Your Law Firm Is a Target, and Privilege Doesn’t Protect a Server

Law firms hold exactly the kind of data ransomware groups want most: sensitive, long-lived, and high-leverage for extortion. Recent incidents involving Australian firms (from the April 2023 HWL Ebsworth intrusion, where the ALPHV/BlackCat group claimed to have exfiltrated four terabytes of material including files belonging to government clients, to the February 2025 attack on Sydney firm Brydens Lawyers, reported at around 600GB of client, case, and staff data) are a reminder that legal professional privilege protects a communication in court, not a server from an attacker.

It’s tempting for legal practices to think of themselves as too small or a lower-value target than banks or health insurers. The data says otherwise. The OAIC recorded 1,205 notifiable data breaches in 2025 (an 8% increase on 2024 and the highest annual total since the scheme commenced in 2018), with legal, accounting and management services among the most-affected sectors, at 81 notifications. Client files, trust account records, and privileged correspondence are exactly the material that makes a firm an attractive ransomware target, and the profession has already had its own headline incidents.

Why Firms Are Attractive Targets

A single matter file can contain identity documents, financial records, trust and estate details, and commercially sensitive information about a client’s business, often for multiple parties to a transaction at once. That concentration of sensitive, long-lived data is precisely what makes exfiltration valuable to a ransomware group, independent of whether the ransom itself is ever paid.

It is also why parts of the profession are now targeted by design rather than opportunistically. The Silent Ransom Group has focused consistently on law firms since 2023, and the April 2026 phishing compromise at Jones Day (a global firm with a Sydney office) reached client files through a single phishing email: the firm confirmed that “an unauthorised third party accessed a limited number of dated files for 10 clients”. Closer to home, Queensland practice Kelly Legal was listed on the INC Ransom leak site in November 2025, with the group claiming more than 447GB of data including contracts, financial and customer records, and HR files. Once material is exfiltrated, it cannot be recalled by any privilege claim.

The pressure we see most often arrives second-hand. A defence or government-contracting client is required to flow security obligations down its supply chain, and the questionnaire that lands on external counsel’s desk asks about MFA coverage, backup isolation and incident response testing. Firms that have never been asked these questions by a client are increasingly being asked by that client’s prime contractor, and a credible answer is becoming a condition of continuing to act.

The Privilege Misconception

Legal professional privilege governs whether a communication can be compelled to be disclosed in litigation or regulatory proceedings. It has no bearing on whether an attacker can access, copy, or publish that same communication after a network intrusion. Firms sometimes conflate the two, and it leads to under-investment in the security side of the equation.

The obligations that do bite sit elsewhere. APP 11 of the Privacy Act 1988 (Cth) requires reasonable steps to protect personal information, and the Notifiable Data Breaches scheme requires a firm to assess a suspected breach and, where the serious harm threshold is met, notify the OAIC and affected individuals. The duty of confidentiality under the Australian Solicitors’ Conduct Rules runs alongside that and is not discharged by a privilege claim. The ransomware payment reporting regime introduced under the Cyber Security Act 2024 (Cth) adds a further layer for entities with annual turnover of $3 million or more: a payment must be reported to the Australian Signals Directorate within 72 hours, with enforcement active from January 2026. A decision to pay and a decision to notify now run in parallel, on different clocks.

In practice, the privilege misconception rarely travels alone. The version I hear most often from firms is that because they have a CRM or an outsourced managed service provider, they are safe, that security is something the vendor does. It isn’t. A managed service provider maintains infrastructure to whatever scope its contract specifies; it does not assume the firm’s obligations under APP 11, it does not make the serious harm assessment, and it does not sign the notification to the OAIC. The provider is also an access path in its own right, and the Jones Day compromise began with a phishing email rather than a technical exploit. Any firm relying on this answer should be able to point to the clause that says what its provider is actually responsible for, and name who owns everything the clause leaves out.

What a Firm-Appropriate Baseline Looks Like

  • A documented security baseline appropriate to the sensitivity of client data held, not a generic small-business template. At a minimum: enforced multi-factor authentication on email, remote access and the practice management system; backups that are offline or immutable and have actually been restored in a test; and patching timeframes the firm can evidence.
  • A tested incident response and breach notification plan that names who assesses the serious harm threshold, who signs the OAIC notification, and who authorises (or refuses) a ransom payment, with a partner accountable for activating it.
  • Staff training that reflects how firms are actually targeted: credential phishing against webmail, settlement and invoice redirection, and social engineering aimed at trust account transfers, paired with a verified callback rule for any change to payment details, applied without exception.
  • A retention and deletion practice for closed matters, tested against the firm’s actual file stores.
  • Due diligence on the third parties holding client data on the firm’s behalf: cloud practice management, e-discovery and review platforms, transcription providers, and file-sharing with counsel and experts. A vendor breach is still the firm’s notification obligation.
  • Board or partnership-level ownership of security posture, reviewed on a schedule, not only after an incident.

Standing this baseline up, and keeping it current, is where a fractional general counsel arrangement earns its place, building breach response and board-level decision-making into the practice rather than assembling them mid-incident.

Related reading: AML: The Other Half of the Job. A Legal Roadmap for Newly Regulated Firms · What “Reasonable Steps” Actually Means: The Qantas Lesson for Every Board

Disclaimer

This article is general information only and is not legal advice. It references publicly reported cyber incidents involving law firms, including claims made by threat actors that the affected firms have not necessarily confirmed, and does not comment on any specific firm’s circumstances or compliance position. Obtain advice specific to your practice before acting.

Source: Office of the Australian Information Commissioner, Notifiable Data Breaches Report: July to December 2024, https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-july-to-december-2024.

Share :

About the author

Kirsten Dilena

Kirsten Dilena is the founder and principal lawyer at DLC Legal, a boutique commercial and regulatory practice advising on governance, compliance, cybersecurity and data privacy law, and government procurement. With 20+ years of legal experience across government, defence, and commercial and emerging technology sectors, Kirsten helps regulated businesses build compliance architecture that is proportionate, defensible, and workable.