The Law Firm Hired the Forensic Team. That Does Not Make the Report Privileged.
A law firm hit by a cyberattack occupies two chairs at once. It is counsel to clients whose information may be at risk. It is also the incident victim, the regulated data holder, the insured, and a potential defendant. The forensic investigation has to serve several of those roles. That is exactly why routing the work through a lawyer does not automatically protect the resulting report from discovery.
The lawsuits turn an internal response into an evidence question
Reuters reported on September 21 that Greenberg Traurig faces proposed class actions in the Southern District of New York arising from a cyber incident. The complaints allege that personal information was compromised and that the firm did not provide adequate or timely notice. Greenberg Traurig had not appeared in the cases when Reuters published its report. The allegations have not been adjudicated, and filing a complaint does not establish negligence, causation, damages, or the scope of any disclosure.
The known public account is narrower. On September 10, Reuters reported that Greenberg Traurig said an unauthorized actor accessed a limited number of documents and posted some data on the dark web. The firm said a small number of clients were affected, that its systems remained secure and operational, and that it was notifying people as appropriate. Reuters also reported that a Vermont regulatory notice identified Social Security numbers as one category of exposed information. Those are attributed statements and notices, not a complete reconstruction of the incident.
Once litigation begins, the reconstruction matters. Plaintiffs may seek timelines, forensic findings, remediation recommendations, notice decisions, and information about which systems or records were involved. The firm may have sound reasons to obtain legal advice immediately. But the factual inquiry still has a business and professional purpose independent of litigation: stop the intrusion, understand the exposure, protect ongoing matters, communicate accurately, and decide what must change.
Clark Hill tried a separate legal track. The record did not support it.
The most instructive published decision involves another law firm. In Guo Wengui v. Clark Hill, a former client sought a forensic report concerning a 2017 attack that allegedly led to publication of his confidential information. Clark Hill's outside counsel had retained Duff & Phelps two days after the attack began. The engagement documents described litigation preparation, and the firm argued that its regular cybersecurity provider handled business continuity on a separate track.
Judge James Boasberg compelled production in January 2021. The opinion did not hold that forensic work can never be protected. It held that Clark Hill had not carried its burden on the record before the court. The purported ordinary-course track did not produce an equivalent investigation. Clark Hill's own interrogatory answers said its understanding of the incident came solely from outside counsel and counsel's consultants. The Duff & Phelps report investigated how the attack happened, what information was taken, and how security should be improved. It was shared with members of leadership and IT and used for non-litigation purposes.
That combination mattered more than the engagement-letter vocabulary. Work-product protection applies to material prepared because of litigation, not to an ordinary factual investigation made undiscoverable by inserting counsel between the company and the investigator. Attorney-client privilege can extend to a consultant who helps counsel translate or understand client information, but the court found that Clark Hill primarily sought the consultant's cybersecurity expertise. The report supplied facts and remediation advice, not merely assistance in delivering legal advice.
Capital One shows why preexisting work cannot be relabeled after the breach
The Clark Hill court relied in part on the 2020 Capital One breach litigation. Capital One had a preexisting relationship with Mandiant for incident-response services. After discovering the breach, outside counsel entered a letter agreement under which Mandiant performed substantially the same services and delivered its report to counsel. The court still ordered production, concluding that Capital One had not shown the report would have been materially different without anticipated litigation.
Several operational details supported that conclusion. The scope resembled the earlier statement of work. The expense was initially treated as business-critical. The report was used for business and regulatory purposes and distributed beyond the small group advising on litigation. The district judge affirmed the magistrate judge's order. Again, the rule was not that a familiar vendor defeats privilege. The problem was functional continuity: work the company already expected to perform did not acquire protection merely because counsel became the formal channel.
The two cases expose a common mistake. Organizations sometimes treat privilege as a routing protocol. Have outside counsel send the email, place a legal label on the engagement, and deliver the report first to counsel. Those facts may support protection when they reflect the work's actual legal purpose. They are weak when the same report answers the same operational questions, reaches the same decision-makers, and drives the same remediation that the organization would have needed anyway.
The firm still needs an ordinary-course factual record
A defensive reaction to these decisions would be to avoid a written report or to keep technical findings away from the people responsible for repair. That confuses protection with performance. ABA Formal Opinion 483 says a lawyer confronting a breach involving client information should make reasonable efforts to stop it, restore operations, determine what occurred, evaluate what data was lost or accessed, and communicate accurately when the governing duties require it. Jurisdictional rules and applicable notification statutes control, but none of that work can be done well through cultivated ignorance.
The better distinction is between facts needed to run the response and legal advice about the consequences of those facts. An ordinary-course investigation can establish entry point, persistence, affected systems, exfiltration indicators, exposed data, containment, and remediation. Counsel can separately analyze notification law, professional obligations, litigation exposure, insurance, contracts, preservation, and communications. Some materials may combine those functions. A court will examine the reality, not the folder name.
Separate workstreams can be legitimate, but duplication alone proves little. They need distinct questions, deliverables, personnel, audiences, and uses. If the so-called legal report becomes the only complete incident account and supplies the remediation plan to IT, Clark Hill illustrates why a court may reject the separation. If legal analysis is distributed broadly as an operational memo, circulation may likewise undermine the claim that confidentiality was maintained for legal advice.
Independence matters when the law firm is also the client
The breached firm cannot assume that the people who usually advise clients can simply perform every role for their own institution. Management needs immediate technical facts. Current clients may need candid information about their matters. Insurers and regulators may have separate requirements. Litigation counsel must preserve evidence and defend claims. Firm lawyers may become witnesses. A single reporting line can create conflicts in purpose even before anyone reaches a conflict-of-interest analysis.
Outside breach counsel can help identify the roles, preserve legal analysis, and challenge comfortable internal assumptions. Independent forensic experts can test the firm's systems and timeline. Neither engagement should be sold internally as a privilege machine. The practical question is whether the structure produces reliable facts for operational decisions and confidential legal advice for the people authorized to receive it.
The Greenberg Traurig cases may settle, be dismissed, proceed to discovery, or develop facts that alter the public account. Nothing in the filed complaints establishes how the firm organized its investigation or whether any particular document is protected. The present lesson is broader and already supported by published decisions: a law firm cannot turn an investigation into work product by hiring the investigator through another law firm. Privilege is a consequence of purpose, content, and use. It is not the first line of an invoice.
This article analyzes public reporting, allegations in pending litigation, a published discovery opinion, and ABA guidance. It does not provide individualized legal or incident-response advice, and it reaches no conclusion about Greenberg Traurig's liability or privilege claims.
Sources and further reading
Primary and industry sources used to support this page. External guidance should be reviewed in context and for your jurisdiction.
- Reuters, Greenberg Traurig faces class actions after cyber breachPublished September 21, 2026. Source for the newly filed proposed class actions and their unadjudicated allegations.
- Reuters, Greenberg Traurig says limited data posted on dark webPublished September 10, 2026. Source for the firm's attributed statements and the reported Vermont notice.
- Guo Wengui v. Clark Hill, PLC, 338 F.R.D. 7D.D.C. January 12, 2021. Published memorandum opinion compelling production of forensic materials on the specific record before the court.
- In re Capital One Consumer Data Security Breach LitigationE.D. Va. May 26, 2020. Memorandum opinion ordering production of the Mandiant report; the order was affirmed June 25, 2020.
- ABA Formal Opinion 483Issued October 17, 2018. Model Rules guidance on lawyers' post-breach duties; controlling jurisdictional law and rules may differ.