New York County Supreme Court buildings at Foley Square in a file photograph
Courthouse context image; it does not depict the Greenberg Traurig litigation. Photo: Wikimedia Commons.

Greenberg Traurig is facing proposed class actions over a cyber breach, Reuters reported on September 21. As of this report, the class-action development is single-sourced to Reuters; court allegations have not been tested and do not establish liability.

What plaintiffs are arguing

Data-breach lawsuits typically claim that an organization failed to use reasonable safeguards, delayed notice or exposed people to continuing identity and privacy risks. The precise merits will depend on the complaints, the affected data, the timeline and the firm’s security practices.

Why this matters

Law firms occupy an unusually sensitive position. Their systems may contain merger plans, litigation strategy, health information, employee records and communications protected by attorney-client privilege. That concentration can make a firm more attractive than any single client.

Historical comparison

Cybersecurity once sat at the edge of professional-services risk management. Repeated attacks on law firms, consultants and vendors have moved it toward the center. Clients increasingly ask outside counsel to meet security standards similar to those imposed on technology suppliers.

Who benefits and who loses

Plaintiffs’ lawyers gain a vehicle to test damages and disclosure duties. Cybersecurity vendors may see increased demand from professional firms. Clients and employees, however, bear uncertainty over how their information may be used. Greenberg Traurig faces legal cost, reputational scrutiny and possible remediation regardless of the eventual verdict.

Critics and uncertainty

Class actions after breaches often struggle to prove concrete injury, causation and damages for every proposed class member. Defendants may argue that a sophisticated criminal act does not itself prove negligent security. Plaintiffs may respond that foreseeable attacks require demonstrable controls and timely notice.

What happens next

Key documents will include the complaints, motions to dismiss, breach notices and any regulator inquiries. Discovery, if the cases proceed, could clarify the data involved and the security timeline. Until then, the careful formulation is that lawsuits allege failures after a reported breach—not that a court has found the firm responsible.

For the wider legal industry, the operational lesson is clear: map sensitive data, minimize retention, segment systems, rehearse response and make vendor access visible. Privilege protects communications in law; it does not encrypt them in practice.

Reporting basis: Reuters, September 21, 2026. This report preserves the single-source caveat and the distinction between allegations and findings.

Back to the front page