VoIP Security for Law Firms: What the 2026 Threat Data Shows banner

VoIP Security for Law Firms: What the 2026 Threat Data Shows

  • Posted on

Provided by Marlin Communications, a Bristol Law Society supporter.

New sector-wide data shows law firms, alongside accountancies, consultancies and engineering practices, are facing the highest volume of cyber attacks of any industry tracked, with phone systems emerging as a specific and growing point of exposure.

Law firms, alongside accountancies, consultancies and engineering practices, generated more cyber attack traffic in the first half of 2026 than any other sector tracked by SonicWall, and a large share of it was aimed squarely at phone systems. VoIP security has moved from a low priority to a measurable risk for firms in this group: 332 million scanning and cracking attempts hit SIP-based phone systems in six months, a scale no other sector saw. That volume sits inside a wider picture of three billion intrusion prevention events and sustained ransomware activity across the sector.

Why the Sector Is Now a Primary Target

Professional services doesn't typically generate the same cyber security headlines as healthcare or financial services, and law firms are no exception. The first half of 2026 suggests that's no longer an accurate picture. Drawing on data from more than one million security sensors, SonicWall recorded three billion intrusion prevention system events against law firms, accountancies, consulting practices and engineering firms between January and June, the largest attack volume of any sector it tracks, not per device, in total.

Four hundred and sixty organisations across the sector were actively detecting ransomware campaigns during the same period, the broadest exposure of any vertical SonicWall monitors. That breadth is the important detail: rather than a small number of high-profile firms absorbing most of the attacks, this is a sustained pattern running across firms of every size, from sole-practitioner consultancies to large regional practices.

Directory traversal attempts, malformed request probes and remote code execution attempts account for 72% of all attack volume in the sector. Two and a half years after Apache Log4j2 was patched, the vulnerability it exposed still generated 107 million hits against professional services systems in the same six-month period. Old gaps are still being exploited at scale, alongside new ones.

Source: SonicWall, 2026 Professional Services Protect Brief

How VoIP Phone Systems Became a New Point of Entry

The clearest sign of how targeted this sector has become is a single statistic: 332 million hits from SIPVicious, a scanning and password-cracking tool built for VoIP systems, in the first half of 2026 alone. Professional services, including law firms, is the only sector where this pattern appears at this scale, not one of several affected industries. That concentration points to a structural weakness specific to how this sector runs its phone systems.

SIPVicious works by scanning wide ranges of internet addresses for phone systems that respond, then testing which extensions can be registered, then attempting to crack the password on those that can. Once an extension is compromised, attackers can route calls to premium-rate numbers at the firm's expense, a scheme that can run up tens of thousands of pounds in a weekend. Where the phone system shares a network with client portals or document management platforms, a compromised extension can also become a route into those systems.

The reason this concentrates so heavily in professional services is structural. These firms typically run distributed phone infrastructure across multiple offices and remote workers, with endpoints that need to be reachable from outside the network by design. What's often missing is the authentication enforcement and network segmentation needed to limit what an attacker can reach once they've found a way in.

Ransomware Is Targeting What Firms Hold, Not Who They Are

Professional services, including law firms, recorded 69.9 million ransomware hits in the first half of 2026, more than any other industry SonicWall tracks. Ten active ransomware families operated against the sector simultaneously: Filecoder alone generated 19.1 million hits across 113 organisations, alongside 11.9 million from Gandcrab and 10.5 million from Ryuk. Ten families running simultaneously against 460 organisations reflects a coordinated, sector-wide campaign rather than a handful of opportunistic hits.

Some of these families are not new. Gandcrab first appeared several years ago, yet it still generated close to 12 million hits against this sector in six months. That persistence says as much about unpatched, unmonitored systems still in production as it does about the ransomware itself.

Client records tied to live legal or financial matters carry a kind of leverage that ordinary personal data doesn't, and privileged correspondence adds another layer on top of it. Ransomware groups understand that leverage translates directly into a firm's willingness to pay, to avoid disclosure or downtime. The sector's ransomware exposure reflects a calculated assessment of what these firms are likely to do under pressure, not a random targeting pattern.

What This Means in Practice

This data doesn't point to a single fix so much as a pattern: a weak point in one system, a phone extension, a portal login, an unpatched server, rarely stays contained to that system alone. The interconnected way these platforms are typically built is exactly what makes a single compromise expensive.

For firms in this sector, the practical question isn't whether an attack will be attempted, the data suggests it already has been. The question is whether your firm's current setup, its phone system, its client-facing portals, its network segmentation, has kept pace with how specifically this sector is now being targeted. Many haven't had reason to ask that question until now.

That gap is rarely visible until it's tested, which is exactly what the attackers in this data set are doing at scale. Waiting for an incident to reveal it is the expensive way to find out.

This data is worth treating as a prompt to check where the gaps in your own systems actually sit, particularly around how your firm's phone system is secured against exactly this kind of targeting.

Marlin Communications is a proud supporter of Bristol Law Society. Find out more about how Marlin works with law firms on phone systems and network security via our supporter profile.