MEDIUMVulnerability
Global

Hogan Lovells Cadwalader hacked by Silent Ransom Group; re-attacked after they wouldn’t pay

·Source: DataBreaches.net

Updated:

Executive Summary

Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG’s recent attacks on Hogan Lovells Cadwalader. Yes, that’s “attacks,” plural. When New York City’s oldest law firm, Cadwalader, Wickersham & Taft, merged with Hogan Lovells in 2022, it combined two powerhouse firms. Yet despite... Sourc

Analysis

Numerous major law firms have fallen prey to the Silent Ransom Group this year. Now DataBreaches provides exclusive details on SRG’s recent attacks on Hogan Lovells Cadwalader. Yes, that’s “attacks,” plural. When New York City’s oldest law firm, Cadwalader, Wickersham & Taft, merged with Hogan Lovells in 2022, it combined two powerhouse firms. Yet despite... Source
Source Attribution

Originally published by DataBreaches.net on Sep 28, 2026.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-105215 — ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in...

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w

CVE-2026-105215
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105209 — ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorizati...

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r

CVE-2026-105209
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105208 — ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with...

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens

CVE-2026-105208
NIST NVD