Live disclosure tracker · updated continuously

Law Firm Data Breaches

Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.

98B+
Records Exposed
11259
Incidents
94+
Countries
+104%
Breach Velocity YoY
Browse by sector
All breaches Healthcare Finance Government Technology Retail Education Legal
Browse by year
2024 2025 2026 2026 Index

Law Firm Data Breaches (11259 indexed)

critical · tech · Aug 19, 2026

Sakura Internet hack

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

View incident → Original disclosure Indexed 1 week, 6 days ago
high · retail · Aug 19, 2026

Oz Hair and Beauty

1,988,331 records exposed — Email addresses, Geographic locations, Names, Phone numbers and 1 more

View incident → Indexed 1 week, 6 days ago
critical · other · Aug 19, 2026

Waqas

Waqas reports: A server mistake by cybercriminals has exposed the inner workings of a global malware operation that used nearly 2,000 hacked WordPress websites to infect computers, steal files and deploy ransomware. Chec

View incident → Original disclosure Indexed 1 week, 6 days ago
high · tech · Aug 18, 2026

Microsoft SharePoint

Microsoft SharePoint Weak Authentication Vulnerability — Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

medium · other · Aug 18, 2026

SafePal has

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware w

medium · tech · Aug 18, 2026

Tiffany Wang

Tiffany Wang reports: A prolific Russian-speaking extortion group known for supply-chain attacks claimed to have stolen data from more than 40 firms including heavyweight corporations such as oil giant Shell and manufact

high · tech · Aug 18, 2026

Broadcom VMware vCenter

Broadcom VMware vCenter Path Traversal Vulnerability — Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

critical · finance · Aug 18, 2026

A Heights Finance breach

A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal lo