Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Mossack Fonseca & Co.

Mossack Fonseca & Co. Vendor Cyber Rating & Cyber Score

mossfon.com

Established in 1977, Mossack Fonseca has become a global leader in the creation of legal structures designed for asset protection, management and control. Over 450 employees worldwide. MISSION To deliver to our global client base, an integrated approach involving legal, fiduciary, investment advisory and digital solutions, of a qualified and reliable nature, through the various business components within the MF group, our worldwide network of offices, a highly skilled staff, our trademark utilization of technology, in order to satisfy client demand by adding value, and at the same time generate returns for our directors, employees and community in general. VISSION To be recognized as THE local and international leader in the


MFC A.I CyberSecurity Scoring

MFC
Company Information
Website:http://www.mossfon.com/
Employees number:109
Number of followers:2,283
NAICS:5411
Industry Type:Legal Services
Homepage:mossfon.com
MFC Risk Score (AI oriented)
Between 650 and 699
logo
MFCLegal Services
Updated:
30/06/2026
664/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MFC Global Score (TPRM)
xxxx
logo
MFCLegal Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MFC
MFCWeak
Current Score
664B (WEAK)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
665Before Incident
JUNE 2026
664Before Incident
MAY 2026
740Before Incident
APRIL 2026
740Before Incident
MARCH 2026
739Before Incident
FEBRUARY 2026
739Before Incident
JANUARY 2026
739Before Incident
DECEMBER 2025
739Before Incident
NOVEMBER 2025
738Before Incident
OCTOBER 2025
738Before Incident
SEPTEMBER 2025
738Before Incident
AUGUST 2025
738Before Incident
JULY 2022
723Before Incident
Breach
22 Jul 2022MFC
Orrick, Herrington & Sutcliffe, Proskauer Rose, Cravath Swaine & Moore, Mossack Fonseca and Weil Gotshal & Manges: Biggest Legal Industry Cyber Attacks

Law Firms Under Siege: A Rising Tide of Cyber Attacks Targets the Legal Industry

530After Incident
CRITICAL-193
ORRWEICRAMOSPRO1782779207
Law Firms Under Siege: A Rising Tide of Cyber Attacks Targets the Legal Industry The legal sector is facing an escalating cybersecurity crisis, with law firms increasingly targeted by sophisticated threat actors. A recent survey by Arctic Wolf and Above the Law revealed that 39% of law firms experienced a security breach in the past year, with 56% of those incidents resulting in the loss of confidential client data a devastating outcome for an industry built on trust and discretion. ### Why Law Firms Are Prime Targets Several factors make law firms particularly vulnerable: - Digital transformation: Firms rely heavily on cloud-based applications and web platforms, expanding their attack surface. - Valuable data: They store vast amounts of sensitive client information, including financial records, PII, and privileged legal documents. - Lack of preparedness: Only 26% of firms consider themselves "very prepared" to respond to cyber incidents. - Resource constraints: Many lack dedicated cybersecurity personnel or struggle to meet evolving compliance standards. - Sophisticated threats: The average ransom demand for legal organizations reached $1 million in 2023, with attackers exploiting weak incident response (IR) plans and third-party vulnerabilities. ### Notable Cyber Attacks on Law Firms #### 1. Orrick, Herrington & Sutcliffe (2023) - Attack type: Data exfiltration (details undisclosed) - Impact: Compromised PII and health data of 637,000 breach victims, leading to multiple class-action lawsuits. - Target: The firm specializes in data breach litigation, making its own client records a high-value target. #### 2. Grubman Shire Meiselas & Sacks (2020) - Attack type: Ransomware (REvil group) - Demand: Initially $21 million, later doubled to $42 million after hackers leaked Lady Gaga’s legal documents. - Outcome: The firm denied paying the ransom, though reports suggest a partial payment of $365,000 was made. #### 3. Proskauer Rose (2023) - Attack type: Data breach via unsecured Microsoft Azure cloud server - Impact: 184,000+ files exposed for six months, including financial deals, NDAs, and acquisition documents. - Response: The firm secured the server and launched an investigation with cybersecurity experts. #### 4. HWL Ebsworth (2023) - Attack type: Ransomware (ALPHV/Blackcat) - Impact: 4TB of data (2.2 million files) stolen, including employee IDs, financial reports, and client documentation. - Aftermath: Hackers leaked 1.45TB of data on the dark web; an Australian court issued an injunction to block access. #### 5. DLA Piper (2017) - Attack type: NotPetya ransomware (originating in Ukraine) - Impact: Global disruption employees lost access to email, phones, and documents. The firm spent 15,000 hours in overtime rebuilding its Windows environment. - Attribution: Linked to Russian state-backed actors. #### 6. Mossack Fonseca (2016) - Attack type: Alleged hack (or insider leak) - Impact: 11.5 million documents (Panama Papers) exposed, revealing tax evasion schemes and shell companies. - Aftermath: Governments recovered $1.2 billion in unpaid taxes; the firm shut down in 2018 amid reputational damage. #### 7. Cravath Swaine & Moore / Weil Gotshal & Manges (2016) - Attack type: Insider trading via malware - Perpetrators: Three Chinese nationals stole confidential M&A data, earning $4 million in illicit profits. - Penalty: The SEC fined them $8.8 million. ### The Broader Impact Cyber attacks on law firms extend beyond financial losses. Breaches erode client trust, disrupt operations (e.g., frozen billing systems), and trigger regulatory scrutiny. Many firms remain silent about incidents due to lack of mandatory disclosure laws, leaving the full scope of the problem unknown. As threat actors refine their tactics from ransomware to phishing and insider threats the legal industry must confront its cybersecurity gaps or risk becoming a persistent target.
INCIDENT DETAILS -
TYPE
Data exfiltrationRansomwareData breachMalware
MOTIVATION
Financial gainData theftInsider tradingReputational damage
IMPACT
$1 million (average ransom demand in 2023)$42 million (Grubman Shire Meiselas & Sacks)$365,000 (partial ransom payment)$1.2 billion (tax recovery post-Panama Papers)$4 million (illicit profits from insider trading)$8.8 million (SEC fine)Confidential client dataPIIHealth dataFinancial recordsLegal documentsNDAsAcquisition documentsEmployee IDsM&A dataCloud-based applicationsEmail systemsPhonesDocument management systemsBilling systems15,000 hours (DLA Piper)Global disruptionFrozen billing systemsLoss of access to critical systemsFirm shutdown (Mossack Fonseca)Class-action lawsuits (Orrick, Herrington & Sutcliffe)Class-action lawsuitsRegulatory finesInjunctions637,000 breach victims (Orrick)2.2 million files exposed (HWL Ebsworth)
DATA BREACH
PIIHealth dataFinancial recordsLegal documentsNDAsAcquisition documentsEmployee IDsM&A data637,000 (Orrick)11.5 million (Panama Papers)2.2 million files (HWL Ebsworth)184,000+ files (Proskauer Rose)High (privileged legal documents, tax evasion schemes, shell companies)Yes (Orrick, HWL Ebsworth, Grubman Shire Meiselas & Sacks)Yes (NotPetya, ALPHV/Blackcat)Legal documentsFinancial dealsNDAsAcquisition documentsEmployee IDsYes (Orrick, HWL Ebsworth)
APRIL 2016
751Before Incident
Data Leak
01 Apr 2016MFC
Mossack Fonseca & Co.

Panama Papers Data Leak

636After Incident
CRITICAL-115
MOS2154271023
The Panama Papers are an enormous collection of legally secret documents that were posted online by the Panamanian legal firm Mossack Fonseca. Over 11.5 million files, including 2.6 Terabytes of data pertaining to the operations of offshore shell firms utilised by the world's most influential individuals, are contained in the firm's full collection. Ramon Fonseca, a co-founder of the Mossack Fonseca law firm, attested to the validity of the leaked documents to Channel 2 in Panama. The International Consortium of Investigative Journalists (ICIJ) and an unnamed source turned over the Panama Papers documents to the German publication Suddeutsche Zeitung.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 11.5 million files, including 2.6 Terabytes of data
DATA BREACH
Type Of Data Compromised: Legally secret documentsNumber Of Records Exposed: 11.5 million filesSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MFC ?
?
What was MFC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MFC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MFC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MFC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MFC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MFC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MFC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MFC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MFC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was MFC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was MFC's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on MFC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MFC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MFC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?