How do client data breaches actually happen?

Share

Written 4 August 2026 · Last updated 4 August 2026

The word "breach" suggests something dramatic happened. The documented pattern is much duller: nothing gets hacked. Someone logs in, because there was no second factor, or because a sharing link stayed open, or because an account still belonged to a person who left two years ago. One law firm learned it had lost 32GB of client files when the National Crime Agency called. For anyone responsible for client data at a law, accounting, or financial services firm, that dullness is the useful part, because the enforcement record shows exactly which doors were open, and none of them required an attacker with unusual skills to walk through.

This article walks through what that record shows.

Do attackers really hack their way in?

In the documented cases, no. They sign in.

In 2025, the ICO fined DPP Law £60,000 after attackers entered through a single administrator account that had no multi-factor authentication, on a legacy case management system. From that one login, 32GB of client data left the firm. That is the firm the National Crime Agency called.

Three years earlier, Tuckers Solicitors received a £98,000 penalty under Articles 5(1)(f) and 32 of the GDPR after a ransomware attack encrypted 972,191 files on its archive server, including court bundles containing medical records and witness statements. Sixty bundles ended up on the dark web. The ICO's findings centred on two ordinary failures: no multi-factor authentication on remote access, and a critical software patch applied roughly five months after its release.

The pattern is not specific to legal work. The 2023 MOVEit campaign reached hundreds of organisations, professional services and audit firms among them, through a single file transfer tool. And in Lithuania's Registrų centras incident, over 600,000 records were taken using the legitimate credentials of institutions with authorised access. Access that is real but unwatched behaves the same way as access that is stolen. When we built our exposure check, we scored it against these documented control failures rather than hypothetical threats, and the pattern held across every case we reviewed: the entry point was an ordinary door, not a broken wall.

How exposed is your client data? | ZealiD

How exposed is your client data?

Your clients trust you with passports, contracts and financial records, and that trust is the firm's real asset. One weak login, one open sharing link or one forgotten account can expose all of it, and most firms find out months too late. This free 3-minute check shows where your firm stands today: twelve questions, an instant score across access, document handling and compliance, and a clear view of what to fix first.

By ZealiD, an EU Qualified Trust Service Provider listed on the EU Trusted List, audited annually under the same security standards this check draws on.

Why do firms not notice for months?

Because nothing looks wrong. A valid login produces no alarm.

The IBM Cost of a Data Breach Report 2025 puts the mean time to identify and contain a breach at 241 days. DPP Law is the concrete version of that statistic: the firm learned its client files were gone only after the data had already appeared on the dark web.

This is the uncomfortable part for professional services. A firm that does not log access to client documents, review who holds accounts, or watch for unusual download patterns has no mechanism by which it could notice. Detection is not a product you buy after the fact. It is a property of how access is set up in the first place.

We hear a version of the same sentence in conversations with firms: "We know sending documents over email is a risk, but we haven't had a major security incident yet." Given a 241-day average detection window, "yet" is doing more work in that sentence than the speaker intends. Not having noticed an incident and not having had one are different claims, and only firms that log and review access can tell them apart.

Which everyday routes let client data leave a firm?

The enforcement record and our own conversations with law and accounting firms point to the same short list. What is striking is the gap between how partners assume a breach would happen and the mechanism regulators actually documented.

Route What firms tend to assume What the record shows
Logins "We have passwords, we are fine" One admin account without MFA gave attackers 32GB at DPP Law; no MFA on remote access was central to the Tuckers penalty
Email "Attachments are how everyone works" Identity documents and case files sit in inboxes indefinitely, outside any retention schedule, and cannot be recalled once misdirected
Sharing links "The platform is secure" An "anyone with the link" setting is a copy of client data you cannot see, expire or revoke; the tool is rarely the problem, the default setting is
Third-party software "Our vendor handles security" The 2023 MOVEit campaign breached hundreds of organisations, including professional services firms, through one file transfer tool (CISA advisory AA23-158A)
Leavers and closed matters "IT deactivates accounts eventually" Access that outlives the person or the engagement is indistinguishable from an attacker's account once misused

The sharing-link row is not theoretical either. One firm described to us how staff sharing files externally through OneDrive had generated broad "everyone" links back into their own environment, discovered only when someone went looking. Nobody chose that setting. It accumulated.

We have written before about the first row of that table, because email is where the exposure and the compliance problem meet: an attachment proves nothing about who sent or received it, and it stays in inboxes long after the matter closes.

What does GDPR require once you discover a breach?

Article 33 of the GDPR gives you 72 hours from becoming aware of a personal data breach to notify your supervisory authority. Not 72 hours from confirming the details. Awareness starts the clock, which is why firms without a written, rehearsed response plan reliably miss it.

DPP Law took 43 days. The delay became part of the ICO's case, separate from the security failures that caused the breach. This is the practitioner misreading worth correcting: partners often treat notification as something owed once the investigation is complete. The regulation treats late notification as its own contravention, and the enforcement record shows regulators pursuing it that way.

How long should client identity documents be kept?

No longer than the purpose requires. That is the storage limitation principle in Article 5(1)(e) of the GDPR, and in practice it means a defined retention period per document type, actual deletion when the period expires, and clearing identity documents out of inboxes once verification is done. This applies identically whether the documents arrived for a legal matter, an audit engagement, or client onboarding at an advisory firm.

Retention is where breach severity gets decided years in advance. The Tuckers attack hit an archive server; every file kept beyond its purpose was one more file in the encryption count, and among the firm's remediation steps the ICO recorded was automating deletion when retention periods expire. Data you no longer hold cannot be exfiltrated, ransomed, or reported.

What does a breach actually cost a firm?

The fine is usually the smallest line.

The UK legal sector, where incident reporting is centralised, gives the clearest picture of the full cost. The SRA's cybercrime guidance notes that cyberattacks make up 75 per cent of all reported crime in the UK, and that firms attract attackers because they hold both sensitive information and client money, a description that fits accountants and advisers as precisely as it fits solicitors. The SRA's thematic review of 40 firms that reported incidents found more than £4 million stolen across the sample, before counting the costs that appear in no penalty notice: weeks of billable hours lost to recovery, higher professional indemnity premiums, mandatory reporting to the professional regulator alongside the ICO, and the conversation with each affected client about how their identity documents ended up on a criminal marketplace.

For a firm whose product is confidentiality, that last cost compounds. Clients rarely leave over the incident itself. They leave over discovering the firm could not say what was taken, from where, or for how long the door had been open. Identity is the first door attackers try, and it is also the first question clients ask afterwards.

How to find out where your firm stands

You do not need a penetration test to answer the question this article raises. You need honest answers to a handful of operational ones, because the failures regulators documented are visible from inside the firm before any attacker finds them:

  • Does every account that can reach client data require a second factor, including remote and administrator access?
  • Can you list who currently has access to client documents, and would you notice within days if a departed employee's account was used?
  • Do identity documents leave inboxes and get deleted on a schedule, or do they accumulate?
  • If you became aware of a breach this morning, could you notify your regulator within 72 hours with a straight face?

If any answer is uncertain, that uncertainty is the finding. We built a free client data exposure check that turns these questions into a scored twelve-question assessment, three minutes end to end, benchmarked against the enforcement cases above. It comes from our side of the table: as a Qualified Trust Service Provider on the EU Trusted List, ZealiD is audited annually against the same class of access and identity controls these cases turned on, and the audit never asks about firewalls. It asks whether the thing you wrote down is the thing you actually do: who can get in, how you know who they are, and when you last checked.

References

Information Commissioner's Office. "Law firm fined £60,000 following cyber attack." April 2025. ico.org.uk

Law Society of Scotland. "Data protection: Privacy – recent enforcement highlights" (ICO Monetary Penalty Notice to Tuckers Solicitors LLP, 10 March 2022). lawscot.org.uk

General Data Protection Regulation, Regulation (EU) 2016/679, Articles 5(1)(e), 5(1)(f), 32, 33. European Union, 2016. eur-lex.europa.eu

Solicitors Regulation Authority. "The impact of cybercrime." sra.org.uk

Cybersecurity and Infrastructure Security Agency. "#StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability." Advisory AA23-158A, June 2023. cisa.gov

IBM. "Cost of a Data Breach Report 2025." ibm.com