BNB $726.40 +0.03%
XRP $1.37 +0.03%
ETH $2,521.11 -0.72%
BTC $77,150.34 -0.28%
BNB $726.40 +0.03%
XRP $1.37 +0.03%
ETH $2,521.11 -0.72%
BTC $77,150.34 -0.28%
BREAKING
Crypto Exchanges

Greenberg Traurig Breach Exposes Client Data as Dark Web Listings Surge

Law Firms and Crypto Exchanges Bleed Data as Dark Web Listings Hit 69,000 Users
Law Firms and Crypto Exchanges Bleed Data as Dark Web Listings Hit 69,000 Users

Community Trust ScoreVerified

95%
Real
Verified22 votes
Updated 1 hour ago

Greenberg Traurig confirmed it. An unauthorized actor got into a limited number of documents, and some of those documents ended up on the dark web. The firm hasn’t said what was in them or who got hurt.

That’s basically the whole disclosure — short, tight, and deliberately vague. No specifics about affected clients, no timeline beyond the breach itself, no word on how the attacker got in. It’s the kind of statement that tells you something happened while making sure you can’t figure out exactly what. Pretty much every major firm that’s been hit recently has done the same thing.

A Bad Year for Legal Sector Security

Greenberg Traurig isn’t alone. Not even close. Taft Stettinius & Hollister flagged unusual activity back in March — clients’ Social Security numbers were exposed. Herbert Smith Freehills Kramer reported unauthorized access in May, and that one was worse: personal identification numbers and health records were compromised. WilmerHale’s breach ended up in a proposed class action filed in July, with plaintiffs alleging sensitive information got out. Goodwin Procter reported a breach too. So did Quinn Emanuel, though Quinn Emanuel’s situation was different — the attacker didn’t use malware or exploit a software flaw. It was social engineering. Someone got manipulated into handing over access. No technical hack required.

Advertisement

That last one matters. Social engineering is hard to patch. You can update software. You can’t always update people.

BakerHostetler put some numbers to all of this. The firm said it managed nearly 60 cybersecurity incidents for law firms in 2025, up from the year before. Their broader analysis covered more than 1,250 data security incidents across sectors and found phishing was one of the leading causes. And class actions followed 14% of disclosed incidents in 2025. BakerHostetler was careful to note those figures aren’t specific to the legal industry alone — but the trend inside law firms is clearly moving in the wrong direction.

Law firms are obvious targets. They hold financial records, merger details, litigation strategies, health data, personal identifiers. Everything an attacker could want is sitting in one place, often protected by security infrastructure that hasn’t kept pace with the threat.

Crypto’s Data Problem Runs Parallel

The legal sector isn’t the only one bleeding data. Crypto has its own mess.

Coinbase disclosed a breach in 2025 where criminals bribed overseas support agents to pull user information. More than 69,000 users were affected. No funds were taken, no wallet credentials accessed — but the attackers still hit Coinbase with a $20 million ransom demand. The exchange didn’t say whether it paid.

Ledger and SafePal have both reported breaches involving customer information, typically through third-party partners rather than direct attacks on core systems. And Trezor disclosed phishing attacks that used compromised email providers to reach customers. The attacker didn’t need to break into Trezor directly — they just got into an email vendor and went from there.

That’s the pattern. You don’t always attack the target. You attack whoever the target trusts.

Phishing, Bribery, Deception — The Toolkit Is Wide

What’s striking across all of these incidents is how different the attack methods are. Phishing. Social engineering. Third-party vendor compromise. Insider bribery. There’s no single vulnerability to fix. Firms in every sector are dealing with attackers who are patient, creative, and clearly doing their homework.

And the legal consequences are piling up. The 14% class action rate BakerHostetler tracked is probably an undercount — plenty of breaches don’t get disclosed at all, or get disclosed in ways that minimize what actually happened. Greenberg Traurig’s statement is a good example. “A limited number of documents” is doing a lot of work in that sentence.

For crypto companies specifically, the data breach problem has a sharper edge. Users trust exchanges and wallet makers with information tied directly to financial assets. Even when the funds themselves aren’t touched — as with Coinbase — the exposed data can be used for targeted phishing, SIM swapping, or physical threats. The breach doesn’t have to touch the wallet to cause real damage.

Trezor’s situation is worth sitting with. The attack came through a compromised email provider. Trezor’s own systems may have been fine. Didn’t matter. The attacker found a side door through a vendor, reached customers directly, and ran a phishing campaign from what looked like a legitimate address.

The Greenberg Traurig breach involved a limited number of documents, per the firm’s own statement — but “limited” is undefined, and the dark web listing is real.

Frequently Asked Questions

What did Greenberg Traurig say about its data breach?

Greenberg Traurig confirmed an unauthorized actor accessed a limited number of documents, some of which appeared on the dark web, but did not disclose the content of those documents or which parties were affected.

How did the Coinbase breach in 2025 happen?

Criminals bribed overseas support agents to access user data, compromising information belonging to more than 69,000 users; no funds or wallet credentials were accessed, but Coinbase received a $20 million ransom demand.

Why It Matters

The breach at Greenberg Traurig highlights the ongoing vulnerabilities within the crypto sector, where sensitive information is increasingly targeted by malicious actors. As the number of dark web listings continues to rise, it raises concerns about the security measures employed by law firms and exchanges that handle significant amounts of sensitive client data, potentially undermining trust in the crypto ecosystem. This incident serves as a reminder of the critical need for enhanced cybersecurity protocols in an industry that is still grappling with its legitimacy and regulatory challenges.

Community Trust IndexHigh Confidence
95%
Real
Real95%5%Fake
22 community signals

Steven Anderson

Steven is a technology-focused writer with a strong interest in emerging digital trends and innovation. With experience spanning both travel and online projects, he brings a global perspective to his reporting and analysis. His work reflects a practical understanding of how technology, markets, and digital platforms intersect, offering readers clear insights into developments shaping the modern tech and crypto landscape.

Advertisement

Related Stories