Skip to main content

Fake IT team convinces lawyer to hand over sensitive files

The Blank Rome firm faced an incident in which attackers impersonated the IT department and persuaded a lawyer to upload files, exposing personal data of clients and contacts.

CybersecuritySeintec Team2-3 min read
Fake IT team convinces lawyer to hand over sensitive files

News summary

The Blank Rome firm faced an incident in which attackers impersonated the IT department and persuaded a lawyer to upload files, exposing personal data of clients and contacts.

Modern social engineering mimics internal processes. Confirming sensitive requests via a second channel and providing specific training on tech support fraud reduces risk.

Source: Reuters — 27 July 2026

What happened

Law firm Blank Rome suffered an incident in which attackers posed as its own IT department. Through that deception they convinced a lawyer at the firm to upload files to a location controlled by the attackers.

The exposed files included personal data of clients and contacts of the firm. The case is part of a wave of social-engineering attacks against US companies documented by Reuters, in which the entry point was not a technical vulnerability but deceiving a person with legitimate access.

What it teaches any organisation holding client data

A professional firm handles sensitive third-party information — clients, counterparties, other companies' staff — without necessarily being aware of its value to an attacker. Impersonating internal support works because the victim trusts a channel assumed secure by default.

The core lesson is that information security does not rely solely on firewalls or antivirus, but on how unusual requests are verified, especially when they ask to upload, move or share files outside the normal procedure.

What to review

Measures that reduce the risk of this kind of deception:

  • A procedure to verify through a second channel any request from «internal IT» that involves uploading or sharing files.
  • Specific training on tech-support fraud, using real examples rather than generic phishing ones.
  • Restrictions on where sensitive information can be uploaded from corporate devices.
  • Logging and alerting on bulk file uploads to unusual external destinations.

Frequently Asked Questions

How did the attackers get the lawyer to cooperate?
They posed as the firm's own IT department, a channel the victim trusted by default.
What kind of data was exposed?
Personal data of the firm's clients and contacts, as reported as part of this wave of incidents.
How can a small firm avoid this trick?
By requiring that no support request involving file sharing is acted on without verification through a known second channel.

At Seintec we help companies convert these types of technological risks into realistic improvement plans. If you wish to review your situation, contact us and an expert will guide you.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.