What Actually Happens When a Law Firm Gets Hacked

Article summary: A law firm data breach can trigger ethical obligations, Texas notification requirements, operational disruptions, and difficult client conversations. A written response plan, continuous monitoring, and protected backups can help firms contain an incident and recover more effectively. Preparing before an attack gives attorneys a clearer path forward while helping limit disruption to clients and the practice.
It usually starts small. A paralegal notices the document system is crawling. Then a client calls to ask why your firm just emailed them new wiring instructions.
By lunch, everyone realizes this is not a glitch.
The attack itself may only be the beginning. What follows can involve forensic investigations, legal obligations, tight deadlines, and difficult conversations that the firm may never have rehearsed.
Proactive cybersecurity can reduce the likelihood and impact of an attack. Every managing partner should still understand what the days after a law firm data breach can actually look like.
The First 72 Hours Are Chaos Without a Plan
The first priority after discovering an attack is containment. Affected systems may need to be isolated or taken offline while an incident response team determines how the attacker got in, what systems were affected, and whether data was accessed or stolen.
At the same time, the practice does not simply stop. Attorneys still have hearings, deadlines, client calls, and cases that need attention.
This is when firms without a plan start asking basic questions under pressure. Who contacts the cyber insurance carrier? Who coordinates with IT and forensic investigators? Who communicates with employees and clients? Who has the authority to take critical systems offline?
The ABA’s 2023 Cybersecurity TechReport found that only 34% of respondents had an incident response plan, down from 42% the previous year.
A written plan answers those questions before an attack happens, giving the firm a roadmap for making difficult decisions when every minute counts.
The Legal Fallout of a Law Firm Data Breach
Once the immediate threat is contained, the legal and practical fallout begins. For lawyers, a breach can also raise professional responsibility and notification obligations.
Your Ethical Duties to Clients
ABA Formal Opinion 483 outlines lawyers’ ethical obligations after a data breach. Lawyers should act promptly to stop the breach, restore operations, determine what occurred, and evaluate what information may have been accessed.
The opinion also explains that lawyers must notify current clients when material client information was actually or reasonably suspected to have been accessed, disclosed, or lost.
Texas Sets Its Own Clock
Texas breach notification law creates additional requirements. Affected individuals generally must be notified as quickly as possible and no later than 60 days after the firm determines that a breach occurred.
If a breach affects at least 250 Texas residents, the firm must also notify the Texas Attorney General as quickly as possible and no later than 30 days after determining that a breach occurred.
Lawsuits Can Follow
A breach can also lead to litigation.
After law firm Orrick experienced a data breach affecting more than 638,000 people, litigation followed and ultimately resulted in an $8 million class-action settlement. BankInfoSecurity reported that the settlement received final court approval in 2025.
A smaller firm may face a very different incident, but the Orrick case illustrates how the consequences of a breach can continue long after systems are restored.
The Practical Fallout Nobody Budgets For
The costs of a breach can add up quickly. Depending on the incident, a firm may face expenses for forensic investigators, breach counsel, data recovery, client notifications, credit monitoring, and other response efforts.
IBM’s 2026 Cost of a Data Breach Report found that the average U.S. data breach cost reached $11.5 million. The global average climbed 12% to a record $4.99 million.
Those figures cover organizations across IBM’s study and should not be treated as the expected cost for a small law firm. But even a much smaller incident can create expenses that are difficult to absorb.
Then there are costs that are harder to put on an invoice:
- Lost productivity while attorneys and staff work around unavailable systems
- Lost billable time while devices and data are restored
- Client concerns about the security of sensitive information
- Potential changes to cyber insurance costs or requirements
- Added pressure on employees working through the disruption
Cyber insurance can help manage some of the financial risk, but firms also need to understand what their policies require. Our guide to answering cyber insurance renewal questions explains how to approach the process without putting coverage at risk.
How to Make a Breach Survivable
No firm can guarantee it will never experience a cyberattack. What you can control is how prepared you are to respond.
Start with a written incident response plan. Identify who contacts the insurer, coordinates with IT and legal counsel, and communicates with clients when necessary. Decide who has the authority to isolate or shut down affected systems. Our guide to building a business continuity plan covers the essentials.
Next, monitor your network and systems for suspicious activity. Early detection can give your team more time to contain an intrusion before an attacker causes additional damage.
Finally, maintain protected backups that cannot easily be altered or deleted if your primary systems are compromised. Clean, isolated backups give your firm another path to recovery when ransomware or other incidents make critical data unavailable.
Preparation will not prevent every breach, but it can be the difference between scrambling for answers and following a response plan your firm has already tested.
Is Your Firm Ready for Its Worst Day?
A law firm data breach can test your technology, your response plan, and your client relationships all at once. Preparation cannot eliminate the disruption, but it can give your team a clearer path forward when every decision matters.
Digital Crisis was founded by a former hacker who understands how attackers look for weaknesses. We help Texas law firms put monitoring, protected backups, and response planning in place before an incident happens.
Do not wait for a breach to find the gaps in your defenses. Call (713) 965-7200 or contact Digital Crisis online to schedule a consultation.
Article FAQs
What should a law firm do first after a data breach?
Contain the incident and follow your response plan. Isolate affected systems and contact the appropriate IT, legal, insurance, and forensic resources.
Do Texas law firms have to report a data breach?
It depends on the incident. When notification is required, affected individuals generally must be notified within 60 days. Breaches affecting at least 250 Texans must also be reported to the Texas Attorney General within 30 days.
Do lawyers have to tell clients about a data breach?
Yes, in certain circumstances. ABA Formal Opinion 483 requires notice to current clients when material client information was accessed or reasonably suspected to have been accessed, disclosed, or lost.