Major US law firm says hackers broke into attorneys’ emails accounts

Law firm Williams & Connolly on Tuesday said that suspected nation-state hackers recently used a zero-day attack to break into email accounts belonging to a small number of attorneys.

The threat actor involved is believed to be the same one who has recently attacked other law firms and companies, Williams & Connolly said in a statement.

While the firm did not specify which nation-state it believes the hacker is affiliated with, The New York Times reported that sources have said it is China. 

On September 24, Google Threat Intelligence Group and Mandiant reported that suspected “China-nexus threat clusters” have been leading a campaign which exploits zero-day vulnerabilities to target the U.S. legal sector and collect information “related to U.S. national security and international trade.”

The FBI’s Washington Field Office is investigating the incident, the Times reported. The FBI did not respond to a request for comment.

Williams & Connolly, which represents high-profile politicians including Bill and Hillary Clinton, said that it has “taken steps to block the threat actor” and has found no evidence that the attack is ongoing. It has hired cybersecurity company CrowdStrike to assist in its investigation.

The firm emphasized that it does not have evidence that confidential client data was taken from central databases where files are kept.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.

 

Total
0
Shares
Previous Post

Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks

Next Post

China-linked hackers target Asian organizations with Nezha monitoring tool

Related Posts

$50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections

A group of academics from KU Leuven and the University of Birmingham has demonstrated a new vulnerability called Battering RAM to bypass the latest defenses on Intel and AMD cloud processors. "We built a simple, $50 interposer that sits quietly in the memory path, behaving transparently during startup and passing all trust checks," researchers Jesse De Meulemeester, David Oswald, Ingrid
Read More

CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of two sets of malware that were discovered in an unnamed organization's network following the exploitation of security flaws in Ivanti Endpoint Manager Mobile (EPMM). "Each set contains loaders for malicious listeners that enable cyber threat actors to run arbitrary code on the compromised server,"
Read More

FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available

The Sangoma FreePBX Security Team has issued an advisory warning about an actively exploited FreePBX zero-day vulnerability that impacts systems with an administrator control panel (ACP) exposed to the public internet. FreePBX is an open-source private branch exchange (PBX) platform widely used by businesses, call centers, and service providers to manage voice communications. It's built on top
Read More