US law firm Katten said it recently identified and contained a limited cybersecurity incident involving an unauthorised third party that had targeted organisations within the legal industry.
According to the firm, an investigation conducted with the assistance of external cybersecurity experts found that the individuals involved did not gain access to Katten’s systems or network.
However, a limited number of files were obtained through a social engineering incident, including a “very small number” of files containing client information, the firm said.
Katten said it promptly notified law enforcement after identifying the incident and is communicating directly with affected clients, as appropriate.
“The security of our systems and the confidentiality and privacy of client information remain our highest priority,” firm said in a statement.
The firm did not disclose further details on the nature of the social engineering incident, the number of files accessed or the identities of the affected clients.
The incident highlights the growing cybersecurity risks faced by law firms, which hold sensitive client, transactional and legal information and are increasingly targeted through social engineering and other forms of cyber-enabled attacks.


