Your Vendor Got Hacked. Now What? — Sovereign Discovery
S|D
Sovereign DiscoveryeDiscovery & Litigation Support
Short on time? Listen to this article below.
Newsletter · Issue 7

Your Vendor Got Hacked. Now What?

Law firms are the fourth most targeted industry for ransomware in 2026. A vendor breach is no longer an if — it is a when. The question is whether your organization is ready to respond.

In September 2025, attackers gained access to DocketWise — a widely used immigration case management platform — through stolen credentials in a data migration pipeline. The breach exposed 116,666 individuals' records, including Social Security numbers, passport data, medical records, and attorney-client case information. The platform did not disclose the breach until April 2026. Seven months elapsed between the initial compromise and notification.

During those seven months, immigration attorneys whose clients' data was exposed had no opportunity to take protective action. Many of those clients were in active removal proceedings — situations where exposed data could have immediate, life-altering consequences. The attorneys did nothing wrong. Their vendor failed them. And the legal, ethical, and client relationship consequences landed anyway.

This is the emerging reality of vendor-side risk in legal technology — and it is arriving at a moment when law firms are already firmly in the crosshairs of cybercriminals.

#4
legal sector ranked by ransomware targeting in early 2026
increase in ransomware incidents against law firms year over year
25%
of law firm breaches involve a third-party vendor
7 mo.
between DocketWise breach and client notification
Breach Timeline · Sept. 2025 – April 2026

The DocketWise Incident: When Your Vendor's Problem Becomes Your Ethical Obligation

DocketWise, used by immigration law firms across the United States, was compromised through a supply chain attack — cloned repositories in a data migration pipeline accessed with stolen credentials. The data exposed included Social Security numbers, passport information, medical records, and attorney-client case materials for 116,666 individuals.

ABA Formal Opinion 483 requires attorneys to monitor their technology vendors' data security controls — an obligation that applies to vendor-side incidents as much as firm-side ones. The New York City Bar's Formal Opinion 2024-3 further clarifies that when a cybersecurity incident occurs, a lawyer must act reasonably and promptly to stop the breach and mitigate damage. With a seven-month notification gap, attorneys had no opportunity to act reasonably. The ethical obligations were triggered without warning, and without the information needed to meet them.

Visual Overview
How a Vendor Breach Reaches Your Clients and Your Practice
ATTACKER Stolen credentials Supply chain entry LEGAL TECH VENDOR Case mgmt platform Data exfiltrated LAW FIRM No breach notification for 7 months CLIENT DATA EXPOSED SSNs, passports, medical records, case files ETHICAL OBLIGATIONS ABA 483 triggered without information to act PRIVILEGE EXPOSURE Attorney-client case data in attacker hands The firm did nothing wrong. The vendor failed. The consequences arrived anyway. Vendor risk is your risk. Your clients' data is only as safe as your weakest vendor. Sources: BakerHostetler 2026 DSIR · ComplexDiscovery · Halcyon Ransomware Research Center · ABA Formal Opinion 483
01

Law Firms Are the Fourth Most Targeted Industry. Vendor Risk Is the Biggest Gap.

According to Halcyon's Ransomware Research Center, the legal sector ranked as the fourth most targeted industry by ransomware actors in the first months of 2026. BakerHostetler's 2026 Annual Data Security Incident Response Report — which draws on data from more than 1,250 incidents — found that ransomware incidents against law firms nearly doubled year over year. And a quarter of all law firm breaches involved a third-party vendor.

What makes this particularly difficult for legal teams is the nature of the data they hold. Law firms are attractive targets precisely because the information in their systems — active case files, privileged communications, deal documents, deposition transcripts, client identity records — is time-sensitive, highly confidential, and involves parties with a strong incentive to pay rather than have it exposed. The 2026 BakerHostetler report found average ransom demands in the legal and professional services sector ranging from $500,000 to $21 million, with the average payout just under $2 million.

The DocketWise incident illustrates a specific and growing risk category: the legal tech vendor that holds client data but whose security controls are not visible to the law firm relying on it. Most firms cannot audit their vendors' infrastructure. Most vendor contracts do not require meaningful security certifications or breach notification timelines. And as the DocketWise timeline demonstrates, seven months can pass before you know there is a problem — seven months during which your clients' data is in the hands of an attacker and your ethical obligations are already running.

Attackers aren't breaking down the front door. They're walking right in because someone clicked a link — or a vendor relationship created a direct way in.

02

Vendor Risk Management Is Now an Ethical Obligation — Not Just a Security Best Practice

ABA Formal Opinion 483 makes clear that attorneys have an obligation to monitor their technology vendors' data security controls. This is not a general aspiration — it is a specific professional responsibility that applies when a vendor holds client data. For most law firms, this obligation is easier to acknowledge than to operationalize.

Most vendor agreements do not require the vendor to maintain specific security certifications, notify the firm within a defined timeframe of a breach, or allow the firm to audit security controls. Most firms do not conduct annual vendor risk assessments or require their eDiscovery, case management, or document review vendors to carry documented security programs. Most firms do not have an incident response plan that accounts for a vendor-side breach — a plan that can be executed before the vendor notifies them.

The gap between what ABA Opinion 483 requires and what most firms have actually built is significant. And in a year when a quarter of law firm breaches involve vendor relationships, closing that gap is no longer optional.

Section 2 · Visual
The Vendor Risk Checklist Most Firms Don't Have
1 Require documented security programs from all legal tech vendors SOC 2 Type II, ISO 27001, or equivalent — not a self-attestation, a third-party certification 2 Negotiate breach notification timelines into vendor contracts 72-hour notification is the floor — the DocketWise 7-month gap is not acceptable by any standard 3 Build a vendor-side incident response plan Know what you will do before the notification arrives — not after Conduct annual vendor risk assessments — not just at onboarding Security posture changes. A vendor that passed in 2024 may not meet the standard in 2026.
03

What Legal Teams Need to Act On

Five Things the DocketWise Incident Makes Clear

  • Vendor risk is your risk. ABA Formal Opinion 483 places the obligation to monitor vendor security on the attorney — not the vendor.
  • A seven-month notification gap is not unusual. The DocketWise timeline reflects how vendor breaches typically unfold. Your incident response plan cannot depend on prompt notification.
  • One in four law firm breaches involves a vendor relationship. Third-party risk is not a secondary concern — it is the primary attack vector for a significant portion of incidents.
  • Privileged communications are the prize. Law firms are targeted because the data they hold is uniquely sensitive and uniquely valuable — to adversaries, to foreign intelligence, and to extortionists.
  • Cyber insurance requirements are tightening. Insurers now require documented vendor risk management programs as a condition of coverage. Firms without them face higher premiums or denied claims.
Industry Perspective — Sovereign Discovery

The DocketWise incident is not primarily a story about one vendor's security failure. It is a story about what happens when the legal industry's vendor oversight practices do not keep pace with its vendor dependency. Law firms have outsourced significant portions of their data management — case files, discovery data, document repositories — to third-party platforms while maintaining the ethical obligation to protect everything those platforms hold.

At Sovereign Discovery, we approach vendor relationships with the same defensibility mindset we bring to discovery workflows. That means understanding what data each vendor holds, what their security posture looks like, and what obligations are triggered if their posture fails. It is not a comfortable conversation to have. But it is a necessary one — and the DocketWise timeline demonstrates what happens when it does not happen at all.

Final Thought

The legal sector will continue to be a high-value target. The data is too sensitive, the deadlines are too real, and the pressure to resolve incidents quietly is too strong for attackers to look elsewhere. What changes is not the threat — it is how prepared your organization is when the threat arrives through a vendor you trusted.

Vendor risk management is no longer a security team issue. It is a legal team issue — and it has been since ABA Formal Opinion 483. The DocketWise incident is the reminder the profession did not want but needed.

Is your vendor risk framework ready for a breach?
Schedule a Consultation