing the scope of the required client notifications.

Security awareness training would have reinforced the importance of unique passwords and taught the partner to recognize the risk of credential reuse.

The total cost of implementing all of these controls? Approximately $2,000 per month for the entire firm. The cost of not implementing them? $340,000 in direct costs, $400,000+ in lost annual revenue, a bar complaint, and lasting damage to the firm's reputation.

How secure is your firm, really? [Get a free site audit](#assessment) and find out before a reused password costs you everything.

Get Your Free Site Audit

Find out where your firm stands on security, compliance, and IT performance — at no cost.

Related Articles

Ready to see where your brand stands?