Brydens Lawyers
Incident posture
Linked entities
- Victim
- Brydens Lawyers
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A prominent Sydney law firm with offices across Sydney and regional NSW suffered a cyberattack resulting in unauthorised access to its servers and the theft of more than 600 gigabytes of data relating to the firm, its clients, ongoing cases, and staff. Foreign actors subsequently used the exfiltrated information to extort a ransom from the organisation. Upon discovering the breach, the firm's principal alerted employees and took digital systems offline while engaging external advisers, legal counsel, and security specialists to investigate the scope and restore IT security. The incident was reported to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, with the firm committing to notify affected individuals and take appropriate remedial steps once investigations concluded.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Brydens Lawyers, one of the largest law firms in New South Wales with offices across Sydney and regional NSW, experienced a significant cyber incident around February 20, 2025, when unauthorised actors gained access to the firm's servers and exfiltrated a large volume of data. According to reporting from the Sydney Morning Herald, the attackers stole more than 600 gigabytes of material relating to the firm, its clients, its cases, and its staff. The breach was described by the firm's principal, Bandeli "Lee" Hagipantelis, in internal communications to employees as a "very significant and potentially damaging security breach of the firm's server and the integrity of our data." The incident took the form of a ransomware-style attack in which foreign threat actors obtained sensitive files and subsequently moved to extort the firm for a ransom in exchange for not publishing or otherwise misusing the stolen data. The exact method of initial intrusion, such as the specific malware family or vulnerability exploited, was not disclosed in the available source material.
The breach was discovered by the firm in late February 2025, less than a week before Hagipantelis issued an alert to employees. On the day of detection, Hagipantelis wrote to staff confirming the discovery of the threat to the integrity of the firm's internal systems, and the firm's digital systems were promptly taken offline as a containment measure. External specialists, including security advisers and lawyers, were engaged to assist with response, investigation, and remediation. The firm's IT security was subsequently hardened, and on February 20, 2025, a public statement was posted on the Brydens Lawyers website and issued via news channels notifying clients and the public of the incident. In that statement, Hagipantelis confirmed that the firm had reported the incident to the Australian Cyber Security Centre and to the Office of the Australian Information Commissioner, the two principal regulatory and security bodies for cyber incidents affecting Australian organisations. The statement also confirmed that the security of the firm's IT system had been restored, indicating that the immediate operational compromise had been addressed even as the broader investigation into the exfiltrated data continued.
The scale of the data taken was substantial, with the Sydney Morning Herald reporting the theft at over 600 gigabytes of confidential documents covering clients, matters, and staff information. This places the Brydens incident within a pattern of large-scale attacks against Australian legal practices that handle reams of highly sensitive and confidential material on behalf of their clients. The attackers, described as foreign actors, did not merely disrupt the firm's operations but obtained files that could implicate the privacy of clients and the integrity of legal matters, raising the prospect of reputational and legal consequences for the firm beyond the immediate ransom demand. The available sources do not detail the specific categories of client or staff data contained within the stolen files, nor do they identify the individuals or entity behind the attack, but the description of foreign actors using the data for extortion aligns the incident with the broader trend of ransomware operations targeting professional services firms. The attacker's communication channel, the ransom amount, and whether any payment was made or refused were not addressed in the available reporting.
In response to the incident, Brydens Lawyers undertook a sequence of containment, investigation, and notification actions consistent with obligations under Australian privacy and cybersecurity frameworks. The firm took its digital systems offline, engaged external security and legal advisers, hardened its IT environment, and reported the matter to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. The public statement committed the firm to completing its investigation, working with relevant parties, and notifying affected individuals as required to provide guidance and support once the scope of impacted information was determined. The firm did not, in the available public statements, identify which clients, matters, or staff had their data taken, nor did it disclose the identity of the threat actors or the ransom demand, indicating that these details were either still under investigation or withheld on legal and operational grounds. The combination of regulatory reporting, third-party specialist engagement, public disclosure, and restoration of IT security formed the core of the firm's documented response in the immediate aftermath of the breach.
The Brydens incident occurred against a backdrop of comparable cyberattacks against law firms in the Australasian region, underscoring that the firm was not an isolated target. Reporting cited a mid-January 2025 ransomware-style breach at the New Zealand firm Bell and Graham, where staff returning from the Christmas break discovered that the firm's server had been compromised, with the firm subsequently issuing a public statement acknowledging the incident and committing to identifying those impacted. Two years prior to the Brydens breach, the Russian-linked group ALPHV/BlackCat claimed responsibility for exfiltrating approximately four terabytes of data from the Australian firm HWL Ebsworth, an incident that ultimately affected more than 60 government departments that had engaged the firm for tender-related work and led the NSW Supreme Court to issue an injunction preventing access to the stolen files. The Brydens data theft, at more than 600 gigabytes, was approximately one seventh the size of the HWL Ebsworth breach but still represented an enormous volume of confidential material, illustrating the persistent attractiveness of large legal practices as targets for financially motivated cyber actors. The available source material ends with the firm's confirmation that its IT security had been restored and that investigations into the scope of the breach were ongoing, with notifications to affected individuals anticipated once those investigations were complete.
Sources
Sources available to members: 2 sources.