ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Money, Files and Leverage: What Attackers Want From a Law Firm

Why attackers target law firms of every size, what data and access they want, and which low-cost security controls matter most for small and mid-size practices.

3 min readBy Counsel Cyber Team

Small firm partners sometimes say, "We're too small to be a target." It is an understandable belief, and it is wrong in a way that matters. Attackers rarely select victims by admiring their prestige. They select them by opportunity, and law firms offer a lot of it.

What Makes a Law Firm Attractive

You hold valuable information

A single firm may hold merger plans, litigation strategy, medical records, financial statements, immigration documents, trade secrets and personal identifiers for hundreds of people. Stolen information can be sold, used for extortion or used to trade on nonpublic news.

You move money

Real estate closings, settlements and trust accounts mean large transfers on short deadlines. That is exactly what business email compromise schemes are built around.

You face pressure to recover quickly

A firm that cannot reach its files faces missed deadlines and unhappy clients. Attackers know that pressure makes some victims willing to pay, which is the premise of ransomware.

You are connected to bigger targets

Clients, courts, insurers and co-counsel may all exchange data with you. An attacker who cannot easily breach a large corporation may try a smaller firm that serves it, hoping for a softer way in.

Security is often an afterthought

Small firms rarely have a dedicated security staff. Software goes unpatched, MFA is partial, and the person who "does IT" is the office manager. Attackers scan the internet for exactly these conditions, often with automated tools that do not care who owns the system.

What Attackers Actually Want

Understanding the goal helps you prioritize.

  1. Credentials. Email and cloud logins are the master keys. Phishing messages usually aim to steal them.
  2. Money. Through fraudulent wires, fake invoices or direct theft from compromised accounts.
  3. Extortion leverage. Encrypting files, stealing them, or both, then demanding payment.
  4. Information. Client data for sale or for competitive advantage.
  5. A foothold. Access to use your systems or email to attack your clients and contacts.

How They Usually Get In

The CISA and FBI guidance published over the years keeps pointing at a short list of entry points:

  • Phishing emails with malicious links or attachments
  • Stolen or reused passwords
  • Remote access tools with weak protection or missing updates
  • Unpatched software
  • Compromised vendors or accounts of trusted contacts

None of these require sophistication to exploit, which also means none of them require extraordinary effort to defend against.

What Works, Even on a Modest Budget

Multi-factor authentication everywhere

It blunts stolen-password attacks, the most common route in. Prefer authenticator apps or hardware keys over text messages where possible.

Patch promptly

Set a rule for how quickly critical updates must be installed, and verify it with a report.

Filter and flag email

Use modern email filtering, mark external messages and make it easy to report suspicious ones.

Watch for compromise

Endpoint detection and monitoring, ideally with people watching alerts, can catch an intruder before encryption starts.

Back up and test

Isolated, tested backups reduce the leverage of ransomware.

Train people frequently

Short, realistic, recurring sessions build habits. Pair them with a no-blame reporting culture.

Control access

Give people the access they need and no more. Remove it promptly when they leave.

The Ethics Angle

ABA Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and Formal Opinion 477R discusses how risk should shape the safeguards chosen. "Reasonable" depends on the facts, which makes documented basic controls a sensible baseline. Confirm what your state requires.

Start With an Honest Look

You do not need to guess at your exposure. A review of accounts, devices, email settings and backups will show you where the open doors are. Most are fixable with configuration changes and consistent habits rather than large purchases.

Counsel Cyber is a cybersecurity-first managed IT company built around law firms. If you want a plain-English view of where your firm stands, we can perform a security review and prioritize the fixes.