DEV Community

Cover image for AI-Powered Attacks Are Coming for Law Firms' Most Sensitive Files
Jeanclaude Aoun for Untrace Network

Posted on Originally published at untrace.network

AI-Powered Attacks Are Coming for Law Firms' Most Sensitive Files

If you have ever bought a house, gone through a divorce, settled an injury claim or signed an employment contract, a law firm may hold a copy of your passport, your tax return or your medical records. Law firms keep an extraordinary concentration of the documents people work hardest to protect: government IDs, financial records, health information and the legal strategy behind live cases.

That pile has always been a target. What is changing is the attacker's toolkit. Criminals are now using AI to research targets, write convincing approaches, test ways in and work through stolen data faster than any manual team could. The danger is not that an AI decides on its own to attack a law firm. The danger is that the people who already attack law firms can now do more, faster.

What happened in the 2026 law firm data breaches?

Between Memorial Day and Labor Day, at least 10 large US law firms confirmed a data breach, according to The American Lawyer, and many of those attacks relied on social engineering. These incidents reveal the prize attackers are pursuing. AI changes the speed, scale and precision with which they can pursue it.

Quinn Emanuel: one account, one application. In a letter seen by Reuters, the firm said an "unauthorized third party obtained access through social engineering" on 14 August and reached "stored files for a single software application through one temporarily compromised user account."

McDermott Will & Schulte: one user, a limited set of documents. McDermott told the Vermont attorney general that the exposed files included Social Security numbers and health data, according to the same Reuters report, and called it "an isolated social engineering incident involving a single user."

Seyfarth Shaw: a fake help desk. Someone posing as Seyfarth's IT help desk "deceived" an employee into emailing "a limited number of client documents to an unauthorized outside account," Above the Law reported, citing Reuters.

Herbert Smith Freehills Kramer. According to JD Journal, the firm's filings said the information may have included Social Security numbers, government ID numbers and some health information.

Four 2026 law firm breaches and how each one started: one compromised account at Quinn Emanuel, one deceived user at McDermott, a fake IT help desk at Seyfarth, and unauthorized access at HSF Kramer. Each time the exposed material was client documents

BakerHostetler, which handles breach response for other companies, wrote in its 2026 Data Security Incident Response Report that it responded to more than 30 law firm incidents in 2024 and that the number "nearly doubled" in 2025. "Often the data stolen belongs to the law firm's clients," the report says. The FBI warned in May 2025 that one group, the Silent Ransom Group, had "consistently targeted US-based law firms" since 2023 by posing as the firm's IT department.

These breaches show what is waiting behind the door. AI changes how quickly and convincingly an attacker can reach it.

What makes an attack AI-powered?

Research at scale. Before a fake help-desk call, someone has to learn who works at the firm, who their clients are and which matters are active. In a campaign Anthropic disclosed in November 2025, attackers used its Claude Code tool to inspect target systems and find the highest-value databases, work Anthropic said took "a fraction of the time it would've taken a team of human hackers."

More convincing impersonation. The FBI says criminals use generative AI "to commit fraud on a larger scale which increases the believability of their schemes," including AI-written messages for spear phishing and cloned voices. In May 2025 it reported AI-generated voice messages impersonating senior US officials. A fake IT caller who sounds right and knows the matter names is harder to doubt.

Faster entry and faster processing. In the Anthropic case, AI performed 80 to 90 percent of the campaign and made thousands of requests, often several per second. In September, GreyNoise traced a campaign that used AI agents to compromise at least 440 PaperCut servers at 395 organizations in 48 countries, including 11 organizations in 26 seconds.

A human still runs the campaign. In both cases people chose the targets and made the key calls; Anthropic counted perhaps four to six human decision points per intrusion. AI adds speed, reach and persistence. It does not replace the attacker.

Put those together and a law firm faces a familiar attack running at a new pace: one convincing call, one opened account, and an agent that can find and copy the most valuable client files in minutes.

One trusted account opens a store of complete client files, compared with a file encrypted in the browser and split into six pieces across three providers, where any three rebuild it and one breached provider holds too few

What is Untrace?

The answer is not another lock on the same door. It is changing what exists behind it.

This is the problem Untrace is built to solve. Law firms cannot answer AI-powered attacks by keeping complete client files in the same storage architecture built for yesterday's threats. Untrace is file storage designed for what comes next: no single storage provider ever holds enough to reconstruct a file. The idea goes back to Adi Shamir's 1979 paper How to Share a Secret: split a secret into pieces so that a set number of them rebuild it and fewer cannot.

In the current Untrace architecture, each file is encrypted in the browser before it is stored, then divided into six encrypted shards distributed across three independent providers. Any three shards can reconstruct the file. Fewer than three cannot.

What problems does Untrace solve?

There is no agent access path. Untrace does not issue API keys or agent tokens that open stored files. Rebuilding a file takes the user's passkey, and the passkey asks for the person at the device, by fingerprint, face or PIN. An AI agent has no standing credential it can use to pull complete files out of Untrace.

A breached provider holds fragments, not files. No single provider holds enough shards to reconstruct a file. An AI-powered attacker who compromises one storage provider finds encrypted fragments, not complete contracts, passports, medical records or litigation files. Speed does not help when the complete file was never in one place.

The storage companies cannot read what they hold. Files are encrypted in the browser and part of the key comes from the user's passkey, so the providers storing the shards only ever see encrypted pieces.

One provider going down does not take the files with it. With six shards in the system and any three needed to rebuild a file, files stay available when one provider is offline.

AI changes the attacker. Untrace changes what the attacker finds.


Originally published at untrace.network.

Top comments (0)