That was it. One word. Apple’s rainbow logo wrapped in barbed wire.
The article inside was titled “101 Ways to Save Apple.” Michael Dell told reporters he’d “shut it down and give the money back to the shareholders.” Steve Jobs would later say Apple was 90 days from bankruptcy.
I was writing code on a Macintosh Performa 6200 at the time. Everyone told me I was an idiot. “Apple’s dead.” “Switch to Windows before it’s too late.” “You’ll never find work as a Mac developer.”
Twenty-nine years later, Apple is the most valuable company in the world. And I’m still building software on a Mac.
Why I Never Left
It wasn’t loyalty. It wasn’t stubbornness. It was simple: the Mac let me do better work.
As a developer, I need a machine that gets out of my way. No driver conflicts. No registry corruption. No mystery processes eating my CPU. Just me and my code.
When I built TimeNet Law, I made a deliberate choice: Mac only. Not because I’m lazy. Because after 30+ years of watching attorneys struggle with Windows machines, I knew the truth:
The attorneys who use Macs have fewer problems. Period.
Why Lawyers Should Want a Mac
I’ve spent decades building software for attorneys. Here’s what I’ve learned:
1. Security Isn’t Optional Anymore
Law firms are targets. Client data, case strategies, privileged communications: hackers want all of it. macOS was built on Unix, with security baked into the architecture. It’s not bolted on as an afterthought.
2. It Just Works (Still)
That old Apple slogan? Still true. I don’t spend my days troubleshooting TimeNet Law crashes caused by Windows updates. My users don’t call me because their antivirus flagged legal billing software as malware. The Mac ecosystem is predictable, stable, and professional.
3. Privacy by Design
Apple’s business model is selling hardware, not your data. They’ve built privacy into everything, from on-device processing to app sandboxing. For attorneys handling confidential client information, that matters.
4. Longevity
My users run TimeNet Law on Macs that are 8, 10, even 12 years old. Try that with a Windows laptop. Apple silicon has only made this better. M1 machines from 2020 still feel fast in 2026.
5. The Ecosystem
iPhone, iPad, Mac: they talk to each other seamlessly. Copy on your phone, paste on your Mac. Answer calls from your desktop. AirDrop files in seconds. For attorneys who are always moving, this isn’t convenience. It’s competitive advantage.
“But Macs Are Expensive”
Are they?
Calculate the cost of a Windows laptop over 5 years: the machine itself, the antivirus subscription, the IT support calls, the productivity lost to updates and crashes, the replacement when it dies at year 3.
Now calculate a Mac over 5 years. Or 7. Or 10.
The Mac isn’t expensive. It’s economical, if you think beyond the sticker price.
The Bet I Made in 1997
When everyone said Apple was finished, I kept coding on my Performa. When everyone said “real business software” had to run on Windows, I built TimeNet Law for Mac.
That bet paid off. Not because I got lucky, because I understood something the critics didn’t:
The best tools attract the best users.
Attorneys who choose Macs aren’t making a fashion statement. They’re making a business decision. They want reliability over troubleshooting. Security over crossed fingers. Tools that help them practice law instead of fighting their computers.
That’s who I build software for.
That’s who TimeNet Law is for.
Ready to run your practice on a machine that works as hard as you do?
You chose it because you value thoughtful design. Because you wanted something that works reliably, looks beautiful, and doesn’t fight you every step of the way.
So why would you settle for billing software that treats your Mac like an afterthought?
The “Mac Compatible” Lie
Here’s a dirty secret of legal tech: most “Mac compatible” software isn’t Mac software at all.
It’s Windows software that technically runs on a Mac. Or it’s a web app crammed into an Electron wrapper. Or it’s a browser tab that asks you to pretend it’s a native application.
You can feel the difference immediately:
The lag when you click something and wait for the interface to catch up
The battery drain from running what amounts to a Chrome browser in disguise
The alien interface that looks nothing like the rest of your Mac
The missing shortcuts, no Command-key anything, no proper menu bar, no integration with your workflow
“Mac compatible” is marketing speak for “we didn’t want to lose the sale.”
What Mac-Native Actually Means
True Mac-native software is built from the ground up for macOS. It uses Apple’s frameworks. It respects Apple’s design language. It feels like it belongs on your machine.
Here’s what that looks like in practice:
It’s fast. No Electron bloat. No web rendering. Native code runs at native speed.
It’s familiar. Standard Mac keyboard shortcuts. Proper menu bar. Drag and drop that works like you expect.
It integrates. Works with Spotlight, Time Machine, iCloud, and all the other Mac features you rely on.
It respects your battery. Because it’s not secretly running a web browser, your laptop doesn’t turn into a space heater.
Ransomware encrypted their entire Windows network, including the cloud-synced “backup” that was also connected
A Windows update rebooted mid-trial prep. Goodbye, unsaved work
Blue Screen of Death during a client presentation
The antivirus software decided the billing app was a threat and quarantined it
Mac isn’t immune to problems. But attorneys who chose Mac did so because they wanted fewer of these surprises. Then they install Windows-first software and invite the chaos back in.
What to Look for in Legal Software for Mac
If you’re evaluating billing or time tracking software, here’s your checklist:
✓ Is it actually native?
Ask directly: “Is this built with Apple’s native frameworks, or is it Electron/web-based?” If they hesitate, you have your answer.
✓ Does it work offline?
If the software requires an internet connection to function, it’s not truly yours. It’s a rental.
✓ Where does your data live?
On your Mac? On someone else’s server? Can you back it up yourself, or are you trusting a company that might get acquired next quarter?
✓ How long has it been around?
New software is exciting. Software that’s been stable for 20 years is reliable. When it comes to your billing records, I’ll take reliable.
✓ Who answers the phone?
When something goes wrong, do you get a chatbot? A ticket queue? Or the person who actually built the software?
The Real Cost of Cross-Platform Compromises
“But the features are the same!”
Sure. And a Kia has four wheels and an engine, just like a BMW. The spec sheet doesn’t capture what it feels like to use something every day.
Time adds up.
That extra half-second of lag, multiplied by thousands of interactions per year. That awkward interface that never quite clicks. The workarounds you develop because the software doesn’t work the way your Mac does.
Attorneys bill their time in six-minute increments because every minute matters. But somehow they accept software that wastes their time by design.
You Chose Your Platform. Own It.
When you bought a Mac, you made a statement about the tools you want to use. You chose quality over lowest-common-denominator. You chose an ecosystem that values user experience.
Don’t accept “Mac compatible” when you can have Mac-native.
Don’t accept cloud-dependent when you can have local-first.
Don’t accept software that fights your workflow when you can have software that enhances it.
TimeNet Law: Built for Mac, By Someone Who Gets It
I started building TimeNet Law in 2003 because Mac-using attorneys had been abandoned by the industry. Twenty-two years later, I’m still here, still building native Mac software, still answering my own support line, still obsessing over the details that make software feel right.
P.S. If you’re currently using Windows-first software on your Mac and it’s driving you crazy, I wrote a guide on switching. Your sanity is worth more than switching costs.
What I found should concern every attorney who takes client confidentiality seriously.
What’s Actually in Their Privacy Policy
Let’s start with the quote that matters most:
“Information submitted to our AI-powered tools… may include Sensitive Personal Information, including information relating to the cases or financial information of our Customers’ clients.”
Your client’s secrets. Their case details. Their financial information. All flowing through third-party AI systems.
That’s not speculation. That’s their own disclosure.
It Gets Worse
Cross-context behavioral advertising. MyCase shares your data with advertising partners who track you across every website you visit. Your billing software is following you around the internet.
Psychological profiling. They build “inferences” about you including preferences, characteristics, behavior, attitudes, and aptitudes. For “advertising purposes.”
Medical information. Their privacy policy explicitly mentions collecting health records. Why does billing software need your medical history?
The minors admission. From their California disclosure: “We do not have actual knowledge that we have sold or shared the personal information of children under the age of 16.”
Read that carefully. They’re not saying they don’t sell data. They’re saying they don’t know if any of it belongs to minors.
The Attorney-Client Privilege Problem
Here’s the question every MyCase user should ask: Can you look your client in the eye and tell them their case details are being fed to AI models and shared with advertising partners?
California Bar ethics opinions are clear that attorneys must take reasonable steps to protect client confidentiality when using technology. “We didn’t read the privacy policy” isn’t a defense.
This isn’t just a California problem. State bar associations across the country are rolling out updated guidance on technology competence and data handling. The message is consistent: you have an affirmative duty to understand what your software does with client information.
ABA Model Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure of client data. Reasonable efforts. If your practice management software is routing client details through third-party AI models and sharing data with advertising networks, and you knew about it (or should have known, because it was disclosed in the privacy policy you agreed to), that is a potential failure of your ethical duty.
This isn’t theoretical anymore. Ethics complaints related to technology negligence are on the rise. Bar disciplinary boards are scrutinizing how attorneys handle digital client data. The question isn’t whether you use technology. Every attorney does. The question is whether you chose technology that protects your clients or technology that profits from them. I’ve watched firms scramble after a complaint gets filed. Don’t wait for that to be you.
There’s Another Way
TimeNet Law exists because this doesn’t have to be the trade-off.
Your data never leaves your machine. Not to our servers. Not to AI models. Not to “advertising partners.” It stays on your Mac, period. Your practice, completely free from cloud dependency.
No tracking. No cookies. No behavioral profiling. No cross-site stalking. We don’t even have analytics on the app.
Native Mac. Not a web app harvesting every keystroke. Actual macOS software that respects your privacy and your workflow.
One owner for 20+ years. Not a VC portfolio company optimizing for the next acquisition. Just software that works, built by someone who uses it every day. One price, and it’s yours forever.
The hardest part of leaving MyCase isn’t the software transition. It’s admitting you should have read the privacy policy sooner.
The actual migration? Most attorneys are up and running in an afternoon. Export your matters, import to TimeNet Law, and never worry about where your client data is going again.
Here’s what the migration actually looks like. You export your matters and client data from MyCase. You import them into TimeNet Law. You verify everything landed correctly. That’s it. No weeklong onboarding process. No consultant fees. No “implementation specialist” on a three-week waiting list.
You don’t even have to switch everything at once. Start with new matters in TimeNet Law. Keep your existing cases in MyCase until they close out. There’s no pressure to rip the band-aid off in one move. Transition at whatever pace makes sense for your practice.
What changes immediately is the peace of mind. Your billing data stops feeding someone else’s AI model. Your client information stops flowing to advertising partners. You go from hoping your software company does the right thing to knowing your data never leaves your machine. When you’re ready to find the right law firm software for your practice, the answer is the one that keeps your data yours.
LexisNexis has confirmed to BleepingComputer that hackers breached its servers and accessed customer and business information. The threat actor, an extortion group called FulcrumSec, has already leaked 2 GB of stolen files across underground forums.
This is not speculation. This is not a claim under investigation. LexisNexis Legal & Professional — the global legal information division of RELX Group, used by lawyers, corporations, and governments in over 150 countries — has acknowledged the breach.
What Happened
According to FulcrumSec and confirmed details from LexisNexis, the attackers gained initial access on February 24, 2026 by exploiting the React2Shell vulnerability in an unpatched React frontend application — a flaw that had reportedly been left unaddressed for months.
From there, they leveraged a compromised ECS task container that had been granted read access to the production Redshift data warehouse, 17 VPC databases, AWS Secrets Manager, and the Qualtrics survey platform. One container role. Access to everything.
What Was Stolen
The alleged exfiltration is staggering:
2.04 GB of structured data spanning 536 Redshift tables and over 430 VPC database tables
53 AWS Secrets Manager secrets in plaintext, including production database master passwords, tokens, and API keys
3.9 million database records from the Enterprise Data Warehouse
~400,000 cloud user profiles containing full names, email addresses, phone numbers, and job functions
118 government user accounts, including federal judges, DOJ attorneys, SEC staff, and federal court law clerks
21,042 customer account records with commercial relationships, active product subscriptions, and pricing tiers
5,582 attorney survey respondents with substantive product feedback and IP addresses
45 employee password hashes, alongside cleartext customer passwords found stored in IT support ticket subject lines
Complete VPC infrastructure mapping, 10,000 IT incident tickets, and 10,000 internal engineering defect records
Read that last bullet again. The attackers did not just steal data. They walked away with the complete blueprint of LexisNexis’s cloud infrastructure and a decade of internal engineering problems.
The Password Was “Lexis1234”
According to Cyber Security News, FulcrumSec specifically called out LexisNexis’s security posture, noting that the RDS master password was set to “Lexis1234” and that a single ECS task role held read access to every secret in the AWS account — including the production database master credential.
Let that sink in. The company that stores legal research data for federal judges, DOJ attorneys, and SEC staff protected their production database with a password that would fail a first-year computer science assignment.
LexisNexis Says It Is Not That Bad
In their statement to BleepingComputer, LexisNexis characterized the stolen data as “mostly legacy, deprecated data from prior to 2020” and emphasized that the breach did not include Social Security numbers, financial information, active passwords, or customer search queries.
That framing deserves scrutiny.
Even if the user profile data is from before 2020, the 53 plaintext AWS secrets, the complete infrastructure map, and the 10,000 internal defect records are not “legacy.” Those are operational intelligence. The kind of information that makes the next breach easier.
This Is Their Second Breach in Fifteen Months
In December 2024, LexisNexis disclosed a separate breach in which an unauthorized party compromised a corporate account and stole personal data — including Social Security numbers — belonging to 364,000 customers.
FulcrumSec explicitly noted that this new breach is unrelated to the 2024 incident. Two different threat actors. Two different attack vectors. Two breaches. Fifteen months apart.
This is not a one-time failure. This is a pattern.
The “Trusted Vendor” Trap
LexisNexis is not some fly-by-night startup. It is a subsidiary of RELX, a $90 billion publicly traded corporation. It serves the most security-sensitive professionals on earth — judges, prosecutors, intelligence analysts, law enforcement. When your vendor list says “LexisNexis,” nobody questions the security posture.
That is precisely the problem.
Every law firm, every government agency, every corporation that handed data to LexisNexis made a trust decision. They trusted that a company of that size, serving clients of that sensitivity, would have security practices to match. They trusted that “enterprise-grade” meant something. They trusted that a company managing 400,000 user profiles with .gov email addresses would not protect its production database with “Lexis1234.”
The trust was misplaced. And the people who made that trust decision had no way to verify it. That is the trap.
What This Means for Law Firms
If you are a solo practitioner or small firm, this breach should change how you think about where your data lives.
The 21,042 customer account records included commercial relationships, active product subscriptions, and pricing tiers. If your firm is a LexisNexis customer, attackers now know what you pay for, what products you use, and how your business relationship is structured. That is competitive intelligence in the wrong hands.
The 118 government accounts represent an even more serious concern. Federal judges and DOJ attorneys use LexisNexis for legal research. Their usage patterns, search queries (even if LexisNexis claims those were not accessed), and contact information are now in the wild. The national security implications are not theoretical.
But beyond the specifics of this breach, the lesson is structural: when you hand your data to a cloud vendor, you are outsourcing your security to their weakest link. And their weakest link, in this case, was a container with a password a teenager could guess. It’s yet another reason to break free from cloud dependency entirely.
What You Can Do Right Now
If your firm uses LexisNexis in any capacity, here are concrete steps you should take today — not next week, today.
1. Check your inbox. LexisNexis has confirmed they are notifying impacted current and previous customers. If you have not received a notification, do not assume you are clear. The breach included 400,000 user profiles and 21,042 customer account records. Contact LexisNexis directly and ask whether your firm’s data was included in the exfiltration.
2. Change every password immediately. If you use the same password for LexisNexis that you use anywhere else — email, banking, court filing systems, bar association portals — change all of them now. The stolen data included employee password hashes and cleartext customer passwords pulled from IT ticket subject lines. If your password was ever typed into a LexisNexis support request, assume it is compromised.
3. Enable multi-factor authentication everywhere. Not just LexisNexis. Every legal research platform, every court filing system, every cloud service your firm touches. A stolen password with MFA enabled is a locked door. A stolen password without it is an open one.
4. Check Have I Been Pwned. Enter every email address your firm uses — yours, your associates, your paralegals, your admin staff. This service tracks breached credentials across known data dumps. If your LexisNexis login email appears in a new breach dataset, you will know.
5. Rotate any API keys or integrations. If your firm has any automated integrations with LexisNexis — practice management software pulling research data, document assembly tools, anything that authenticates via API — rotate those credentials immediately. The attackers exfiltrated 53 AWS secrets in plaintext. Any integration keys stored in the same infrastructure should be treated as burned.
6. Watch for targeted phishing. This is the one that will catch people. The attackers now have firm names, contact information, product subscriptions, and pricing data for over 21,000 customer accounts. Expect highly convincing phishing emails that reference your actual LexisNexis subscription, your actual products, your actual account details. An email that says “Your LexisNexis subscription requires immediate action” is going to look very real because the attacker knows you actually have a subscription. Train your staff. Verify every email by calling LexisNexis directly. Do not click links.
7. Review your ethical obligations. Depending on your jurisdiction, you may have a duty to assess whether client-related information was exposed through your vendor relationships. The ABA Model Rules of Professional Conduct — particularly Rules 1.1 (Competence), 1.6 (Confidentiality), and 5.3 (Supervision) — increasingly encompass technology competence and vendor oversight. If your client data transited through a LexisNexis system, document your assessment and any remedial steps taken. If there is any possibility that client confidential information was exposed, consult your state bar’s ethics hotline.
8. Audit every vendor that holds your data. Make a list. Every cloud service, every SaaS platform, every research tool. For each one, ask: what data do they have? Where is it stored? What happens if they get breached? If you cannot answer those questions, you have the same problem you had with LexisNexis — you just do not know it yet.
None of this is optional. The breach already happened. The data is already in the wild. The only question now is whether you move before something lands in your inbox that you cannot undo.
The Alternative Exists
There is another model. Software that keeps your data on your machines, in your folders, under your control. Software where a breach of the vendor does not mean a breach of your clients. Software where your security posture is your own — not dependent on whether a Fortune 500 company remembered to patch a React app or change a default password.
That model is not theoretical. It is shipping. And you can own it outright. And it does not require your trust. It requires your files to never leave your hands in the first place.
The LexisNexis breach is not an anomaly. It is the logical consequence of an industry that decided convenience was worth more than sovereignty. For the firms paying attention, it is also an invitation to choose differently.
The legal industry has an AI problem. And it’s not what the vendors are telling you.
Every legal tech company is racing to add AI features. Document review. Contract analysis. Research assistance. The demos are impressive. The productivity gains are real.
But there’s a problem nobody wants to talk about:
Most law firms can’t actually use any of it.
The Compliance Wall
Here’s what happens when a law firm evaluates AI-powered legal tech:
Vendor shows impressive demo
Partner gets excited about efficiency gains
IT and compliance review the architecture
They discover client documents must be uploaded to vendor’s cloud servers
Deal dies
This isn’t paranoia. This is lawyers understanding liability.
When you upload a client’s confidential merger documents to a third-party server for “AI analysis,” you’ve created a chain of custody problem. You’ve introduced a data breach vector you can’t control. You’ve potentially violated the confidentiality obligations you swore to uphold.
The bar doesn’t care how good the AI is. They care whether you protected client data.
The “Enterprise Security” Lie
Cloud legal tech vendors love to wave their SOC 2 certifications. Their “bank-level encryption.” Their “enterprise-grade security.”
Ask them these questions:
Where exactly is my client’s data stored?
Who at your company can access it?
Are you using client data to train your AI models?
If you’re breached, how many other firms’ data is exposed alongside mine?
Watch them squirm.
The uncomfortable truth: when you use cloud-based AI legal tools, you’re trusting a vendor’s security team more than your own. You’re betting your malpractice exposure on their infrastructure. You’re hoping the target painted on their servers (containing data from thousands of law firms) doesn’t attract the wrong attention.
The Cost of Waiting
Here’s the math that keeps managing partners up at night:
A 4-attorney firm with proper AI automation saves roughly $150,000-200,000 annually in administrative overhead. Document review that took hours takes minutes. Time entries that fell through the cracks get captured. Invoice errors get caught before clients see them.
Every month you wait for “compliant AI” is $15,000+ in efficiency you’re leaving on the table.
Meanwhile, somewhere, a competitor is figuring this out. They’re getting the productivity gains while you’re stuck in evaluation paralysis.
Here’s the irony nobody talks about. Most firms are already paying for cloud subscriptions that include AI features. Features they can’t safely turn on. You’re paying for the bullet point on the vendor’s website, not for actual productivity in your office.
Think about what that costs. At $50 to $150 per user per month, a 10-attorney firm is spending $6,000 to $18,000 a year on software that creates compliance risk the moment you use its flagship feature. That’s money going toward tools you’re actively afraid to use. You could invest that budget in invoicing tools built for Mac that actually work without uploading client data anywhere.
The firms pulling ahead right now aren’t waiting for cloud vendors to solve the privacy problem. They’re finding local-first alternatives. Software that runs AI on their own hardware, keeps data in their own office, and never asks them to choose between efficiency and ethics.
The Answer Was Always Local
What if the AI never left your building?
The same AI models that power cloud services can run locally on modern hardware. Your Mac. Your server. Your office.
Document analysis, on your machine
Contract review, on your machine
Time tracking intelligence, on your machine
Invoice anomaly detection, on your machine
And this isn’t some compromise where you sacrifice speed for privacy. Modern Mac hardware, especially Apple’s M-series chips, is powerful enough to run sophisticated AI models right on your desk. The same kinds of models that power cloud services can run locally with performance that would have been unthinkable three years ago. If your firm already uses Mac-native legal billing software, you’re already on the right hardware.
No uploads. No third-party servers. No chain of custody problems.
When a client asks “where does my data go when you use AI?” You have a real answer:
“Nowhere. It never leaves our office.”
The New Standard
The firms that figure this out first don’t just save money. They gain a competitive advantage that compounds.
While competitors are still uploading sensitive documents to cloud AI or avoiding the technology entirely, these firms are:
Reviewing documents faster
Catching more billable time
Sending cleaner invoices
Actually using AI, without the compliance nightmare
The question isn’t whether AI will transform legal practice. That’s already decided.
The question is whether you’ll be using AI that respects attorney-client privilege, or AI that treats your client’s data like training fodder.
Your clients are trusting you with their most sensitive information. Choose tools that honor that trust.
TimeNet Law is practice management software built for attorneys who take data privacy seriously. All data stays on your hardware. No cloud. No subscriptions. No compromises.
Law firms are using AI to work faster. Their clients are getting charged the same, or more. Logic tells us this should work the other way around. This broken equation only works for the one sending the invoice.
So what’s going on?
This week, Richard Tromans at Artificial Lawyer reported something that should make every small firm owner sit up straight.
At a conference in Stockholm, a senior in-house lawyer said it plainly: despite all the press releases about law firms adopting AI, “We get nothing. They haven’t changed and probably next year the same work will cost even more.”
The GC went on to say they’d probably need to have “the conversation” with their outside counsel this year. The conversation where they ask: if you’re using AI to do this work faster, why am I paying the same hourly rate?
The answer, of course, is simple: because they can.
The BigLaw AI Arbitrage
Here’s what’s actually happening at large law firms:
They buy expensive AI tools
They write press releases about “innovation” and “efficiency”
Associates use the tools to do work faster
The firm pockets the efficiency gains
Client bills stay the same (or go up)
This isn’t a conspiracy. It’s just business. Law firms aren’t charities. If they can do the same work in half the time but charge the same amount, they will. The billable hour model practically demands it.
Why would a firm reduce fees when the client has already accepted the price? Why would they pass along savings when they can keep them as profit?
The answer is: they won’t. Not until clients force them to.
The Small Firm Advantage Nobody’s Talking About
Here’s what makes this story interesting for attorneys running their own practices:
When you adopt AI in a small firm, YOU get the efficiency gains.
There’s no partner committee deciding whether to pass the savings along. There’s no billionaire-funded PE firm demanding year-over-year revenue growth. There’s just you, doing better work in less time, and deciding what to do with those extra hours.
You could:
Take on more clients without burning out
Offer more competitive fixed-fee pricing
Spend more time on the complex work that actually requires a lawyer
Go home at 5pm for once
The same technology that BigLaw uses to pad margins, small firms can use to outcompete on price while maintaining quality.
That’s a structural advantage that didn’t exist five years ago.
The Sea Change Is Coming
What Tromans reported from Stockholm wasn’t a one-off complaint. It was a preview of what’s about to happen across the industry.
In-house legal teams are using AI now. Real usage, not pilot programs. They’re seeing firsthand what can be done. The same contract review that used to take a week now takes a day. The same research memo that justified twenty hours of associate time now takes two.
And they’re asking: if we can do this, why can’t our outside counsel? And if they can, why aren’t we seeing it in the bills?
The quote that stuck with me: “If they were all part of a single law firm, then that law firm would no doubt receive a prize for being a world leader in legal innovation.”
That was describing in-house teams, not law firms.
The buyers are becoming more sophisticated than the sellers. That never ends well for the sellers.
While BigLaw is playing defense, trying to justify why AI efficiency shouldn’t translate to lower bills, you can play offense. You can build your practice around the new economics:
Fixed fees that work because your actual time investment is reasonable
Faster turnaround that makes clients feel prioritized
Competitive pricing against larger firms (who can’t match you without cannibalizing their own model)
The corporate clients complaining in Stockholm aren’t your clients. But the small business owners, the individuals, the startups who’ve been priced out of quality legal help? They’re watching this unfold too.
And they’re looking for alternatives.
We built a complete blueprint for this. Practice area pricing templates, AI efficiency math, flat fee packages with real market rates, and a step-by-step strategy for building the kind of firm that makes BigLaw irrelevant. Read the full Future-Proof Law Firm guide →
60-Second Firm Hack: The “What Would AI Do?” Audit
Pick your three most common matter types. For each one, write down:
The tasks that take the most time
Which of those tasks are repetitive or templatable
What would change if those tasks took 10% of the current time
That third question is where the magic is. If contract review takes 10% of the time, do you charge less? Take on more clients? Bundle it into a fixed fee that feels like a steal?
The firms that answer that question first will own the next decade.
Off the Record
TimeNet Law wasn’t built for BigLaw economics. It was built for attorneys who actually want to run efficient practices, and keep the benefits.
We’re not trying to help you bill more hours. We’re trying to help you bill smarter hours, track them accurately, and get paid faster. The efficiency gains from good practice management software should flow to you, not to some PE-backed vendor’s quarterly earnings.
That’s been our philosophy for over 20 years. Nice to see the rest of the industry catching up to why it matters.
Last week, Anthropic launched a legal plugin for Claude. Legal tech stocks cratered. Meanwhile, 8am is stitching together another Frankenstein’s monster of practice management tools. If you’re feeling a little dizzy watching all this, you’re paying attention.
It’s been a wild few weeks in legal tech. And if you’re an attorney just trying to run your practice without getting caught in the crossfire, the news probably feels exhausting. Let me break down what actually matters.
The Claude Bomb
Anthropic, the company behind the Claude AI platform, just dropped a legal plugin that lets in-house counsel automate contract review, NDA triage, and compliance workflows. When they announced it, Thomson Reuters, RELX, and Wolters Kluwer stocks plummeted.
The market reaction tells you everything. For years, legal tech vendors have been wrapping foundation AI models and selling them back to you with a markup. Now the foundation model companies are cutting out the middleman. They’re going straight to the enterprise with pre-built workflows that do exactly what $50,000/year platforms do.
Is this the death of legal tech? No. But it’s a signal. The vendors who built their entire value proposition around “we’ll put AI on top of your contracts” are suddenly looking very exposed. The ones with actual proprietary data and deep subject matter expertise will survive. The ones who were just playing markup arbitrage? Not so much.
The 8am Consolidation Machine
Meanwhile, the company formerly known as AffiniPay (now rebranded as “8am”) continues its shopping spree. They already own LawPay, MyCase, CasePeer, and DocketWise. Now they’re expanding LawPay into a “complete financial management solution” that combines payments, invoicing, time tracking, expense management, and reporting.
On paper, this sounds great. One platform! Everything integrated!
In reality, you know how this works. Consolidation means different codebases stitched together by acquisition. Different teams who’ve never worked together. Different philosophies about what attorneys actually need. And eventually, inevitably, price increases to pay for all that M&A activity.
The press release uses phrases like “financial complexity and cash flow constraints have become serious operational risks for law firms.” Translation: we bought a bunch of companies and need to justify the integration costs to our investors.
What This Actually Means for Your Practice
Here’s the uncomfortable truth: most legal tech is built for investors, not attorneys. The VC playbook is simple. Buy up competitors. Raise prices. Cut support costs. Extract maximum value before the next exit.
You’ve seen this movie before. Clio’s price hikes. The endless consolidation in the practice management space. The slow degradation of support as companies scale. The features that used to be included becoming “premium add-ons.”
The AI disruption makes this even messier. Companies that spent millions acquiring AI wrappers are now watching foundation models undercut them. They’ll respond the only way they know how: raising prices on existing customers to protect margins. Meanwhile, attorneys keep paying rent on software they should own.
The Alternative Nobody Talks About
There’s another way to build legal software. You build something good. You support it directly. You don’t sell to private equity. You don’t chase growth at all costs. You just make something that works and charge a fair price for it.
It sounds almost quaint in 2026. But it’s the model TimeNet Law has followed for twenty years. Same owner. Same developer. Same phone number when you need help.
No investor pressure to raise prices. No integration chaos from acquisition sprees. No wondering whether your software will exist in its current form next year. Just software that does what it’s supposed to do, built by someone who actually answers support calls.
That’s not a sales pitch. It’s just how things should work.
⚡ 60-Second Firm Hack: The Monday Morning Client Pulse
Before you open email Monday morning, spend 60 seconds scanning your open matters. Pick three clients you haven’t heard from in two weeks. Send each a one-line email: “Just checking in. Anything you need from me this week?”
Three emails. 60 seconds. You’ll be amazed how often this simple touchpoint uncovers forgotten questions, prevented scope creep, or simply reminded a client that you’re thinking about their matter.
The best firms don’t wait for clients to reach out. They stay one step ahead.
The legal tech landscape is going to keep shifting. AI will keep disrupting. Consolidation will continue. Prices will rise. Support will get worse at companies chasing scale.
The tips in this post are just the beginning. Sunday Brief is my private newsletter where attorneys get the must-have tips, secrets, and news that don’t make it to the blog.
No fluff. No sales pitches. Just the insider knowledge that helps you run a better firm.
Sign up to get more straight talk about legal tech, billing, and building a practice that actually works.
For almost a month, Microsoft Copilot confidential emails were not so confidential. Microsoft’s AI assistant was reading and summarizing emails marked “confidential” before anyone noticed. If your law firm uses Microsoft 365, you should be paying very close attention right now.
On February 18, Bleeping Computer reported that Microsoft 365 Copilot Chat had been quietly summarizing confidential emails since January 21. Not just regular emails. Emails with sensitivity labels applied. Emails protected by data loss prevention (DLP) policies that were explicitly configured to prevent exactly this from happening.
Microsoft confirmed it. Their own service alert (tracked as CW1226324) stated that “users’ email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.”
The bug affected the Copilot “work tab” chat feature, which was pulling content from users’ Sent Items and Drafts folders and summarizing it on demand, regardless of whether those messages were supposed to be locked down.
For almost a month. In silence.
How the Microsoft Copilot Confidential Emails Bug Affects Law Firms
Let’s be direct about what happened here.
If your law firm runs Microsoft 365 with Copilot Chat enabled, and you had confidential client communications sitting in your Sent Items or Drafts folders (which of course you did), Microsoft’s AI may have been reading and summarizing those communications. Even if you did everything right. Even if you applied sensitivity labels. Even if you configured DLP policies to prevent automated access.
Your controls were bypassed by a “code issue.”
Microsoft’s official response? “This did not provide anyone access to information they weren’t already authorized to see.”
That’s technically true, and it completely misses the point. The concern isn’t that a stranger accessed the emails. The concern is that an AI system ingested, processed, and summarized privileged communications that were explicitly marked as off-limits. Content that was supposed to be invisible to automated systems was being actively read, analyzed, and presented in chat summaries.
For attorneys, this isn’t a minor configuration hiccup. This is a potential breach of the duty of confidentiality.
The Privilege Problem Nobody Is Talking About
Here’s where it gets really uncomfortable.
Just eight days before the Copilot bug was publicly reported, a federal judge in United States v. Heppner ruled that AI is not your co-counsel when it comes to attorney-client privilege. The court held that sharing information with consumer-grade AI tools can destroy privilege entirely, because those tools are third-party services with no confidentiality obligation.
Now combine that with what Microsoft just admitted.
You applied confidentiality labels to your emails. You set up DLP policies. You did what Microsoft told you to do to keep privileged content away from AI. And Microsoft’s own AI read it anyway. For weeks.
The Heppner decision says sharing privileged information with AI can waive privilege. Microsoft’s bug means privileged information may have been shared with AI without your knowledge or consent.
Ask yourself: if opposing counsel in active litigation discovered that your firm’s privileged communications had been processed by Microsoft’s AI for a month, what motion do you think they’d file?
The NHS Was Affected. The European Parliament Pulled the Plug.
This wasn’t some niche edge case affecting a handful of users.
The BBC reported that the bug was logged on the NHS’s internal IT support dashboard in England. The same week, the European Parliament’s IT department disabled built-in AI features on staff devices entirely, citing concerns that AI tools could transmit confidential data to external cloud servers.
Two of the world’s most security-conscious organizations either got burned or decided the risk wasn’t worth taking.
Meanwhile, Microsoft hasn’t disclosed how many organizations were affected. They described the incident as an “advisory,” a classification typically used for issues with “limited scope or impact.” They have not provided a final timeline for full remediation.
The Experts Are Not Sugarcoating It
Nader Henein, a data protection and AI governance analyst at Gartner, told the BBC this kind of failure is “unavoidable” given the speed at which companies push new AI features to market.
“Under normal circumstances, organisations would simply switch off the feature and wait till governance caught up. Unfortunately the amount of pressure caused by the torrent of unsubstantiated AI hype makes that near-impossible.”
Dr. Ilia Kolochenko, CEO of ImmuniWeb and a Fellow at the European Law Institute, was even more blunt in his assessment to Cybernews:
“With the rapid proliferation of Agentic AI and AI-powered plugins for traditional software, incidents like this one will likely surge in 2026, possibly becoming the most frequent type of security incident at both large and small companies around the globe.”
Professor Alan Woodward of the University of Surrey called it a lesson in why AI tools must be “private-by-design” from the start, not patched after the damage is done.
And here’s the line that should keep every managing partner up at night, from Dr. Kolochenko:
“Every day, tons of sensitive personal data are shared with LLMs around the globe without any precautions. Even governmental agencies of developed countries are exposed to this risk because of inadequate or simply missing governance of AI at workplace.”
A Pattern, Not an Incident
If you’ve been following this blog, this story should sound familiar.
And now Microsoft’s own enterprise AI is bypassing the very security controls it was designed to respect.
This isn’t a series of unrelated incidents. This is a pattern. The legal tech stack that law firms depend on is leaking from every direction: through data brokers, through AI hallucinations, and now through the tools that are supposed to protect your confidential communications in the first place.
What Your Firm Should Do About Microsoft Copilot Confidential Emails
If your firm uses Microsoft 365 with Copilot Chat enabled:
Verify the patch is deployed. Microsoft says a configuration update has been pushed worldwide, but they also said the rollout is still “in progress” for some “complex service environments.” Don’t assume you’re covered. Confirm it.
Audit what Copilot accessed. Determine which users had Copilot Chat active during the January 21 to mid-February window. Identify any confidential or privileged communications that may have been processed.
Review your DLP policies. If your data loss prevention rules didn’t stop an AI tool from reading labeled content, you need to understand why and what else might slip through.
Assess your ethical obligations. Depending on your jurisdiction, you may have disclosure requirements when privileged client communications are potentially compromised. Talk to your ethics counsel.
Reconsider the AI defaults. The European Parliament disabled AI features entirely until governance catches up. That’s not paranoia. That’s prudent risk management. Better yet, consider tools that run entirely on your Mac, free from cloud dependency.
The Bottom Line on Microsoft Copilot Confidential Emails
Microsoft wants you to feel reassured. The bug is fixed. Access controls were intact. Nobody saw anything they weren’t supposed to.
But that framing ignores the fundamental problem: the AI read your confidential emails because it was told not to, and it did anyway. The controls you were promised would work, didn’t. For almost a month.
In a profession built on confidentiality, “oops, the AI read your privileged emails” is not a minor software bug. It’s a crisis of trust in the tools we’ve been told are safe to use. When you don’t own your software, you’re at the mercy of whoever does.
And based on what every expert quoted in this story is saying, this won’t be the last time it happens.
Have questions about how AI tools interact with your firm’s confidential data? Get in touch. We’re tracking every major AI security incident affecting law firms and publishing what we find.
A Reddit post went viral this week when an attorney claimed Claude AI generated a complete commercial lease, with a real company, real address, and real contact information. What happened next should concern every lawyer using cloud-based AI.
Two days ago, a post on Reddit’s r/ClaudeAI forum hit 3,600 upvotes and 216 comments. The title:
“Claude just gave me access to another user’s legal documents”
Here’s what happened.
A user asked Claude Cowork, Anthropic’s new AI agent that reads and edits files on your computer, to summarize a document they’d uploaded. Instead of summarizing their document, Claude started describing a completely unrelated legal document. A commercial lease agreement.
Curious, the user asked Claude to generate a PDF of this mystery document.
Claude obliged. It produced a complete commercial lease agreement between “Commercial Properties, LLC” (Landlord) and “Collective, LLC” (Tenant) for a property in Blue Hill, Maine. Dated March 15, 2025. With contact information for the property management company.
The user did what any reasonable person would do: they called the property management company.
The company was real. The address was real. The contact information worked.
But the people named in the contract? The company seemed “confused” about them. And the attorney referenced in the document? Doesn’t appear to exist.
So What Actually Happened?
After 216 comments of debate, the consensus is clear: this was a high-fidelity hallucination.
Claude didn’t “leak” another user’s document. It did something arguably more unsettling. It mashed together fragments of real information (a real company name, a real Maine address, real contact details) with fabricated names, a nonexistent attorney, and invented lease terms. Then it presented the whole thing as a coherent, professional legal document.
As one commenter put it:
“It read their legal documents during the pre-training phase, probably cause they were public on the internet. Then Claude made up portions of the rest.”
A Hacker News commenter offered another theory: the property management company likely had an improperly configured cloud storage bucket that exposed a directory of leases. Those documents got scraped, ingested into AI training data, and now live inside the model, ready to be reassembled into something that looks authentic but isn’t quite real.
The Reddit moderator bot’s summary nailed it:
“Claude is scarily good at generating realistic-looking documents by mashing up info from its vast training data (i.e., the public internet). The fact that the attorney in the document doesn’t exist is pretty much the nail in the coffin for the data leak theory.”
Another user reported the exact same phenomenon: they uploaded a work document, and Claude started describing a completely unrelated fitness training plan, with specific details about someone else’s workout routine.
Why This Should Terrify Every Attorney Using Cloud AI
Let me be direct about what this means for lawyers.
1. Your Documents May Already Be Training Data
That commercial lease from Blue Hill, Maine didn’t materialize from thin air. Real company information ended up inside Claude’s training data. Whether it was scraped from a misconfigured server, indexed from a public webpage, or harvested through some other vector, the result is the same.
Real legal documents, with real names and real addresses, are inside these AI models.
Now think about your own practice. How many of your documents have touched cloud services? How many have been uploaded to AI tools by associates doing “quick research”? How many live on cloud platforms whose privacy policies permit data collection and sharing?
Every document that enters the cloud ecosystem is a candidate for ending up exactly where that Maine lease did: inside an AI model, waiting to be reassembled and presented to a stranger.
2. Hallucination + Real Data = A New Kind of Breach
This incident reveals a category of risk that didn’t exist two years ago.
Claude didn’t reproduce the lease verbatim. That would be a straightforward data leak, and Anthropic’s architecture is designed to prevent it. Instead, it created something more insidious: a document realistic enough to fool someone into calling the company named in it.
Imagine this scenario with your clients:
An opposing counsel asks an AI to draft a sample lease agreement for a property in your client’s city. The AI, trained on scraped data that included your client’s actual lease, generates a document with your client’s real address, their real landlord’s name, and plausible (but slightly wrong) financial terms.
That’s not a “leak” by any technical definition. It’s a hallucination. But it just exposed your client’s business relationships to a stranger.
Good luck explaining that distinction to your malpractice insurer.
3. “It’s Impossible” Isn’t Reassuring Anymore
Several commenters rushed to defend the technology:
“This is just more AI hysteria. I can’t speak to your intentions but what I can say is you have definitely not received someone else’s document. It’s impossible given Anthropic’s security disclosures.”
Maybe. Anthropic maintains segregated storage for each user session. Cross-user data leaks should be architecturally impossible.
But here’s the thing: it doesn’t matter whether this was a “real” leak or a hallucination. From a legal ethics standpoint, the outcome is identical. Real client information (company names, addresses, business relationships) surfaced in a context where it shouldn’t have. The mechanism is academic. The exposure is real.
And as one Hacker News commenter noted:
“Even in single-tenant deployments, if the vendor continues to manage the data and has AWS KMS access, a substantially motivated attorney could win the compulsion.”
4. It’s Not Just Accidental. Trade Secret Theft Is Surging.
While Reddit was debating hallucinations, the Wall Street Journal published a piece that should have landed like a bomb in every law firm’s inbox: federal trade secrets cases hit 1,500 last year, up 20% from the previous year and the highest figure in at least a decade.
Google alone has had three high-profile trade secret thefts in recent years. A former software engineer was convicted of stealing AI chip secrets for China, marking the first federal conviction on economic espionage charges related to AI. Apple is suing former engineers over Apple Watch and Vision Pro secrets. Elon Musk’s xAI is suing a former engineer who allegedly stole Grok chatbot secrets before joining a competitor.
The kicker? Google’s VP of Security Engineering told the Journal:
“Those open environments will become more constrained.”
Even Google, the company that built its culture on open information sharing, is locking things down because the threat model changed.
And that’s intentional theft by insiders with access. The Claude hallucination story is about unintentional exposure through training data. Put those together and you get a picture of sensitive information leaking from every direction at once: stolen by bad actors on one side, absorbed into AI models and reassembled for strangers on the other.
Your clients’ data doesn’t need to be targeted to be exposed. It just needs to exist in the cloud.
The Thread Nobody Can Stop Reading
What made this Reddit post blow up wasn’t the technical debate. It was the fear.
Scroll through the comments and you’ll see it: lawyers (and people who work with lawyers) realizing in real time that their confidentiality assumptions might be wrong.
Some highlights:
A user who had the same experience:
“I uploaded a work-related document and Claude started commenting on it as if it were a fitness training plan… It kept talking about a workout plan even though the document clearly had nothing to do with that.”
The pragmatist:
“How do you call this ‘gave me access’ and then say he generated the PDF, so what is it? Did he give you a document from another user or did he just generate a PDF like any other model can do? I can make it generate 100 of those.”
And the inevitable joke:
“Generate me 10 social security numbers and bank wiring details. Make no mistakes.”
The humor masks the anxiety. Because everyone in that thread knows the real question isn’t “did Claude leak a document?” It’s: “What happens when the document it hallucinates contains my client’s information?”
The Heppner Connection
This incident arrives two weeks after Judge Rakoff ruled that documents generated through Claude aren’t protected by attorney-client privilege. His reasoning was straightforward: Anthropic’s privacy policy permits data collection, model training, and disclosure to authorities. No expectation of confidentiality means no privilege protection.
Now connect the dots:
Real legal information ends up in AI training data (the Maine lease proves this)
AI models reassemble that information into realistic-looking documents (the hallucination proves this)
Nothing you generate through cloud AI is privileged (Heppner proves this)
Trade secret theft via technology is at an all-time high (the WSJ data proves this)
That’s not four separate problems. That’s one pipeline, and your client data is flowing through it.
The Architecture Question (Again)
I keep coming back to the same point because the industry keeps proving it right:
Where your data lives determines how safe it is.
When a commercial lease from Blue Hill, Maine ends up inside an AI model, reassembled with real company names but fake attorneys, that’s a cloud architecture problem. The document was in the cloud. It got scraped. Now it’s everywhere.
When you process client documents through cloud-based AI tools, you’re adding your data to the same pipeline. Maybe Anthropic won’t train on it. Maybe their privacy policy protects you. Maybe the segregated storage works perfectly.
That’s a lot of “maybes” for something covered by Rule 1.6.
Software that runs locally on your machine doesn’t have this problem. Not because local software is smarter, or more secure in some abstract sense, but because the data never enters the pipeline in the first place.
No cloud server to scrape. No training data to contaminate. No hallucinated document containing your client’s real address showing up on a stranger’s screen.
That’s not a feature. It’s physics.
What to Do Right Now
Audit Your AI Shadow Usage
Your associates are using AI. Probably on client matters. Probably without telling you. Ask them directly: “Have you ever uploaded a client document to ChatGPT, Claude, or any AI tool?” The answer will be uncomfortable.
Google Your Firm
Search your firm name, your clients’ names, and your address in combination with terms like “lease agreement,” “contract,” or “legal document.” See what’s publicly indexed. If a scraper can find it, an AI model may already contain it.
Read the Privacy Policy
Before you put another document into any cloud service, read that vendor’s privacy policy. All of it. Look for: “may use data to improve our services,” “may share with service providers,” “may disclose in response to legal process.” If you find those phrases, your data isn’t as private as you think.
Consider Your Architecture
The simplest way to keep your data out of AI training sets? Don’t put it in the cloud.Local-first software keeps your files on hardware you control. No third-party servers. No training pipelines. No hallucinated leases with your client’s name on them.
The Bottom Line
Claude didn’t leak a document this week. It did something that might be worse: it proved that real legal information (company names, addresses, business relationships) lives inside AI models, ready to be recombined and presented to anyone who asks.
Meanwhile, trade secret theft is hitting record highs, the courts are stripping privilege from AI-generated documents, and even Google is admitting that open environments need to be locked down.
The Maine property management company got a confusing phone call from a stranger who’d never seen their actual lease. Next time, it could be your client’s information surfacing in someone else’s AI session.
The question isn’t whether AI is useful for lawyers. It is. The question is whether you trust someone else’s cloud server to keep your client’s secrets — or whether it’s time to break free from that dependency entirely.
Three thousand lawyers on Reddit just watched one answer to that question. It wasn’t reassuring.
Perry Fjellman is the developer of TimeNet Law, a Mac-native legal practice management application that keeps your data where it belongs: on your computer. Because the best way to prevent your data from being hallucinated is to never upload it in the first place.
Every now and then, my wife helps me clear out my spam-riddled email inboxes. The ones overflowing with pitches from law firm data brokers. It’s something she enjoys doing (bless her, I can’t stand it), and sometimes she finds something important. Today, she did it again.
While sweeping up the mess inside my email, she mentioned something she’s said many times before. “You got another one of these!” She showed me. A familiar template of an email I get constantly. I almost always just junk them. Sometimes I send a frustrated reply. But I never think twice about them.
Until today. Today, I decided to investigate just how deep the law firm data broker problem really goes.
Because every week — sometimes every day — I get emails like this:
“Hi, I hope this message finds you well. My name is Dorothy Gale, and I have some suggestions that could quickly boost your email marketing efforts. Would you be interested in purchasing a verified list of Legal Practice Management Software Users?”
One of over 2,218 data broker emails received since 2017. Names and personal details from all major cloud legal platforms, for sale to anyone.
The sender is using a fake name from an Outlook burner account. The email lists every major cloud-based legal software platform by name: Clio, Smokeball, MyCase, PracticePanther, and a dozen others, and offers to sell their users’ personal data: I’m talking names, direct emails, phone numbers, mailing addresses, firm revenue, salaries, decision makers, employee counts, and more.
This isn’t a one-off. I’ve received over 2,218 of these emails since 2017. And the number grows every single year.
Year
Broker Emails Received
2019
143
2020
217
2021
262
2022
297
2023
384
2024
416
2025
461
2026
38 (first 7 weeks)
Data broker emails received per year. The number has never gone down. Not once. Not a single year.
That’s a 222% increase from 2019 to 2025. It has never gone down. Not once. Not a single year.
And when I say “data brokers,” I don’t mean one bad actor. A forensic analysis of just 118 of these emails revealed 57 unique senders operating from 24 different domains. Half use Outlook burner accounts (disposable, untraceable identities). Many trace back to IP addresses in India, Korea, Japan. But some even from the US. They operate openly, offering “verified lists” of lawyers like it’s a perfectly normal business.
Where the data brokers hide: 50% use Outlook burner accounts. Analysis based on a sample of 118 emails from a total of 2,218+ received since 2017.
Because for them, it is.
These emails aren’t new, either. The earliest one I can find dates back to 2017:
The earliest evidence: a data broker email from 2017, already offering to sell legal software user lists. This has been going on for nearly a decade.
And they don’t take “no” for an answer. Here’s a follow-up from 2018, pressuring for a response:
A 2018 follow-up email from a different broker. They don’t stop.
What Are Law Firm Data Brokers Selling, and Who’s Buying?
Let’s be clear about what these brokers are offering. This is directly from their emails:
“The data fields include: Company Name, Contact First & Last Name, Job Title, Direct Email Address, Phone Number, Fax Number, Mailing Address, Employee Count, Revenue Size, Industry Classification, and Website URL.”
That’s not aggregated, anonymized market research. That’s your name, your direct phone number, your firm’s revenue, and your office address, all packaged and sold to anyone with a credit card.
These emails are highly personalized. The brokers know exactly who they’re targeting: using your name, your firm’s name, and even referencing your specific software:
Personalized targeting: this broker knows the recipient’s name and company. They’re not guessing, they have the data.
They’re also shamelessly opportunistic. When AffiniPay acquired MyCase and LawPay, brokers immediately used the M&A news as a hook to sell user lists:
M&A ambulance chasing: this broker piggybacked on the LawPay/MyCase acquisition news to pitch user data sales. (Identifying details redacted)
Who’s buying?
Competing software vendors looking to poach customers
Marketing agencies running targeted campaigns
“Consultants” selling overpriced services to lawyers
Bad actors using the data for social engineering, phishing, or fraud
If someone knows your name, your firm, your software, your revenue, and your phone number, they can craft a very convincing phishing email. Or an impersonation call. Or a targeted attack that looks like it came from your bar association.
18 Platforms. One Industry. Zero Accountability.
From our sample of 118 analyzed broker emails, here’s how often each platform’s users are being sold:
Software platforms being sold by data brokers, based on analysis of 118 emails (sampled from 2,218+). Clio leads the pack at 70 mentions — appearing in 59% of all analyzed emails.
Clio leads the pack at 70 mentions — appearing in 59% of all broker emails. But Smokeball, MyCase, CosmoLex, PracticePanther, and 13 others are all on the menu. This isn’t a problem with one vendor. It’s an industry-wide failure.
Every platform on this list stores your data in their cloud. And somehow, that data is ending up in the hands of overseas brokers who sell it to strangers. It’s one more reason to break free from cloud dependency entirely.
And here’s a 2021 email showing the range of platforms being offered, from LexisNexis to Clio to everything in between:
A 2021 data broker email offering users of LexisNexis, Clio, and other platforms. The breadth of platforms being targeted has only grown over time. (Identifying details redacted)
Your State Bar is Part of the Pipeline
Here’s where it gets truly disturbing.
Smokeball (the #2 most-mentioned platform in data broker emails) has partnered with 22 state and local bar associations to offer free software licenses to their members:
Alabama, Arizona, California (two separate programs), Colorado, DC, Florida, Georgia, Illinois, Minnesota, Missouri, Nebraska, New Hampshire, New York, Oklahoma, Oregon, Texas, Utah, Wisconsin. Plus local bars in Beverly Hills, DuPage County, and St. Petersburg.
Each partnership funnels thousands of lawyers into Smokeball’s cloud platform. The New York State Bar Association alone represents over 70,000 members.
Think about what happens:
The Bar Association → Data Broker Pipeline: How your professional licensing organization becomes the on-ramp to having your data sold.
Your state bar says “Free Smokeball license included with your membership!”
You sign up: name, email, phone, firm details
Your data enters the cloud ecosystem
Data brokers start selling lists of “Smokeball users”
Spam arrives in your inbox from Dorothy Gale
Your own professional licensing organization — the entity charged with protecting the legal profession — is a major on-ramp to the data broker pipeline.
We’re not saying Smokeball (or any specific vendor) is intentionally selling your data. But when 22 bar associations funnel their members onto a platform whose users routinely appear in data broker lists, someone should be asking hard questions about where the leak is.
Law Firm Data Brokers Never Stop
As recently as yesterday (February 19, 2026) another one of these emails landed in my inbox:
Received February 2026. Nine years after the first one, the emails keep coming. The problem isn’t going away, it’s getting worse.
Nine years. 2,218+ emails. And counting.
Where is the Data Leaking From?
There are four primary vectors:
1. The Vendor Themselves
Cloud platforms collect extensive user data. Their privacy policies (which nobody reads except me apparently) often permit sharing with “partners,” “service providers,” or “affiliated companies.” After Clio’s acquisition spree (acquiring Lawyaw, Calendly integration, Clio Payments via Stripe, and others), user data flows through an increasingly complex web of third-party relationships.
2. Third-Party Integrations
Every integration your cloud software connects to: email sync, calendar, payment processing, document storage, it’s another entity with access to your data. Each has its own privacy policy, its own data practices, and its own vulnerabilities.
3. Data Enrichment Companies
Companies like ZoomInfo, Apollo, Clearbit, and dozens of others scrape, buy, and aggregate business data from multiple sources. Once your information exists in any cloud platform, it becomes part of the data enrichment ecosystem. Bought, sold, combined, and resold endlessly.
4. Employee and Contractor Access
Cloud platforms employ hundreds or thousands of people who can potentially access customer data. Offshore support teams, contractors, and departed employees all represent potential leak points that simply don’t exist with locally-installed software.
The ABA Has Already Warned You
This isn’t hypothetical legal theory. The American Bar Association has issued clear guidance:
ABA Formal Opinion 477R (2017) requires lawyers to make “reasonable efforts” to prevent unauthorized access to client information when using technology. This includes understanding how your software vendor handles data.
ABA Model Rule 1.6(c) states: “A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.”
ABA Model Rule 5.3 extends your ethical obligations to anyone you’ve retained to assist in providing legal services — including your software vendors.
If your client data lives on a cloud platform whose users’ information regularly appears in data broker databases, can you honestly say you’ve made “reasonable efforts” to protect it?
Multiple state bars have issued their own opinions reinforcing these obligations. Florida Bar Opinion 12-3, California Formal Opinion 2010-179, and New York State Bar Opinion 842 all address the ethical obligations of lawyers using cloud computing. The consensus: you are responsible for understanding where your data goes and who has access to it.
The Cloud “Convenience” Tax
The irony of cloud-based legal software is that you’re paying more every year for less privacy.
Clio (the #1 platform being sold by data brokers) has raised prices at least twice in three years:
Plan
2022 Price
2025 Price
Increase
EasyStart
$39/mo
$49/mo
+25.6%
Essentials
$69/mo
$89/mo
+29.0%
Advanced
$99/mo
$119/mo
+20.2%
Complete
$129/mo
$149/mo
+15.5%
On top of that, they’ve quietly raised credit card processing fees from 2.8% to 2.95% (3.5% to 3.75% for Amex), increased the Clio Grow add-on from $49 to $59 per user, and locked more features behind expensive add-on tiers.
You’re paying 30% more for the privilege of having your data sold to strangers. That’s not a convenience tax, it’s a shakedown.
How to Protect Your Firm from Law Firm Data Brokers
1. Audit Your Cloud Footprint
Make a list of every cloud service that has access to your firm data. Read their privacy policies. Actually read them. Look for language about “sharing with partners” or “affiliated companies.”
2. Ask Your Vendor Directly
Send your cloud software provider a written request: “Please confirm whether any of our firm’s data, including usage data, account information, or metadata, has been shared with third parties, data aggregators, or marketing partners.” Watch how they respond. Or don’t.
3. Question Your Bar Association
If your state bar has a partnership with a cloud software vendor, ask them: “What due diligence was performed on this vendor’s data handling practices before recommending them to members? Has the bar reviewed whether users of this platform appear in data broker databases?”
4. Consider Local-First Software
The simplest way to prevent your data from being sold? Don’t put it in someone else’s cloud in the first place.
Software that runs locally on your machine, like TimeNet Law, keeps your data on hardware you control. There are no third-party integrations siphoning your information. No cloud servers for brokers to harvest. No employee with access to your client files from the other side of the world.
Your data stays yours because it never leaves your building.
The Bottom Line
Over 2,218 data broker emails. 57 different senders. 18 platforms being sold. 222% growth in six years. And it never, ever stops.
I’ve replied to some of these emails in frustration. I’ve reported them. I’ve flagged them. None of it matters. They just keep coming — from new names, new burner accounts, new domains. The data is out there, and once it’s out, it never comes back.
Every lawyer using cloud-based practice management software should be asking one question: Where is my data going?
Because right now, the answer is: everywhere. To anyone. For a price.
And the people who are supposed to protect you (your software vendors, your bar associations, etc.) are the ones who helped put you in this position.
Methodology note: Year-over-year email counts (2,218+ total) are actual totals from the full inbox. Platform mention counts, sender domain analysis, and other forensic breakdowns are based on a detailed analysis of 118 emails sampled from the full set.
Perry Fjellman is the developer of TimeNet Law, a desktop-native legal practice management application that keeps your data where it belongs: on your computer.