Legal
Overview
Cyber attacks and data security vulnerabilities are frequently in the headlines, to the point that users have become desensitized to the subject. If a lawyer’s or a client’s personal information is on the internet, it is more than probable that it has been accessed by someone, somewhere. This is why it is extremely important that law firms prioritize cybersecurity.
Data breaches in law firms have dominated the news over the past few years. DLA Piper, a worldwide law company, suffered a data breach in late June 2017 that forced the firm to shut down its digital activities around the globe. This was followed by another event that made headlines in 2016 when Mossack Fonseca, a Panamanian legal company, suffered a data breach in which more than 2.6 TB of data and 11.5 million sensitive files were stolen. The theft went completely undetected by the firm.
Legal emails often make the recipient feel rushed or even induce panic, which is why cybercriminals frequently impersonate lawyers or law companies by spoofing their email addresses and domains. To a legal service, it becomes critical that documents and sensitive client information are handled with great care. A phishing email that appears to come from your firm and uses your company’s email domain might undermine your client’s confidence, as well as result in financial loss or privacy violations.
As more consumers use legal services and work with law firms, cybersecurity experts warn that law companies will need to fully embrace Domain-based Message Authentication, Reporting, and Conformance (DMARC) protocol in the future. DMARC provides an additional layer of defence that prevents supply chain attacks as fraudsters would be forced to use an email address that differs somewhat from the original domain, making it easier for supply chain workers to see a red signal.
To read more about Domain-based Message Authentication, Reporting, and Conformance, head over to What is DMARC?

Legal sector biggest cyber breaches
- According to a press release, a cybercriminal using the alias ‘Oleras’ allegedly targeted 50 law firms in 2016 in order to steal private information and allow insider trading. The hacker attempted to recruit accomplices through the criminal underworld to aid him in breaching law firms’ defences.
- Another news article revealed that in 2017 Jenner & Block mistakenly transferred employee W-2 documents to an unauthorized recipient in response to a seemingly genuine request. The phishing attack resulted in the unintended release of personal information, such as Social Security Numbers and wages of 859 people.
- In 2016, two law companies were targeted by malware known as GozNym, which hackers used to collect banking login and password information. They used a phishing email to trick law firm employees into revealing their banking information. The email routed the recipient to online sites that looked exactly like their bank’s website. This attack cost the firm $117,000.
- Appleby, a Bermuda-based offshore law business, was the victim of a cyberattack in 2016. The ICIJ became interested in the hack in 2017, which led to news about the attack. The legal firm’s breached records, dubbed the Paradise Papers, included 13.4 million files. The records were evaluated by 96 media companies and 381 journalists according to The Guardian.

Legal Sector DMARC Adoption
250ok, a leading provider of advanced email analytics for DMARC, deliverability, design, and engagement, published the DMARC adoption of the top 100 law firms:
- With 38% of domains adopting at least a none policy, this is the highest level of adoption in our series of DMARC Adoption Reports. This is much higher than the SaaS 1000 (35%) and significantly better than major US and EU merchants (15.8%), US colleges and universities (11.2%), and top Chinese companies (4.6 per cent).
- Only 5% of domains use a policy that is more stringent than the none policy.
- Only 3% of the domains examined had a reject policy, which is the gold standard of DMARC.

How Can EmailAuth Help?
EmailAuth, through DMARC’s implementation, gives companies and organizations guaranteed security and complete control of their email domains. However, it has other advantages too, and you can read more about them in detail here.
EmailAuth also provides a free DMARC Record Checker to display your record, test it, and verify its validity. For a DMARC record check, all you need to do is provide your domain name. The tool will then analyze and display your record along with other important information.
Similarly, you can verify your DKIM and SPF records using EmailAuth’s free and automated tools:
If you do not have a DMARC record published for your domain and wish to publish one, you can use EmailAuth’s DMARC Record Generator to generate a record instantly. It completely automates the setup process for DMARC, making it easier to choose who is allowed to send emails on your domain’s behalf and keep track of your domain’s enforcement policies.