Greenberg Traurig Confirms Data Breach After Client Files Posted to Dark Web

Greenberg Traurig confirmed an unauthorized actor accessed client documents and posted stolen material to the dark web, with Social Security numbers exposed.
Greenberg Traurig logo centered on a dark cybersecurity background with red and silver digital streaks.

Greenberg Traurig has confirmed a data breach after an unauthorized actor accessed a limited number of documents and subsequently published some of the stolen material on the dark web, adding the global law firm to a growing list of legal-sector organizations targeted in cyberattacks.

The firm said the incident affected documents associated with a small number of clients and maintained that its broader systems were not compromised. However, regulatory disclosures show that Social Security numbers were among the personal information exposed.

Greenberg Traurig has not publicly disclosed the total number of people affected or provided a detailed breakdown of the documents obtained by the attacker.

Regulatory filings confirm Social Security number exposure

A filing with the California Attorney General lists Aug. 26, 2026 as the date of the Greenberg Traurig breach, with the incident reported to the state on Sept. 9.

California requires organizations to provide the Attorney General with a sample breach notification when notices are sent to more than 500 California residents, indicating that the incident affected at least hundreds of people in the state.

A separate filing with the Vermont Attorney General provides additional information about the exposed data. Greenberg Traurig reported that 10 Vermont residents were affected and identified Social Security numbers as the category of compromised information.

The filings do not establish the total number of affected individuals nationwide. Greenberg Traurig has offices across the United States and internationally and represents clients across a wide range of industries, making the potential sensitivity of compromised legal documents particularly significant even if the number of affected clients is limited.

Stolen documents appeared on dark web

Greenberg Traurig acknowledged that an unauthorized actor obtained access to a limited number of documents and that some of the material was later posted to the dark web.

The firm characterized the exposure as limited and said only a small number of clients were affected. It also said its systems were not compromised, suggesting the attacker may have obtained access to a narrower collection of information rather than gaining widespread control of the firm’s infrastructure.

Greenberg Traurig has not publicly explained the initial access vector or disclosed whether compromised credentials, phishing, social engineering or another technique was used to obtain the documents.

The publication of stolen material nevertheless moves the incident beyond an unverified extortion claim. Greenberg Traurig’s acknowledgment and the state breach filings independently confirm that unauthorized access occurred and that sensitive information was exposed.

Silent Ransom Group claimed Greenberg Traurig attack

Silent Ransom Group claimed responsibility for the Greenberg Traurig breach after listing the law firm on its data leak site. Greenberg Traurig has not publicly attributed the attack to the group, so its involvement remains unconfirmed.

Silent Ransom Group, also tracked as Luna Moth, Chatty Spider and UNC3753, has drawn particular attention from U.S. authorities because of its focus on law firms and its reliance on social engineering rather than conventional ransomware deployment.

The FBI issued a warning in May specifically addressing Silent Ransom Group activity against law firms. According to the bureau, the group has impersonated IT personnel to convince employees to grant access to systems, including through remote management software.

The group’s operations are primarily focused on data theft and extortion. Instead of necessarily encrypting an organization’s network, attackers attempt to steal valuable information and threaten to publish it unless the victim pays.

The FBI has also warned that the campaign evolved beyond telephone-based social engineering, with individuals associated with the activity reportedly attempting to gain physical access to organizations by impersonating employees or contractors.

Law firms face sustained data theft campaigns

Greenberg Traurig’s breach comes amid mounting cyberattacks against major law firms, which present particularly valuable targets because their systems can contain confidential information belonging to numerous corporate clients.

Depending on a firm’s practice areas, compromised legal data can include litigation records, merger and acquisition documents, financial information, intellectual property, internal investigations and personally identifiable information.

The risk therefore extends beyond the law firm itself. A successful intrusion can potentially expose information belonging to clients that were never directly compromised by the attacker.

Several other major U.S. law firms have disclosed cybersecurity incidents during 2026, while the FBI’s warning about Silent Ransom Group indicates that attackers are deliberately targeting the sector rather than encountering law firms opportunistically.

Greenberg Traurig has not disclosed the total number of people whose information was compromised or publicly confirmed Silent Ransom Group’s claim of responsibility. The firm’s acknowledgment that stolen documents reached the dark web, however, confirms that the incident resulted in actual data exposure rather than an attempted intrusion alone.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site