Cyber criminals are giving corporate litigation departments yet another reason to worry—that organizations could be on the hook for their law firms' data breaches.

Global snack food conglomerate Mondelez found this out the hard way when it was sued over a data breach suffered by its law firm, Bryan Cave Leighton Paisner, in 2023. The plaintiffs, a proposed class of 1,100 current and former Mondelez employees, argued that the company had not properly protected their sensitive data by ensuring that Bryan Cave had "reasonable cybersecurity procedures" in place when intruders accessed its systems in February 2023, "including an area it used to store certain customer files."