Hogan Lovells Cadwalader Data Breach Exposes Confidential Client and Legal Files

Published: 28 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

Hogan Lovells Cadwalader, formed from the 2022 merger of Cadwalader, Wickersham & Taft and Hogan Lovells, was reportedly targeted twice by the Silent Ransom Group after refusing to pay a ransom. The firm has not publicly confirmed the incident. Affected clients and individuals should monitor credit reports, watch for phishing attempts, and consider a credit freeze as a first step.

CompanyHogan Lovells Cadwalader
IndustryOther Commercial
Data Types ExposedClient Names and Contact Information, Confidential Legal Case Files, Corporate Transaction Documents, Financial Records, Employee Personal Information, Internal Firm Communications
People AffectedNot Publicly Disclosed
Attack MethodExtortion/Ransom Attack
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Hogan Lovells Cadwalader Data Breach?

Hogan Lovells Cadwalader, the law firm formed through the 2022 merger of Cadwalader, Wickersham & Taft and Hogan Lovells, has reportedly been targeted twice by a cybercriminal group known as Silent Ransom Group. According to reporting, the group first breached the firm’s systems and later returned for a second attack after the firm would not meet its ransom demand. This pattern of repeat targeting is notable. It suggests attackers believed there was more value to extract even after an initial failed extortion attempt.

Silent Ransom Group has been linked to a wave of attacks against major law firms throughout the year. The group is known for using social engineering and extortion tactics rather than always relying on traditional encryption-based ransomware. In this case, the timeline of the firm’s breach discovery has not been publicly disclosed. However, the reporting indicates the second intrusion followed directly from the firm’s refusal to pay after the first attack.

As of this writing, Hogan Lovells Cadwalader has not publicly confirmed the incident. Because this report stems from claims tied to the attacker group’s own activity, the full scope of any internal investigation or forensic response remains unclear. Readers should treat details about the intrusion as allegations from the threat actor’s side until the firm issues its own statement.

Who was affected?

The population affected by this incident has not been publicly disclosed. Law firms like Hogan Lovells Cadwalader typically hold enormous volumes of sensitive data. This can include information belonging to corporate clients, individual clients, opposing parties, employees, and outside counsel across multiple industries.

Because the firm operates across the United States and internationally, the geographic scope of any exposure could be broad. It is not yet known whether the affected individuals include current clients, former clients, employees, or third parties connected to ongoing legal matters. As a result, anyone who has worked with either legacy firm, Cadwalader or Hogan Lovells, may want to stay alert for further updates.

What Information Was Potentially Exposed?

Specific details about the exact files taken have not been fully confirmed by the firm itself. However, based on the nature of law firm operations and the type of attack reported, the kinds of information typically at risk in incidents like this one can include:

  • Client names and contact information
  • Confidential legal case files and correspondence
  • Corporate transaction and deal documents
  • Financial records tied to client matters
  • Employee personal information
  • Internal firm communications

Because law firms often hold extremely sensitive material tied to mergers, litigation, and financial transactions, exposure of these records could carry serious consequences. For example, corporate clients could see confidential deal terms or trade secrets leaked. This could affect business negotiations or give competitors an unfair advantage.

In addition, individuals whose personal information appears in legal files could face heightened identity theft risk. This is especially true if financial account details, Social Security numbers, or other identifying data were part of the files stored on the firm’s systems. Attackers who specialize in extortion often threaten to publish or sell stolen files if payment demands are not met, which increases the urgency for potentially affected individuals to stay informed.

What is the company doing?

Hogan Lovells Cadwalader has not publicly confirmed this incident as of this writing. Because the available reporting centers on claims connected to the attacker group, there is no confirmed statement from the firm describing an internal investigation, remediation steps, or a notification timeline.

As a result, it is not currently known whether the firm has engaged outside forensic experts, notified affected clients, or begun offering any protective services such as credit monitoring. If the firm issues a public statement or begins notifying affected individuals, that information would typically follow standard breach notification practices used across the legal industry. Readers should watch for official communications directly from the firm rather than relying solely on outside reporting.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who has worked with Hogan Lovells Cadwalader, or with either legacy firm, should consider checking their credit reports regularly. This is a simple, free step that can reveal early signs of fraud. You can request free reports from each of the three major credit bureaus through the official annual credit report system.

Because identity thieves sometimes wait months before using stolen information, ongoing monitoring matters more than a single check. If you notice unfamiliar accounts or inquiries, report them immediately. Early detection often limits the damage from fraudulent activity.

Consider a Fraud Alert or Credit Freeze

If you believe your financial or identifying information may have been part of this incident, placing a fraud alert on your credit file is a strong precaution. A fraud alert requires lenders to take extra steps to verify your identity before opening new credit in your name.

For even stronger protection, you can request a credit freeze with each bureau. This makes it much harder for anyone to open new accounts using your information. While a freeze takes a bit more effort to lift when you need credit yourself, it offers one of the most effective defenses against identity theft.

Watch for Phishing and Social Engineering Attempts

Because Silent Ransom Group is known for using social engineering tactics, affected individuals should be especially cautious of unexpected phone calls, emails, or messages claiming to be from the firm or related parties. Attackers often use stolen information to make scam attempts feel convincing.

Therefore, never click links or share personal details in response to unsolicited messages. Instead, verify any communication by contacting the firm directly through a known, official phone number or website. This simple habit can prevent a data breach from turning into a direct financial loss.

Safeguard Sensitive Legal and Financial Documents

If you were involved in a legal matter handled by either firm, consider reviewing any correspondence or documents you may have shared. This can help you understand what type of information might be at risk in your specific case.

In addition, it may help to speak with a data breach attorney about your options. An attorney can help you understand whether you may be eligible for compensation and what steps make sense based on your specific situation. Many offer free consultations to evaluate potential claims.

Stay Alert for Official Notifications

Because the firm has not yet confirmed details publicly, it is important to watch for any official notification letters or public statements. These communications typically explain what data was involved and what protections, if any, are being offered.

Until then, treat unsolicited requests for personal information with skepticism. If you receive a notification letter, keep a copy for your records. This documentation can be useful if you decide to pursue legal action later.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →