London Daily

Focus on the big picture.
Saturday, Feb 22, 2025

A data breach is exposing Big Law firms who were using a 20-year-old system for handling sensitive documents. Here's what we know so far.

A data breach is exposing Big Law firms who were using a 20-year-old system for handling sensitive documents. Here's what we know so far.

Accellion, a top legal data vendor, was hit by a data breach. Here are firms that could be at risk in the legal industry's latest data security risk.
Leading law firm data vendor Accellion fell victim to a data breach now tied to hacks at least two big customers, the latest in a string of data-security failures that has affected the legal industry in recent years.

Accellion said this month that its aging File Transfer Appliance (FTA) product was compromised. For years, Accellion, which provides file transfer services, has been a top choice among Big Law to share sensitive files that are too big to be emailed, and is used by 35% of the largest law firms.

Accellion FTA is meant to help large companies like law firms securely transfer large and sensitive files through a private cloud system. The 20-year-old platform is being phased out, Accellion said this month, and will not allow renewals after April 30.

The Wall Street Journal on Tuesday reported that Jones Day, which has represented major corporate clients like Alphabet and Goldman Sachs, along with Donald Trump's presidential campaign, was among the firms impacted. The anonymous hacker who posted documents purported to be from Jones Day on the dark web told the Journal that it had accessed Jones Day servers and didn't obtain the information through Accellion, something Jones Day disputed.

"Jones Day's network has not been breached," the firm said in a statement, adding that the incident was still under investigation. "Jones Day has been informed that Accellion's FTA file transfer platform, which is a platform that Jones Day — like many law firms, companies and organization — used was recently compromised and information taken."

Goodwin Procter, another large firm that has used Accellion, experienced a data breach on Jan. 20, Bloomberg Law first reported. When reached by Insider on Wednesday, the firm declined to comment.

In addition to using Accellion, Goodwin Procter also represented an investor in the company in a $120 million financing round last year.

Many law firms have been mentioned in the Accellion's marketing material over the years, but several — including Cozen O'Connor, Seyfarth Shaw, Arent Fox, and Barnes & Thornburg — weren't impacted by the breach, according to statements by the firms or people familiar with the matter.

Rob Dougherty, an Accellion spokesman, told Insider that "the vast majority" of its law-firm clients no longer use FTA and have upgraded to its newer Kiteworks product, but didn't respond to a request for specific numbers.

Kiteworks was launched in 2014. FTA, meanwhile, is nearing the end of its product life, Accellion said in its Feb. 1 statement disclosing what it called a "sophisticated cyberattack."

Accellion has also touted Fragomen Del Rey Bernsen & Lowey; Cahill Gordon & Reindell; Willkie Farr & Gallagher; Squire Patton Boggs; Ropes & Gray; Dentons; Latham & Watkins; Foley & Lardner; and Cadwalader Wickersham & Taft as clients.

Representatives for Cahill, Squire, Ropes, Latham and Cadwalader said they weren't impacted by the breach. A Dentons representative said the firm does not use the DTA system. People at the other firms didn't respond to comment requests.

Law firms and the companies that manage their data have been targeted in privacy attacks in recent years: DLA Piper was hit in a major cybersecurity attack in 2017, in which hackers demanded a mere $300 in bitcoin for the firm to regain access to its computer systems. A 2019 Law.com report estimated that more than 100 Big Law firms have reported data breaches.

Frank Gillman, a law firm information technology consultant with Vertex Advisors, told Insider that he couldn't speak about Accellion specifically, but said software vendors are generally not looking to break the bank when they ask a firm to upgrade.

"Typically, software companies looking to get clients from an older iteration to a newer product line keep the overall price increase to a 10% to 15% range increase, with large incentives for longer subscription periods," he said in an email. "Otherwise, it's difficult to meet budgetary restrictions of the customer."

The responses from law firms and their third-party data storage partners to data breaches have varied. In some cases, hackers have threatened to erase or release files unless they are paid. In a late 2020 breach notification, Cadwalader reportedly told a regulator that one of its vendors was impacted by a ransomware attack and paid to have its systems unencrypted.

The Wall Street Journal reported that the hacker who claimed to have breached Jones Day said the firm hadn't responded to its outreach.
Newsletter

Related Articles

0:00
0:00
Close
Good News: Senate Confirms Kash Patel as FBI Director
Officials from the U.S. and Hungary Engage in Talks on Economic Collaboration and Sanctions Strategy
James Bond Franchise Transitions to Amazon MGM Studios
Technology Giants Ramp Up Lobbying Initiatives Against Strict EU Regulations
Alibaba Exceeds Quarterly Projections Fueled by Growth in Cloud and AI
Tequila Sector Faces Surplus Crisis as Agave Prices Dive Sharply
Residents of Flintshire Mobile Home Park Grapple with Maintenance Issues and Uncertain Future
Ronan Keating Criticizes Irish Justice System Following Fatal Crash Involving His Brother
Gordon Ramsay's Lucky Cat Restaurant Faces Unprecedented Theft
Israeli Family Mourns Loss of Peace Advocate Oded Lifschitz as Body Returned from Gaza
Former UK Defense Chief Calls for Enhanced European Support for Ukraine
Pope Francis Admitted to Hospital in Rome Amid Rising Succession Speculation
Senate Republican Leader Mitch McConnell, at the age of 83, Declares His Retirement.
Whistleblower Reveals Whitehall’s Focus on Kabul Animal Airlift Amid Crisis
Politicians Who Deliberately Lie Could Face Removal from Office in Wales
Scottish Labour Faces Challenges Ahead of 2026 Holyrood Elections
Leftwing Activists Less Likely to Work with Political Rivals, Study Finds
Boris Johnson to Host 'An Evening with Boris Johnson' at Edinburgh's Usher Hall
Planned Change in British Citizenship Rules Faces First Legal Challenge
Northumberland Postal Worker Sentenced for Sexual Assaults During Deliveries
British Journalist Missing in Brazil for 11 Days
Tesco Fixes Website Glitch That Disrupted Online Grocery Orders
Amnesty International Critiques UK's Predictive Policing Practices
Burglar Jailed After Falling into Home-Made Trap in Blyth
Sellafield Nuclear Site Exits Special Measures for Physical Security Amid Ongoing Cybersecurity Concerns
Avian Influenza Impact on Seals in Norfolk: Four Deaths Confirmed
First Arrest Under Scotland's Abortion Clinic Buffer Zone Law Amidst International Controversy
Meghan Markle Rebrands Lifestyle Venture as 'As Ever' Ahead of Netflix Series Launch
Inter-Island Ferry Services Between Guernsey and Jersey Set to Expand
Significant Proportion of Cancer Patients in England and Wales Not Receiving Recommended Treatments
Final Consultation Launched for Vyrnwy Frankton Power Line Project
Drug Misuse Deaths in Scotland Rise by 12% in 2023
Failed £100 Million Cocaine Smuggling Operation in the Scottish Highlands
Central Cee Equals MOBO Awards Record; Bashy and Ayra Starr Among Top Honorees
EastEnders: Four Decades of Challenging Social Norms
Jonathan Bailey Channels 'Succession' in Bold Richard II Performance
Northern Ireland's First Astronaut Engages in Rigorous Spacewalk Training
Former Postman Sentenced for Series of Sexual Offences in Northumberland
Record Surge in Anti-Muslim Hate Crimes Across the UK in 2024
Omagh Bombing Inquiry Concludes Commemorative Hearings with Survivor Testimonies
UK Government Introduces 'Ronan's Law' to Combat Online Knife Sales to Minors
Metal Detectorists Unearth 15th-Century Coin Hoard in Scottish Borders
Woman Charged in 1978 Death of Five-Year-Old Girl in South London
Expanding Sinkhole in Godstone, Surrey, Forces Evacuations and Road Closures
Bangor University Announces Plans to Cut 200 Jobs Amid £15 Million Savings Target
British Journalist Charlotte Peet Reported Missing in Brazil
UK Inflation Rises to 3% in January Amid Higher Food Prices and School Fees
Starmer Defends Zelensky Amidst Trump's 'Dictator' Allegation
Zelensky Calls on World Leaders to Back Peace Efforts in Light of Strains with Trump
UK Prime minister, Mr. Keir Starmer, has stated that any peace agreement aimed at ending the conflict in Ukraine "MUST" include a US security guarantee to deter Russian aggression
×