{
  "id": 12689713,
  "title": "AI-Powered Attacks Are Coming for Law Firms' Most Sensitive Files",
  "url": "https://urgent.news/2026/10/07/ai-powered-attacks-are-coming-for-law-firms-most-sensitive-files",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-07T18:56:03.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/untrace/ai-powered-attacks-are-coming-for-law-firms-most-sensitive-files-1bba"
  },
  "original_language": "en",
  "account": "Law firms house sensitive documents that people strive to keep private, such as IDs, financial records, medical data, and legal strategies. Traditionally, these firms have been prime targets for cybercriminals. However, the advent of AI is changing the landscape. Criminals now harness AI to research targets, craft convincing messages, test entry points, and quickly process stolen data. The danger does not stem from AI deciding to attack law firms autonomously; rather, it lies in the enhanced capabilities of human attackers using AI tools.\n\nIn the 2026 data breaches of several major US law firms, including Quinn Emanuel, McDermott Will & Schulte, Seyfarth Shaw, and Herbert Smith Freehills Kramer, social engineering played a significant role. These incidents revealed the lucrative nature of the data attackers pursue. Quinn Emanuel's breach, for instance, involved unauthorized access to stored files via a compromised user account. McDermott Will & Schulte and Seyfarth Shaw experienced breaches facilitated by fake help desk impersonations, resulting in the exposure of sensitive client information, including Social Security numbers and health data.\n\nThe FBI has warned about the Silent Ransom Group, a threat actor consistently targeting US-based law firms since 2023 by posing as the firm's IT department. AI-powered attacks exacerbate the speed and effectiveness of these breaches. AI enables attackers to conduct extensive research at scale, creating highly convincing impersonations, and rapidly gaining unauthorized access. A notable example is Anthropic's case, where AI performed 80 to 90 percent of a cyber campaign, making thousands of requests in seconds.\n\nUntrace offers a solution to mitigate the impact of AI-powered attacks. It employs a unique file storage architecture that splits encrypted files into shards and distributes them across three independent providers. No single provider holds enough shards to reconstruct a file, rendering it inaccessible to AI agents. To access the files, users must provide their passkey, which undergoes biometric authentication, such as fingerprints or facial recognition. This approach eliminates the risk of a single point of failure and ensures that even if an AI agent compromises one storage provider, it cannot reconstruct the complete file.",
  "summary": "If you have ever bought a house, gone through a divorce, settled an injury claim or signed an employment contract, a law firm may hold a copy of your passport, your tax return or your medical records. Law firms keep an extraordinary concentration of the documents people work hardest to protect: government IDs, financial records, health information and the legal strategy behind live cases. That…",
  "key_points": [
    "Law firms store sensitive documents like IDs, financial records, and legal strategies.",
    "AI enhances human attackers' capabilities, enabling faster and more convincing breaches."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}