
IBM’s recent Cost of a Data Breach Report ought to be a wake-up call for legal. Not just for the raw numbers but for the conclusion that “frontier AI models have radically shifted the cybersecurity threat landscape.” And that hits home hard for legal even if the legal market was not specifically studied.
The underlying research for the report was done by Ponemon Institute. That in and of itself is important because Ponemon isn’t selling a product. It’s an independent research outfit devoted to information and privacy management. So unlike many surveys that are conducted by vendors, there is less likelihood of a bias that pushes the need to buy something. For this particular survey, Ponemon studied 602 businesses in 17 industries and 16 countries.
The Raw Numbers
The raw numbers themselves are startling:
- The average cost of a data breach last year was almost $5 million, up 12% from the year before.
- There was a 56% increase in AI generated cybersecurity attacks.
- Ninety-two percent of the organizations that reported an AI related data breach lacked proper AI controls.
The report concludes simply that AI-driven attacks are getting faster and cheaper to launch, and the resulting breaches are getting more expansive to find and then fix.
So Why Is This Important For Legal?
So data breaches are costing more to fix. What’s new about that; the study didn’t even examine the legal industry. But there is an old and accurate saying, when it comes to data breaches, there are two kinds of firms: those that have been breached and those that don’t know they have been breached.
The number of law firms that have reported data breaches continues to grow and includes some of the largest in the country. Large firms that you would think are pretty sophisticated when it comes to cybersecurity. Firms like Herbert Smith Freehills Kramer (2,700 lawyers), Mayer Brown (1,800 lawyers), and Goodwin Procter (also about 1,800 lawyers). All were recently reported to have been breached. Others include Fox Rothschild, Taft Stettinius & Hollister, and Wiley Rein.
Of those, the rumor is that three paid approximately $50 million in ransom as a result of the breaches. And that’s not to mention the cost of finding and fixing the breach, the damage to reputation, and the potential loss of clients and lawsuits. Clearly, law firms are just as much a target and their losses just as great if not more so, than the industries surveyed by Ponemon and IBM.
But Wait, There’s More
Other aspects of the report could spell trouble for law firms. According to the report, breaches of healthcare organizations remain the most expensive for the thirteenth consecutive year. Why? Because these organizations house significant amounts of personally identifiable information (PII) which attackers value. Information that can be used for such things as identity theft, insurance fraud, and other financially related crime. PII is the most frequently stolen information, says the report.
And what do law firms have a lot of: the same type of information. Social Security numbers. Medical records. Financial information. Addresses. You name it. Fox Rothschild, for example, reported that this was the exact information stolen from it: Social Security numbers, financial account codes, and credit information. It’s this type of information that fuels ransomware, according to the report. And it was just this type of ransomware attacks law firm face. Not to mention the fact that, in light of its breach, the Wiley Rein firm was recently sued, not by its clients, but by those whose information was compromised.
So clearly law firms are targets. The notion of cybersecurity by obscurity, the idea that law firms have nothing the bad guys want, is long gone, if it was ever viable.
And If That’s Not Enough
And here’s something else: of the breached organizations studied in the survey, 53% didn’t bother to encrypt sensitive data at rest and in motion, leading to it being compromised. And attackers used impersonations (phishing) in the majority of attacks. The email from what appears to be the managing partner or GC asking for money to be wired. Or a call from someone purportedly in the IT department asking for security credentials.
Another gaping hole Ponemon found: data being copied to removable media. Data on the USB stick that’s misplaced turns up 200 days later on the dark web. Believe me, lawyers use removable media tools more than we would like to admit. I know how easy and convenient it is to use things like USB flash drives. And how easy for them to seemingly vanish.
When a breach happens, recovery is difficult and can take years. According to the report, 58% of those surveyed who suffered a breach had not yet recovered. Think about that. And the longer it takes to recover, the more the costs add up. More disruption. An adverse impact on billable hours. It allegedly took Wiley Rein over a year to even discover its breach and over two years to give notice. That’s a lot of down time.
The Elephant In The Room
If all this isn’t enough to keep a managing partner up at night, we now have the specter of AI attacks. “Attackers are using AI as a critical tool … in generating phishing email, scanning code for vulnerabilities and automating attacks at scale,” according to the report. One in four of the organizations experiencing a breach were attacked through AI. Those attacks have gotten so fast and good that keeping up with them is difficult. And those AI attacks increased the cost of the data breach, adding $1 million on average.
But here is the real headline from the report: “Organizations continue to prioritize innovation over security for AI models and applications, which can leave them vulnerable to AI-related breaches.” And this: security incidents involving the so-called shadow use of AI — personnel using unapproved AI — more than doubled year over year, according to the report. Most of the organizations studied lacked governance tools to discover this shadow use.
Quite simply, says the report, “AI adoption is outpacing oversight.” Does all this sound familiar? A recent Blickstein Group Study of COOs in law firms found 69% of the firms surveyed were using both legal-specific and general-AI tools. That would suggest that many firms are allowing use of general-AI tools. That’s scary and shows a lack of governance that could lead to just the sort of breach those in the Ponemon study experienced.
And the 2026 Legal Industry Report from 8am demonstrates that over half of its respondents in a law firm study reported their firm has provided no training on the responsible use of AI. Moreover, while seven in 10 lawyers personally use AI, firm-level adoption is much lower.
Even more importantly, only 9% of those surveyed by 8am said their firm had a written policy that was actually enforced. A 2026 Thomson Reuters Institute report revealed that 52% of those surveyed said their organization still had no generative-AI policy. Leading one commentator to conclude “usage is outpacing structure.”
Houston, We Have a Problem
Putting all this together reveals a perfect storm. You have complacency and disinterest by law firm leaders who often don’t understand cybersecurity and its risks or care all that much. You have an over reliance on cyber insurance and internal staff. And cyberattacks using AI are increasing in speed and vulnerability at an alarming rate.
To top it off, you have lawyers and law firm leadership more interested in the adoption of shiny new AI toys than in providing the guard rails to protect data that attackers are more and more interested in.
The Mayer Brown, Goodwin Procter, and Wiley Rein attacks are just the tip of the coming iceberg. It’s an Apollo moment:
Cybersecurity expert: “Houston, we have a problem.”
Law firm response: “This is Houston. Say again, please.”
Stephen Embry is a lawyer, speaker, blogger, and writer. He publishes TechLaw Crossroads, a blog devoted to the examination of the tension between technology, the law, and the practice of law.