Chinese hackers breach US law firms, FBI launches probe: Report

#News Desk
Representative Image | Photo: Canva
Representative Image | Photo: Canva

Washington DC: Prominent US law firm Williams & Connolly has informed clients that Chinese hackers infiltrated parts of its computer systems, as part of a wider campaign by China to target American law firms, The New York Times reported.

According to two people briefed on the matter, the FBI’s Washington field office is investigating the breach and similar attacks carried out by the same group. The hackers are believed to have compromised the networks of more than a dozen law firms and technology companies in recent months.

Those familiar with the investigation spoke on the condition of anonymity, as the matter remains under federal investigation, The New York Times said.

Williams & Connolly — known for representing high-profile figures such as Bill and Hillary Clinton — has told clients that some of its lawyers’ email accounts were breached. However, the firm assured that the hackers are not expected to make the stolen information public or sell it.

“During the incident, a small number of Williams & Connolly attorney email accounts were accessed by leveraging what is known as a zero-day attack,” the firm said in a statement to The New York Times. “Importantly, there is no evidence that confidential client data was extracted from any other part of our IT system, including from databases where client files are stored.”

The firm added, “We have taken steps to block the threat actor, and there is now no evidence of any unauthorised traffic on our network.”

Cybersecurity firm Mandiant reported in September that Chinese hackers had been conducting a years-long espionage campaign exploiting zero-day vulnerabilities to collect intelligence from institutions, including law firms.

“Since March 2025, Mandiant Consulting has responded to intrusions across a range of industry verticals, most notably legal services and software companies,” the firm said in its September report. “Based on evidence from recent investigations, the targeting of the US legal space is primarily to gather information related to US national security and international trade.”

Williams & Connolly has enlisted cybersecurity firm CrowdStrike and law firm Norton Rose Fulbright to manage the fallout. “Based on the firm’s investigation, conducted in conjunction with cyberexperts at CrowdStrike, the threat actor is believed to be affiliated with a nation-state actor responsible for recent attacks on a number of law firms and companies,” the firm stated, according to The New York Times.