Your Law Firm’s Network Wasn’t Breached. Could Its Documents Still Reach the Dark Web?
Client documents can be at risk beyond your office network. Learn what law firms should verify about cloud access, sharing links, and account security.
Your Law Firm’s Network Wasn’t Breached. Could Its Documents Still Reach the Dark Web?
Blog post – By Securing Your Law Firm
Start the free Zero-Access Exposure Review™ | See the Law Firm Security Baseline
Your office can be operating normally while a client document is copied, shared, or exposed somewhere else.
What happened
On September 10, Greenberg Traurig told Reuters that an unauthorized actor accessed a limited number of documents and published them on the dark web.
The firm said its “firm systems were not compromised or breached” and that operations continued without disruption. The report does not identify how the documents were accessed or where they were obtained.
That distinction matters. A firm can have no confirmed breach of its office network and still need to investigate how a document reached an unauthorized person.
Your document boundary is larger than your office network
A matter file may begin in a document management system, move through email to co-counsel, and reach a client through a cloud-sharing link. Someone may also download a copy to a laptop.
Those accounts, services, devices, and links form the firm’s data boundary. It may include Microsoft 365, client portals, email archives, vendors, and synced devices.
This is why Microsoft 365 data protection and internet-facing cloud applications deserve leadership attention. Protecting the network is important, but it does not answer who can retrieve, share, or download the files.
Do not confuse visibility with compromise
Three questions keep the review accurate:
- What is visible from outside? A portal, subdomain, or cloud login page may be publicly identifiable.
- What could permit inappropriate access? Weak authentication, excessive permissions, former-user accounts, and broad sharing links require an authorized settings review.
- What evidence shows unauthorized access? Logs, alerts, and forensic findings are needed to establish that conclusion.
A public login page or a weak setting is a reason to verify. Neither, by itself, proves that client documents were accessed.
Five questions for your IT provider
Ask your MSP or internal IT team to walk through one active matter and provide evidence:
- Where are the documents and copies? Include cloud applications, email, outside providers, and downloaded files.
- Who can retrieve or share them? Check staff, former employees, guests, vendors, and links that still work.
- Which accounts require phishing-resistant MFA? Identify exceptions and set a plan to address them.
- What activity triggers an alert? Ask about unusual sign-ins, downloads, and new external sharing.
- How quickly can access be revoked? Confirm who can disable accounts, revoke sessions, and remove links. Revocation cannot retrieve copies already downloaded.
Evidence should include access lists, relevant settings, audit coverage, and the person responsible for responding to alerts. “We have a firewall” or “we use Microsoft 365” does not answer these questions.
How we help
Law Firm Security Baseline
Our Law Firm Security Baseline reviews Microsoft 365 authentication, administrator access, external sharing, and audit logging. You receive a prioritized leadership brief and technical evidence your MSP or IT team can act on.
Free Zero-Access Exposure Review™
Our free Zero-Access Exposure Review™ examines public exposure signals associated with your firm, without passwords or internal access. It cannot inspect private document permissions or determine whether client files were accessed.
The review shows what is observable from outside. The Security Baseline helps verify the controls inside the firm.
Start with evidence, not assumptions
This incident is not proof that a particular access method affected your firm. It is a reminder that document security must follow the data wherever it travels.
Ask your IT provider to map one active matter, verify who can reach each copy, and show the evidence. If the answers are unclear, start with a Free Zero-Access Exposure Review™ or a Law Firm Security Baseline.
