Categories
Mac for Lawyers

Why Mac-First Matters: A Guide for Mac-Using Attorneys

You didn’t buy a Mac by accident.

You chose it because you value thoughtful design. Because you wanted something that works reliably, looks beautiful, and doesn’t fight you every step of the way.

So why would you settle for billing software that treats your Mac like an afterthought?


The “Mac Compatible” Lie

Here’s a dirty secret of legal tech: most “Mac compatible” software isn’t Mac software at all.

It’s Windows software that technically runs on a Mac. Or it’s a web app crammed into an Electron wrapper. Or it’s a browser tab that asks you to pretend it’s a native application.

You can feel the difference immediately:

  • The lag when you click something and wait for the interface to catch up
  • The battery drain from running what amounts to a Chrome browser in disguise
  • The alien interface that looks nothing like the rest of your Mac
  • The missing shortcuts, no Command-key anything, no proper menu bar, no integration with your workflow

“Mac compatible” is marketing speak for “we didn’t want to lose the sale.”


What Mac-Native Actually Means

True Mac-native software is built from the ground up for macOS. It uses Apple’s frameworks. It respects Apple’s design language. It feels like it belongs on your machine.

Here’s what that looks like in practice:

It’s fast. No Electron bloat. No web rendering. Native code runs at native speed.

It’s familiar. Standard Mac keyboard shortcuts. Proper menu bar. Drag and drop that works like you expect.

It integrates. Works with Spotlight, Time Machine, iCloud, and all the other Mac features you rely on.

It respects your battery. Because it’s not secretly running a web browser, your laptop doesn’t turn into a space heater.

It works offline. When your internet goes down before a court deadline (and it will), your billing software shouldn’t go down with it.


The Windows Disaster Stories

I’ve heard them all. Attorneys call me after:

  • Ransomware encrypted their entire Windows network, including the cloud-synced “backup” that was also connected
  • A Windows update rebooted mid-trial prep. Goodbye, unsaved work
  • Blue Screen of Death during a client presentation
  • The antivirus software decided the billing app was a threat and quarantined it

Mac isn’t immune to problems. But attorneys who chose Mac did so because they wanted fewer of these surprises. Then they install Windows-first software and invite the chaos back in.


What to Look for in Legal Software for Mac

If you’re evaluating billing or time tracking software, here’s your checklist:

✓ Is it actually native?

Ask directly: “Is this built with Apple’s native frameworks, or is it Electron/web-based?” If they hesitate, you have your answer.

✓ Does it work offline?

If the software requires an internet connection to function, it’s not truly yours. It’s a rental.

✓ Where does your data live?

On your Mac? On someone else’s server? Can you back it up yourself, or are you trusting a company that might get acquired next quarter?

✓ How long has it been around?

New software is exciting. Software that’s been stable for 20 years is reliable. When it comes to your billing records, I’ll take reliable.

✓ Who answers the phone?

When something goes wrong, do you get a chatbot? A ticket queue? Or the person who actually built the software?


The Real Cost of Cross-Platform Compromises

“But the features are the same!”

Sure. And a Kia has four wheels and an engine, just like a BMW. The spec sheet doesn’t capture what it feels like to use something every day.

Time adds up.

That extra half-second of lag, multiplied by thousands of interactions per year. That awkward interface that never quite clicks. The workarounds you develop because the software doesn’t work the way your Mac does.

Attorneys bill their time in six-minute increments because every minute matters. But somehow they accept software that wastes their time by design.


You Chose Your Platform. Own It.

When you bought a Mac, you made a statement about the tools you want to use. You chose quality over lowest-common-denominator. You chose an ecosystem that values user experience.

Your billing software should reflect that same choice.

Don’t accept “Mac compatible” when you can have Mac-native.

Don’t accept cloud-dependent when you can have local-first.

Don’t accept software that fights your workflow when you can have software that enhances it.


TimeNet Law: Built for Mac, By Someone Who Gets It

I started building TimeNet Law in 2003 because Mac-using attorneys had been abandoned by the industry. Twenty-two years later, I’m still here, still building native Mac software, still answering my own support line, still obsessing over the details that make software feel right.

No Electron. No browser wrappers. No subscription traps.

Just clean, native Mac software that does exactly what you need and gets out of your way.

Download the free trial and feel the difference.


P.S. If you’re currently using Windows-first software on your Mac and it’s driving you crazy, I wrote a guide on switching. Your sanity is worth more than switching costs.

Categories
Industry Analysis

Why Attorneys Are Leaving MyCase in 2026

First, my wife read MyCase’s privacy policy. And for three hours, I heard her make sounds no human being should make.

After her fifth, “This can’t be legal! How is this allowed?!” outburst, I finally had to dig in myself. So, I read MyCase’s privacy policy so you don’t have to.

Boy I wish I hadn’t.

What I found should concern every attorney who takes client confidentiality seriously.

What’s Actually in Their Privacy Policy

Let’s start with the quote that matters most:

“Information submitted to our AI-powered tools… may include Sensitive Personal Information, including information relating to the cases or financial information of our Customers’ clients.”

Your client’s secrets. Their case details. Their financial information. All flowing through third-party AI systems.

That’s not speculation. That’s their own disclosure.

It Gets Worse

Cross-context behavioral advertising. MyCase shares your data with advertising partners who track you across every website you visit. Your billing software is following you around the internet.

Psychological profiling. They build “inferences” about you including preferences, characteristics, behavior, attitudes, and aptitudes. For “advertising purposes.”

Medical information. Their privacy policy explicitly mentions collecting health records. Why does billing software need your medical history?

The minors admission. From their California disclosure: “We do not have actual knowledge that we have sold or shared the personal information of children under the age of 16.”

Read that carefully. They’re not saying they don’t sell data. They’re saying they don’t know if any of it belongs to minors.

The Attorney-Client Privilege Problem

Here’s the question every MyCase user should ask: Can you look your client in the eye and tell them their case details are being fed to AI models and shared with advertising partners?

California Bar ethics opinions are clear that attorneys must take reasonable steps to protect client confidentiality when using technology. “We didn’t read the privacy policy” isn’t a defense.

This isn’t just a California problem. State bar associations across the country are rolling out updated guidance on technology competence and data handling. The message is consistent: you have an affirmative duty to understand what your software does with client information.

ABA Model Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure of client data. Reasonable efforts. If your practice management software is routing client details through third-party AI models and sharing data with advertising networks, and you knew about it (or should have known, because it was disclosed in the privacy policy you agreed to), that is a potential failure of your ethical duty.

This isn’t theoretical anymore. Ethics complaints related to technology negligence are on the rise. Bar disciplinary boards are scrutinizing how attorneys handle digital client data. The question isn’t whether you use technology. Every attorney does. The question is whether you chose technology that protects your clients or technology that profits from them. I’ve watched firms scramble after a complaint gets filed. Don’t wait for that to be you.

There’s Another Way

TimeNet Law exists because this doesn’t have to be the trade-off.

Your data never leaves your machine. Not to our servers. Not to AI models. Not to “advertising partners.” It stays on your Mac, period. Your practice, completely free from cloud dependency.

No tracking. No cookies. No behavioral profiling. No cross-site stalking. We don’t even have analytics on the app.

Native Mac. Not a web app harvesting every keystroke. Actual macOS software that respects your privacy and your workflow.

One owner for 20+ years. Not a VC portfolio company optimizing for the next acquisition. Just software that works, built by someone who uses it every day. One price, and it’s yours forever.

If you’ve been searching for legal billing software built for Mac that doesn’t treat your client data as a revenue stream, you just found it.

Making the Switch

The hardest part of leaving MyCase isn’t the software transition. It’s admitting you should have read the privacy policy sooner.

The actual migration? Most attorneys are up and running in an afternoon. Export your matters, import to TimeNet Law, and never worry about where your client data is going again.

Here’s what the migration actually looks like. You export your matters and client data from MyCase. You import them into TimeNet Law. You verify everything landed correctly. That’s it. No weeklong onboarding process. No consultant fees. No “implementation specialist” on a three-week waiting list.

You don’t even have to switch everything at once. Start with new matters in TimeNet Law. Keep your existing cases in MyCase until they close out. There’s no pressure to rip the band-aid off in one move. Transition at whatever pace makes sense for your practice.

What changes immediately is the peace of mind. Your billing data stops feeding someone else’s AI model. Your client information stops flowing to advertising partners. You go from hoping your software company does the right thing to knowing your data never leaves your machine. When you’re ready to find the right law firm software for your practice, the answer is the one that keeps your data yours.

Ready to take back control of your client data?

Try TimeNet Law free. Your data stays yours.


TimeNet Law is legal billing software built exclusively for Mac. Local-first. Privacy-first. No cloud required. No data harvesting. Ever.

Sources:

]]>

Categories
Industry Analysis Privacy & Security

LexisNexis Confirms Massive Data Breach: 400,000 User Profiles, Federal Judge Accounts, and a Password Called “Lexis1234”

LexisNexis has confirmed to BleepingComputer that hackers breached its servers and accessed customer and business information. The threat actor, an extortion group called FulcrumSec, has already leaked 2 GB of stolen files across underground forums.

This is not speculation. This is not a claim under investigation. LexisNexis Legal & Professional — the global legal information division of RELX Group, used by lawyers, corporations, and governments in over 150 countries — has acknowledged the breach.

What Happened

According to FulcrumSec and confirmed details from LexisNexis, the attackers gained initial access on February 24, 2026 by exploiting the React2Shell vulnerability in an unpatched React frontend application — a flaw that had reportedly been left unaddressed for months.

From there, they leveraged a compromised ECS task container that had been granted read access to the production Redshift data warehouse, 17 VPC databases, AWS Secrets Manager, and the Qualtrics survey platform. One container role. Access to everything.

What Was Stolen

The alleged exfiltration is staggering:

  • 2.04 GB of structured data spanning 536 Redshift tables and over 430 VPC database tables
  • 53 AWS Secrets Manager secrets in plaintext, including production database master passwords, tokens, and API keys
  • 3.9 million database records from the Enterprise Data Warehouse
  • ~400,000 cloud user profiles containing full names, email addresses, phone numbers, and job functions
  • 118 government user accounts, including federal judges, DOJ attorneys, SEC staff, and federal court law clerks
  • 21,042 customer account records with commercial relationships, active product subscriptions, and pricing tiers
  • 5,582 attorney survey respondents with substantive product feedback and IP addresses
  • 45 employee password hashes, alongside cleartext customer passwords found stored in IT support ticket subject lines
  • Complete VPC infrastructure mapping, 10,000 IT incident tickets, and 10,000 internal engineering defect records

Read that last bullet again. The attackers did not just steal data. They walked away with the complete blueprint of LexisNexis’s cloud infrastructure and a decade of internal engineering problems.

The Password Was “Lexis1234”

According to Cyber Security News, FulcrumSec specifically called out LexisNexis’s security posture, noting that the RDS master password was set to “Lexis1234” and that a single ECS task role held read access to every secret in the AWS account — including the production database master credential.

Let that sink in. The company that stores legal research data for federal judges, DOJ attorneys, and SEC staff protected their production database with a password that would fail a first-year computer science assignment.

LexisNexis Says It Is Not That Bad

In their statement to BleepingComputer, LexisNexis characterized the stolen data as “mostly legacy, deprecated data from prior to 2020” and emphasized that the breach did not include Social Security numbers, financial information, active passwords, or customer search queries.

That framing deserves scrutiny.

Even if the user profile data is from before 2020, the 53 plaintext AWS secrets, the complete infrastructure map, and the 10,000 internal defect records are not “legacy.” Those are operational intelligence. The kind of information that makes the next breach easier.

This Is Their Second Breach in Fifteen Months

In December 2024, LexisNexis disclosed a separate breach in which an unauthorized party compromised a corporate account and stole personal data — including Social Security numbers — belonging to 364,000 customers.

FulcrumSec explicitly noted that this new breach is unrelated to the 2024 incident. Two different threat actors. Two different attack vectors. Two breaches. Fifteen months apart.

This is not a one-time failure. This is a pattern.

The “Trusted Vendor” Trap

LexisNexis is not some fly-by-night startup. It is a subsidiary of RELX, a $90 billion publicly traded corporation. It serves the most security-sensitive professionals on earth — judges, prosecutors, intelligence analysts, law enforcement. When your vendor list says “LexisNexis,” nobody questions the security posture.

That is precisely the problem.

Every law firm, every government agency, every corporation that handed data to LexisNexis made a trust decision. They trusted that a company of that size, serving clients of that sensitivity, would have security practices to match. They trusted that “enterprise-grade” meant something. They trusted that a company managing 400,000 user profiles with .gov email addresses would not protect its production database with “Lexis1234.”

The trust was misplaced. And the people who made that trust decision had no way to verify it. That is the trap.

What This Means for Law Firms

If you are a solo practitioner or small firm, this breach should change how you think about where your data lives.

The 21,042 customer account records included commercial relationships, active product subscriptions, and pricing tiers. If your firm is a LexisNexis customer, attackers now know what you pay for, what products you use, and how your business relationship is structured. That is competitive intelligence in the wrong hands.

The 118 government accounts represent an even more serious concern. Federal judges and DOJ attorneys use LexisNexis for legal research. Their usage patterns, search queries (even if LexisNexis claims those were not accessed), and contact information are now in the wild. The national security implications are not theoretical.

But beyond the specifics of this breach, the lesson is structural: when you hand your data to a cloud vendor, you are outsourcing your security to their weakest link. And their weakest link, in this case, was a container with a password a teenager could guess. It’s yet another reason to break free from cloud dependency entirely.

What You Can Do Right Now

If your firm uses LexisNexis in any capacity, here are concrete steps you should take today — not next week, today.

1. Check your inbox. LexisNexis has confirmed they are notifying impacted current and previous customers. If you have not received a notification, do not assume you are clear. The breach included 400,000 user profiles and 21,042 customer account records. Contact LexisNexis directly and ask whether your firm’s data was included in the exfiltration.

2. Change every password immediately. If you use the same password for LexisNexis that you use anywhere else — email, banking, court filing systems, bar association portals — change all of them now. The stolen data included employee password hashes and cleartext customer passwords pulled from IT ticket subject lines. If your password was ever typed into a LexisNexis support request, assume it is compromised.

3. Enable multi-factor authentication everywhere. Not just LexisNexis. Every legal research platform, every court filing system, every cloud service your firm touches. A stolen password with MFA enabled is a locked door. A stolen password without it is an open one.

4. Check Have I Been Pwned. Enter every email address your firm uses — yours, your associates, your paralegals, your admin staff. This service tracks breached credentials across known data dumps. If your LexisNexis login email appears in a new breach dataset, you will know.

5. Rotate any API keys or integrations. If your firm has any automated integrations with LexisNexis — practice management software pulling research data, document assembly tools, anything that authenticates via API — rotate those credentials immediately. The attackers exfiltrated 53 AWS secrets in plaintext. Any integration keys stored in the same infrastructure should be treated as burned.

6. Watch for targeted phishing. This is the one that will catch people. The attackers now have firm names, contact information, product subscriptions, and pricing data for over 21,000 customer accounts. Expect highly convincing phishing emails that reference your actual LexisNexis subscription, your actual products, your actual account details. An email that says “Your LexisNexis subscription requires immediate action” is going to look very real because the attacker knows you actually have a subscription. Train your staff. Verify every email by calling LexisNexis directly. Do not click links.

7. Review your ethical obligations. Depending on your jurisdiction, you may have a duty to assess whether client-related information was exposed through your vendor relationships. The ABA Model Rules of Professional Conduct — particularly Rules 1.1 (Competence), 1.6 (Confidentiality), and 5.3 (Supervision) — increasingly encompass technology competence and vendor oversight. If your client data transited through a LexisNexis system, document your assessment and any remedial steps taken. If there is any possibility that client confidential information was exposed, consult your state bar’s ethics hotline.

8. Audit every vendor that holds your data. Make a list. Every cloud service, every SaaS platform, every research tool. For each one, ask: what data do they have? Where is it stored? What happens if they get breached? If you cannot answer those questions, you have the same problem you had with LexisNexis — you just do not know it yet.

None of this is optional. The breach already happened. The data is already in the wild. The only question now is whether you move before something lands in your inbox that you cannot undo.

The Alternative Exists

There is another model. Software that keeps your data on your machines, in your folders, under your control. Software where a breach of the vendor does not mean a breach of your clients. Software where your security posture is your own — not dependent on whether a Fortune 500 company remembered to patch a React app or change a default password.

That model is not theoretical. It is shipping. And you can own it outright. And it does not require your trust. It requires your files to never leave your hands in the first place.

The LexisNexis breach is not an anomaly. It is the logical consequence of an industry that decided convenience was worth more than sovereignty. For the firms paying attention, it is also an invitation to choose differently.


Sources:

Categories
Legal Tech & AI

Law Firms Want AI. They Just Can’t Use Yours.

The legal industry has an AI problem. And it’s not what the vendors are telling you.

Every legal tech company is racing to add AI features. Document review. Contract analysis. Research assistance. The demos are impressive. The productivity gains are real.

But there’s a problem nobody wants to talk about:

Most law firms can’t actually use any of it.

The Compliance Wall

Here’s what happens when a law firm evaluates AI-powered legal tech:

  1. Vendor shows impressive demo
  2. Partner gets excited about efficiency gains
  3. IT and compliance review the architecture
  4. They discover client documents must be uploaded to vendor’s cloud servers
  5. Deal dies

This isn’t paranoia. This is lawyers understanding liability.

When you upload a client’s confidential merger documents to a third-party server for “AI analysis,” you’ve created a chain of custody problem. You’ve introduced a data breach vector you can’t control. You’ve potentially violated the confidentiality obligations you swore to uphold.

The bar doesn’t care how good the AI is. They care whether you protected client data.

The “Enterprise Security” Lie

Cloud legal tech vendors love to wave their SOC 2 certifications. Their “bank-level encryption.” Their “enterprise-grade security.”

Ask them these questions:

  • Where exactly is my client’s data stored?
  • Who at your company can access it?
  • Are you using client data to train your AI models?
  • If you’re breached, how many other firms’ data is exposed alongside mine?

Watch them squirm.

The uncomfortable truth: when you use cloud-based AI legal tools, you’re trusting a vendor’s security team more than your own. You’re betting your malpractice exposure on their infrastructure. You’re hoping the target painted on their servers (containing data from thousands of law firms) doesn’t attract the wrong attention.

The Cost of Waiting

Here’s the math that keeps managing partners up at night:

A 4-attorney firm with proper AI automation saves roughly $150,000-200,000 annually in administrative overhead. Document review that took hours takes minutes. Time entries that fell through the cracks get captured. Invoice errors get caught before clients see them.

Every month you wait for “compliant AI” is $15,000+ in efficiency you’re leaving on the table.

Meanwhile, somewhere, a competitor is figuring this out. They’re getting the productivity gains while you’re stuck in evaluation paralysis.

Here’s the irony nobody talks about. Most firms are already paying for cloud subscriptions that include AI features. Features they can’t safely turn on. You’re paying for the bullet point on the vendor’s website, not for actual productivity in your office.

Think about what that costs. At $50 to $150 per user per month, a 10-attorney firm is spending $6,000 to $18,000 a year on software that creates compliance risk the moment you use its flagship feature. That’s money going toward tools you’re actively afraid to use. You could invest that budget in invoicing tools built for Mac that actually work without uploading client data anywhere.

The firms pulling ahead right now aren’t waiting for cloud vendors to solve the privacy problem. They’re finding local-first alternatives. Software that runs AI on their own hardware, keeps data in their own office, and never asks them to choose between efficiency and ethics.

The Answer Was Always Local

What if the AI never left your building?

The same AI models that power cloud services can run locally on modern hardware. Your Mac. Your server. Your office.

  • Document analysis, on your machine
  • Contract review, on your machine
  • Time tracking intelligence, on your machine
  • Invoice anomaly detection, on your machine

And this isn’t some compromise where you sacrifice speed for privacy. Modern Mac hardware, especially Apple’s M-series chips, is powerful enough to run sophisticated AI models right on your desk. The same kinds of models that power cloud services can run locally with performance that would have been unthinkable three years ago. If your firm already uses Mac-native legal billing software, you’re already on the right hardware.

No uploads. No third-party servers. No chain of custody problems.

When a client asks “where does my data go when you use AI?” You have a real answer:

“Nowhere. It never leaves our office.”

The New Standard

The firms that figure this out first don’t just save money. They gain a competitive advantage that compounds.

While competitors are still uploading sensitive documents to cloud AI or avoiding the technology entirely, these firms are:

  • Reviewing documents faster
  • Catching more billable time
  • Sending cleaner invoices
  • Actually using AI, without the compliance nightmare

The question isn’t whether AI will transform legal practice. That’s already decided.

The question is whether you’ll be using AI that respects attorney-client privilege, or AI that treats your client’s data like training fodder.

Your clients are trusting you with their most sensitive information. Choose tools that honor that trust.


TimeNet Law is practice management software built for attorneys who take data privacy seriously. All data stays on your hardware. No cloud. No subscriptions. No compromises.

Learn how local AI actually works →

Categories
Legal Tech & AI

BigLaw Gets AI Efficiency. Their Clients Get Higher Bills.

Law firms are using AI to work faster. Their clients are getting charged the same, or more. Logic tells us this should work the other way around. This broken equation only works for the one sending the invoice.

So what’s going on?


This week, Richard Tromans at Artificial Lawyer reported something that should make every small firm owner sit up straight.

At a conference in Stockholm, a senior in-house lawyer said it plainly: despite all the press releases about law firms adopting AI, “We get nothing. They haven’t changed and probably next year the same work will cost even more.”

The GC went on to say they’d probably need to have “the conversation” with their outside counsel this year. The conversation where they ask: if you’re using AI to do this work faster, why am I paying the same hourly rate?

The answer, of course, is simple: because they can.


The BigLaw AI Arbitrage

Here’s what’s actually happening at large law firms:

  1. They buy expensive AI tools
  2. They write press releases about “innovation” and “efficiency”
  3. Associates use the tools to do work faster
  4. The firm pockets the efficiency gains
  5. Client bills stay the same (or go up)

This isn’t a conspiracy. It’s just business. Law firms aren’t charities. If they can do the same work in half the time but charge the same amount, they will. The billable hour model practically demands it.

Why would a firm reduce fees when the client has already accepted the price? Why would they pass along savings when they can keep them as profit?

The answer is: they won’t. Not until clients force them to.


The Small Firm Advantage Nobody’s Talking About

Here’s what makes this story interesting for attorneys running their own practices:

When you adopt AI in a small firm, YOU get the efficiency gains.

There’s no partner committee deciding whether to pass the savings along. There’s no billionaire-funded PE firm demanding year-over-year revenue growth. There’s just you, doing better work in less time, and deciding what to do with those extra hours.

You could:

  • Take on more clients without burning out
  • Offer more competitive fixed-fee pricing
  • Spend more time on the complex work that actually requires a lawyer
  • Go home at 5pm for once

The same technology that BigLaw uses to pad margins, small firms can use to outcompete on price while maintaining quality.

That’s a structural advantage that didn’t exist five years ago.


The Sea Change Is Coming

What Tromans reported from Stockholm wasn’t a one-off complaint. It was a preview of what’s about to happen across the industry.

In-house legal teams are using AI now. Real usage, not pilot programs. They’re seeing firsthand what can be done. The same contract review that used to take a week now takes a day. The same research memo that justified twenty hours of associate time now takes two.

And they’re asking: if we can do this, why can’t our outside counsel? And if they can, why aren’t we seeing it in the bills?

The quote that stuck with me: “If they were all part of a single law firm, then that law firm would no doubt receive a prize for being a world leader in legal innovation.”

That was describing in-house teams, not law firms.

The buyers are becoming more sophisticated than the sellers. That never ends well for the sellers.


Position Yourself Now

If you’re a small firm or solo practitioner, this is your window.

While BigLaw is playing defense, trying to justify why AI efficiency shouldn’t translate to lower bills, you can play offense. You can build your practice around the new economics:

  • Fixed fees that work because your actual time investment is reasonable
  • Faster turnaround that makes clients feel prioritized
  • Competitive pricing against larger firms (who can’t match you without cannibalizing their own model)

The corporate clients complaining in Stockholm aren’t your clients. But the small business owners, the individuals, the startups who’ve been priced out of quality legal help? They’re watching this unfold too.

And they’re looking for alternatives.

We built a complete blueprint for this. Practice area pricing templates, AI efficiency math, flat fee packages with real market rates, and a step-by-step strategy for building the kind of firm that makes BigLaw irrelevant. Read the full Future-Proof Law Firm guide →


60-Second Firm Hack: The “What Would AI Do?” Audit

Pick your three most common matter types. For each one, write down:

  1. The tasks that take the most time
  2. Which of those tasks are repetitive or templatable
  3. What would change if those tasks took 10% of the current time

That third question is where the magic is. If contract review takes 10% of the time, do you charge less? Take on more clients? Bundle it into a fixed fee that feels like a steal?

The firms that answer that question first will own the next decade.


Off the Record

TimeNet Law wasn’t built for BigLaw economics. It was built for attorneys who actually want to run efficient practices, and keep the benefits.

We’re not trying to help you bill more hours. We’re trying to help you bill smarter hours, track them accurately, and get paid faster. The efficiency gains from good practice management software should flow to you, not to some PE-backed vendor’s quarterly earnings.

That’s been our philosophy for over 20 years. Nice to see the rest of the industry catching up to why it matters.

See what efficient practice management looks like →


The billable hour rewards inefficiency. AI exposes that. What you do with that information depends on which side of the invoice you’re on.

Ready to flip the equation? Build Your Future-Proof Firm →

Categories
Industry Analysis Legal Tech & AI

The Legal Tech Ground Is Shifting. Here’s What You Need to Know.

Last week, Anthropic launched a legal plugin for Claude. Legal tech stocks cratered. Meanwhile, 8am is stitching together another Frankenstein’s monster of practice management tools. If you’re feeling a little dizzy watching all this, you’re paying attention.

It’s been a wild few weeks in legal tech. And if you’re an attorney just trying to run your practice without getting caught in the crossfire, the news probably feels exhausting. Let me break down what actually matters.

The Claude Bomb

Anthropic, the company behind the Claude AI platform, just dropped a legal plugin that lets in-house counsel automate contract review, NDA triage, and compliance workflows. When they announced it, Thomson Reuters, RELX, and Wolters Kluwer stocks plummeted.

The market reaction tells you everything. For years, legal tech vendors have been wrapping foundation AI models and selling them back to you with a markup. Now the foundation model companies are cutting out the middleman. They’re going straight to the enterprise with pre-built workflows that do exactly what $50,000/year platforms do.

Is this the death of legal tech? No. But it’s a signal. The vendors who built their entire value proposition around “we’ll put AI on top of your contracts” are suddenly looking very exposed. The ones with actual proprietary data and deep subject matter expertise will survive. The ones who were just playing markup arbitrage? Not so much.

The 8am Consolidation Machine

Meanwhile, the company formerly known as AffiniPay (now rebranded as “8am”) continues its shopping spree. They already own LawPay, MyCase, CasePeer, and DocketWise. Now they’re expanding LawPay into a “complete financial management solution” that combines payments, invoicing, time tracking, expense management, and reporting.

On paper, this sounds great. One platform! Everything integrated!

In reality, you know how this works. Consolidation means different codebases stitched together by acquisition. Different teams who’ve never worked together. Different philosophies about what attorneys actually need. And eventually, inevitably, price increases to pay for all that M&A activity.

The press release uses phrases like “financial complexity and cash flow constraints have become serious operational risks for law firms.” Translation: we bought a bunch of companies and need to justify the integration costs to our investors.

What This Actually Means for Your Practice

Here’s the uncomfortable truth: most legal tech is built for investors, not attorneys. The VC playbook is simple. Buy up competitors. Raise prices. Cut support costs. Extract maximum value before the next exit.

You’ve seen this movie before. Clio’s price hikes. The endless consolidation in the practice management space. The slow degradation of support as companies scale. The features that used to be included becoming “premium add-ons.”

The AI disruption makes this even messier. Companies that spent millions acquiring AI wrappers are now watching foundation models undercut them. They’ll respond the only way they know how: raising prices on existing customers to protect margins. Meanwhile, attorneys keep paying rent on software they should own.

The Alternative Nobody Talks About

There’s another way to build legal software. You build something good. You support it directly. You don’t sell to private equity. You don’t chase growth at all costs. You just make something that works and charge a fair price for it.

It sounds almost quaint in 2026. But it’s the model TimeNet Law has followed for twenty years. Same owner. Same developer. Same phone number when you need help.

No investor pressure to raise prices. No integration chaos from acquisition sprees. No wondering whether your software will exist in its current form next year. Just software that does what it’s supposed to do, built by someone who actually answers support calls.

That’s not a sales pitch. It’s just how things should work.

⚡ 60-Second Firm Hack: The Monday Morning Client Pulse

Before you open email Monday morning, spend 60 seconds scanning your open matters. Pick three clients you haven’t heard from in two weeks. Send each a one-line email: “Just checking in. Anything you need from me this week?”

Three emails. 60 seconds. You’ll be amazed how often this simple touchpoint uncovers forgotten questions, prevented scope creep, or simply reminded a client that you’re thinking about their matter.

The best firms don’t wait for clients to reach out. They stay one step ahead.


The legal tech landscape is going to keep shifting. AI will keep disrupting. Consolidation will continue. Prices will rise. Support will get worse at companies chasing scale.

Your job isn’t to predict all of it. Your job is to pick tools built by people who share your values, who will still be here in five years, and who won’t hold your data hostage when you need to move on.

That’s not complicated. It’s just rare.


Want the Inside Track?

The tips in this post are just the beginning. Sunday Brief is my private newsletter where attorneys get the must-have tips, secrets, and news that don’t make it to the blog.

No fluff. No sales pitches. Just the insider knowledge that helps you run a better firm.


Sign up to get more straight talk about legal tech, billing, and building a practice that actually works.

Categories
Legal Tech & AI Privacy & Security

Microsoft Copilot Read Your Confidential Emails for a Month. Lawyers Should Be Paying Attention.

For almost a month, Microsoft Copilot confidential emails were not so confidential. Microsoft’s AI assistant was reading and summarizing emails marked “confidential” before anyone noticed. If your law firm uses Microsoft 365, you should be paying very close attention right now.


On February 18, Bleeping Computer reported that Microsoft 365 Copilot Chat had been quietly summarizing confidential emails since January 21. Not just regular emails. Emails with sensitivity labels applied. Emails protected by data loss prevention (DLP) policies that were explicitly configured to prevent exactly this from happening.

Microsoft confirmed it. Their own service alert (tracked as CW1226324) stated that “users’ email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.”

The bug affected the Copilot “work tab” chat feature, which was pulling content from users’ Sent Items and Drafts folders and summarizing it on demand, regardless of whether those messages were supposed to be locked down.

For almost a month. In silence.


How the Microsoft Copilot Confidential Emails Bug Affects Law Firms

Let’s be direct about what happened here.

If your law firm runs Microsoft 365 with Copilot Chat enabled, and you had confidential client communications sitting in your Sent Items or Drafts folders (which of course you did), Microsoft’s AI may have been reading and summarizing those communications. Even if you did everything right. Even if you applied sensitivity labels. Even if you configured DLP policies to prevent automated access.

Your controls were bypassed by a “code issue.”

Microsoft’s official response? “This did not provide anyone access to information they weren’t already authorized to see.”

That’s technically true, and it completely misses the point. The concern isn’t that a stranger accessed the emails. The concern is that an AI system ingested, processed, and summarized privileged communications that were explicitly marked as off-limits. Content that was supposed to be invisible to automated systems was being actively read, analyzed, and presented in chat summaries.

For attorneys, this isn’t a minor configuration hiccup. This is a potential breach of the duty of confidentiality.


The Privilege Problem Nobody Is Talking About

Here’s where it gets really uncomfortable.

Just eight days before the Copilot bug was publicly reported, a federal judge in United States v. Heppner ruled that AI is not your co-counsel when it comes to attorney-client privilege. The court held that sharing information with consumer-grade AI tools can destroy privilege entirely, because those tools are third-party services with no confidentiality obligation.

Now combine that with what Microsoft just admitted.

You applied confidentiality labels to your emails. You set up DLP policies. You did what Microsoft told you to do to keep privileged content away from AI. And Microsoft’s own AI read it anyway. For weeks.

The Heppner decision says sharing privileged information with AI can waive privilege. Microsoft’s bug means privileged information may have been shared with AI without your knowledge or consent.

Ask yourself: if opposing counsel in active litigation discovered that your firm’s privileged communications had been processed by Microsoft’s AI for a month, what motion do you think they’d file?


The NHS Was Affected. The European Parliament Pulled the Plug.

This wasn’t some niche edge case affecting a handful of users.

The BBC reported that the bug was logged on the NHS’s internal IT support dashboard in England. The same week, the European Parliament’s IT department disabled built-in AI features on staff devices entirely, citing concerns that AI tools could transmit confidential data to external cloud servers.

Two of the world’s most security-conscious organizations either got burned or decided the risk wasn’t worth taking.

Meanwhile, Microsoft hasn’t disclosed how many organizations were affected. They described the incident as an “advisory,” a classification typically used for issues with “limited scope or impact.” They have not provided a final timeline for full remediation.


The Experts Are Not Sugarcoating It

Nader Henein, a data protection and AI governance analyst at Gartner, told the BBC this kind of failure is “unavoidable” given the speed at which companies push new AI features to market.

“Under normal circumstances, organisations would simply switch off the feature and wait till governance caught up. Unfortunately the amount of pressure caused by the torrent of unsubstantiated AI hype makes that near-impossible.”

Dr. Ilia Kolochenko, CEO of ImmuniWeb and a Fellow at the European Law Institute, was even more blunt in his assessment to Cybernews:

“With the rapid proliferation of Agentic AI and AI-powered plugins for traditional software, incidents like this one will likely surge in 2026, possibly becoming the most frequent type of security incident at both large and small companies around the globe.”

Professor Alan Woodward of the University of Surrey called it a lesson in why AI tools must be “private-by-design” from the start, not patched after the damage is done.

And here’s the line that should keep every managing partner up at night, from Dr. Kolochenko:

“Every day, tons of sensitive personal data are shared with LLMs around the globe without any precautions. Even governmental agencies of developed countries are exposed to this risk because of inadequate or simply missing governance of AI at workplace.”


A Pattern, Not an Incident

If you’ve been following this blog, this story should sound familiar.

Two weeks ago, we published our investigation into the law firm data broker pipeline, documenting how legal tech SaaS platforms funnel attorney data to third-party brokers. Last week, we covered how Claude AI hallucinated an entire lease agreement using fragments of real data from its training set.

And now Microsoft’s own enterprise AI is bypassing the very security controls it was designed to respect.

This isn’t a series of unrelated incidents. This is a pattern. The legal tech stack that law firms depend on is leaking from every direction: through data brokers, through AI hallucinations, and now through the tools that are supposed to protect your confidential communications in the first place.


What Your Firm Should Do About Microsoft Copilot Confidential Emails

If your firm uses Microsoft 365 with Copilot Chat enabled:

  1. Verify the patch is deployed. Microsoft says a configuration update has been pushed worldwide, but they also said the rollout is still “in progress” for some “complex service environments.” Don’t assume you’re covered. Confirm it.
  2. Audit what Copilot accessed. Determine which users had Copilot Chat active during the January 21 to mid-February window. Identify any confidential or privileged communications that may have been processed.
  3. Review your DLP policies. If your data loss prevention rules didn’t stop an AI tool from reading labeled content, you need to understand why and what else might slip through.
  4. Assess your ethical obligations. Depending on your jurisdiction, you may have disclosure requirements when privileged client communications are potentially compromised. Talk to your ethics counsel.
  5. Reconsider the AI defaults. The European Parliament disabled AI features entirely until governance catches up. That’s not paranoia. That’s prudent risk management. Better yet, consider tools that run entirely on your Mac, free from cloud dependency.

The Bottom Line on Microsoft Copilot Confidential Emails

Microsoft wants you to feel reassured. The bug is fixed. Access controls were intact. Nobody saw anything they weren’t supposed to.

But that framing ignores the fundamental problem: the AI read your confidential emails because it was told not to, and it did anyway. The controls you were promised would work, didn’t. For almost a month.

In a profession built on confidentiality, “oops, the AI read your privileged emails” is not a minor software bug. It’s a crisis of trust in the tools we’ve been told are safe to use. When you don’t own your software, you’re at the mercy of whoever does.

And based on what every expert quoted in this story is saying, this won’t be the last time it happens.


Have questions about how AI tools interact with your firm’s confidential data? Get in touch. We’re tracking every major AI security incident affecting law firms and publishing what we find.

Categories
Legal Tech & AI Privacy & Security

Claude Just Hallucinated a Complete Lease Agreement With Real Names and Addresses. Lawyers Are Freaking Out.

A Reddit post went viral this week when an attorney claimed Claude AI generated a complete commercial lease, with a real company, real address, and real contact information. What happened next should concern every lawyer using cloud-based AI.


Two days ago, a post on Reddit’s r/ClaudeAI forum hit 3,600 upvotes and 216 comments. The title:

“Claude just gave me access to another user’s legal documents”

Here’s what happened.

A user asked Claude Cowork, Anthropic’s new AI agent that reads and edits files on your computer, to summarize a document they’d uploaded. Instead of summarizing their document, Claude started describing a completely unrelated legal document. A commercial lease agreement.

Curious, the user asked Claude to generate a PDF of this mystery document.

Claude obliged. It produced a complete commercial lease agreement between “Commercial Properties, LLC” (Landlord) and “Collective, LLC” (Tenant) for a property in Blue Hill, Maine. Dated March 15, 2025. With contact information for the property management company.

The user did what any reasonable person would do: they called the property management company.

The company was real. The address was real. The contact information worked.

But the people named in the contract? The company seemed “confused” about them. And the attorney referenced in the document? Doesn’t appear to exist.


So What Actually Happened?

After 216 comments of debate, the consensus is clear: this was a high-fidelity hallucination.

Claude didn’t “leak” another user’s document. It did something arguably more unsettling. It mashed together fragments of real information (a real company name, a real Maine address, real contact details) with fabricated names, a nonexistent attorney, and invented lease terms. Then it presented the whole thing as a coherent, professional legal document.

As one commenter put it:

“It read their legal documents during the pre-training phase, probably cause they were public on the internet. Then Claude made up portions of the rest.”

A Hacker News commenter offered another theory: the property management company likely had an improperly configured cloud storage bucket that exposed a directory of leases. Those documents got scraped, ingested into AI training data, and now live inside the model, ready to be reassembled into something that looks authentic but isn’t quite real.

The Reddit moderator bot’s summary nailed it:

“Claude is scarily good at generating realistic-looking documents by mashing up info from its vast training data (i.e., the public internet). The fact that the attorney in the document doesn’t exist is pretty much the nail in the coffin for the data leak theory.”

Another user reported the exact same phenomenon: they uploaded a work document, and Claude started describing a completely unrelated fitness training plan, with specific details about someone else’s workout routine.


Why This Should Terrify Every Attorney Using Cloud AI

Let me be direct about what this means for lawyers.

1. Your Documents May Already Be Training Data

That commercial lease from Blue Hill, Maine didn’t materialize from thin air. Real company information ended up inside Claude’s training data. Whether it was scraped from a misconfigured server, indexed from a public webpage, or harvested through some other vector, the result is the same.

Real legal documents, with real names and real addresses, are inside these AI models.

Now think about your own practice. How many of your documents have touched cloud services? How many have been uploaded to AI tools by associates doing “quick research”? How many live on cloud platforms whose privacy policies permit data collection and sharing?

Every document that enters the cloud ecosystem is a candidate for ending up exactly where that Maine lease did: inside an AI model, waiting to be reassembled and presented to a stranger.

2. Hallucination + Real Data = A New Kind of Breach

This incident reveals a category of risk that didn’t exist two years ago.

Claude didn’t reproduce the lease verbatim. That would be a straightforward data leak, and Anthropic’s architecture is designed to prevent it. Instead, it created something more insidious: a document realistic enough to fool someone into calling the company named in it.

Imagine this scenario with your clients:

An opposing counsel asks an AI to draft a sample lease agreement for a property in your client’s city. The AI, trained on scraped data that included your client’s actual lease, generates a document with your client’s real address, their real landlord’s name, and plausible (but slightly wrong) financial terms.

That’s not a “leak” by any technical definition. It’s a hallucination. But it just exposed your client’s business relationships to a stranger.

Good luck explaining that distinction to your malpractice insurer.

3. “It’s Impossible” Isn’t Reassuring Anymore

Several commenters rushed to defend the technology:

“This is just more AI hysteria. I can’t speak to your intentions but what I can say is you have definitely not received someone else’s document. It’s impossible given Anthropic’s security disclosures.”

Maybe. Anthropic maintains segregated storage for each user session. Cross-user data leaks should be architecturally impossible.

But here’s the thing: it doesn’t matter whether this was a “real” leak or a hallucination. From a legal ethics standpoint, the outcome is identical. Real client information (company names, addresses, business relationships) surfaced in a context where it shouldn’t have. The mechanism is academic. The exposure is real.

And as one Hacker News commenter noted:

“Even in single-tenant deployments, if the vendor continues to manage the data and has AWS KMS access, a substantially motivated attorney could win the compulsion.”

4. It’s Not Just Accidental. Trade Secret Theft Is Surging.

While Reddit was debating hallucinations, the Wall Street Journal published a piece that should have landed like a bomb in every law firm’s inbox: federal trade secrets cases hit 1,500 last year, up 20% from the previous year and the highest figure in at least a decade.

Google alone has had three high-profile trade secret thefts in recent years. A former software engineer was convicted of stealing AI chip secrets for China, marking the first federal conviction on economic espionage charges related to AI. Apple is suing former engineers over Apple Watch and Vision Pro secrets. Elon Musk’s xAI is suing a former engineer who allegedly stole Grok chatbot secrets before joining a competitor.

The kicker? Google’s VP of Security Engineering told the Journal:

“Those open environments will become more constrained.”

Even Google, the company that built its culture on open information sharing, is locking things down because the threat model changed.

And that’s intentional theft by insiders with access. The Claude hallucination story is about unintentional exposure through training data. Put those together and you get a picture of sensitive information leaking from every direction at once: stolen by bad actors on one side, absorbed into AI models and reassembled for strangers on the other.

Your clients’ data doesn’t need to be targeted to be exposed. It just needs to exist in the cloud.


The Thread Nobody Can Stop Reading

What made this Reddit post blow up wasn’t the technical debate. It was the fear.

Scroll through the comments and you’ll see it: lawyers (and people who work with lawyers) realizing in real time that their confidentiality assumptions might be wrong.

Some highlights:

A user who had the same experience:

“I uploaded a work-related document and Claude started commenting on it as if it were a fitness training plan… It kept talking about a workout plan even though the document clearly had nothing to do with that.”

The pragmatist:

“How do you call this ‘gave me access’ and then say he generated the PDF, so what is it? Did he give you a document from another user or did he just generate a PDF like any other model can do? I can make it generate 100 of those.”

And the inevitable joke:

“Generate me 10 social security numbers and bank wiring details. Make no mistakes.”

The humor masks the anxiety. Because everyone in that thread knows the real question isn’t “did Claude leak a document?” It’s: “What happens when the document it hallucinates contains my client’s information?”


The Heppner Connection

This incident arrives two weeks after Judge Rakoff ruled that documents generated through Claude aren’t protected by attorney-client privilege. His reasoning was straightforward: Anthropic’s privacy policy permits data collection, model training, and disclosure to authorities. No expectation of confidentiality means no privilege protection.

Now connect the dots:

  1. Real legal information ends up in AI training data (the Maine lease proves this)
  2. AI models reassemble that information into realistic-looking documents (the hallucination proves this)
  3. Nothing you generate through cloud AI is privileged (Heppner proves this)
  4. Trade secret theft via technology is at an all-time high (the WSJ data proves this)

That’s not four separate problems. That’s one pipeline, and your client data is flowing through it.


The Architecture Question (Again)

I keep coming back to the same point because the industry keeps proving it right:

Where your data lives determines how safe it is.

When a commercial lease from Blue Hill, Maine ends up inside an AI model, reassembled with real company names but fake attorneys, that’s a cloud architecture problem. The document was in the cloud. It got scraped. Now it’s everywhere.

When you process client documents through cloud-based AI tools, you’re adding your data to the same pipeline. Maybe Anthropic won’t train on it. Maybe their privacy policy protects you. Maybe the segregated storage works perfectly.

That’s a lot of “maybes” for something covered by Rule 1.6.

Software that runs locally on your machine doesn’t have this problem. Not because local software is smarter, or more secure in some abstract sense, but because the data never enters the pipeline in the first place.

No cloud server to scrape. No training data to contaminate. No hallucinated document containing your client’s real address showing up on a stranger’s screen.

That’s not a feature. It’s physics.


What to Do Right Now

Audit Your AI Shadow Usage

Your associates are using AI. Probably on client matters. Probably without telling you. Ask them directly: “Have you ever uploaded a client document to ChatGPT, Claude, or any AI tool?” The answer will be uncomfortable.

Google Your Firm

Search your firm name, your clients’ names, and your address in combination with terms like “lease agreement,” “contract,” or “legal document.” See what’s publicly indexed. If a scraper can find it, an AI model may already contain it.

Read the Privacy Policy

Before you put another document into any cloud service, read that vendor’s privacy policy. All of it. Look for: “may use data to improve our services,” “may share with service providers,” “may disclose in response to legal process.” If you find those phrases, your data isn’t as private as you think.

Consider Your Architecture

The simplest way to keep your data out of AI training sets? Don’t put it in the cloud. Local-first software keeps your files on hardware you control. No third-party servers. No training pipelines. No hallucinated leases with your client’s name on them.


The Bottom Line

Claude didn’t leak a document this week. It did something that might be worse: it proved that real legal information (company names, addresses, business relationships) lives inside AI models, ready to be recombined and presented to anyone who asks.

Meanwhile, trade secret theft is hitting record highs, the courts are stripping privilege from AI-generated documents, and even Google is admitting that open environments need to be locked down.

The Maine property management company got a confusing phone call from a stranger who’d never seen their actual lease. Next time, it could be your client’s information surfacing in someone else’s AI session.

The question isn’t whether AI is useful for lawyers. It is. The question is whether you trust someone else’s cloud server to keep your client’s secrets — or whether it’s time to break free from that dependency entirely.

Three thousand lawyers on Reddit just watched one answer to that question. It wasn’t reassuring.


Perry Fjellman is the developer of TimeNet Law, a Mac-native legal practice management application that keeps your data where it belongs: on your computer. Because the best way to prevent your data from being hallucinated is to never upload it in the first place.

See how local-first practice management works →

Or get the Sunday Brief, our newsletter for attorneys who want the real story on legal tech, without the corporate spin.

Subscribe to Sunday Brief →

Categories
Industry Analysis Privacy & Security

Your Law Firm’s Data Is For Sale. Here’s the Proof.

Every now and then, my wife helps me clear out my spam-riddled email inboxes. The ones overflowing with pitches from law firm data brokers. It’s something she enjoys doing (bless her, I can’t stand it), and sometimes she finds something important. Today, she did it again.

While sweeping up the mess inside my email, she mentioned something she’s said many times before. “You got another one of these!” She showed me. A familiar template of an email I get constantly. I almost always just junk them. Sometimes I send a frustrated reply. But I never think twice about them.

Until today. Today, I decided to investigate just how deep the law firm data broker problem really goes.

Because every week — sometimes every day — I get emails like this:

“Hi, I hope this message finds you well. My name is Dorothy Gale, and I have some suggestions that could quickly boost your email marketing efforts. Would you be interested in purchasing a verified list of Legal Practice Management Software Users?”

Email from data broker offering verified lists of legal software users including Clio, Smokeball, MyCase
One of over 2,218 data broker emails received since 2017. Names and personal details from all major cloud legal platforms, for sale to anyone.

The sender is using a fake name from an Outlook burner account. The email lists every major cloud-based legal software platform by name: Clio, Smokeball, MyCase, PracticePanther, and a dozen others, and offers to sell their users’ personal data: I’m talking names, direct emails, phone numbers, mailing addresses, firm revenue, salaries, decision makers, employee counts, and more.

This isn’t a one-off. I’ve received over 2,218 of these emails since 2017. And the number grows every single year.

Year Broker Emails Received
2019 143
2020 217
2021 262
2022 297
2023 384
2024 416
2025 461
2026 38 (first 7 weeks)
Chart showing escalation of data broker emails from 143 in 2019 to 461 in 2025
Data broker emails received per year. The number has never gone down. Not once. Not a single year.

That’s a 222% increase from 2019 to 2025. It has never gone down. Not once. Not a single year.

And when I say “data brokers,” I don’t mean one bad actor. A forensic analysis of just 118 of these emails revealed 57 unique senders operating from 24 different domains. Half use Outlook burner accounts (disposable, untraceable identities). Many trace back to IP addresses in India, Korea, Japan. But some even from the US. They operate openly, offering “verified lists” of lawyers like it’s a perfectly normal business.

Pie chart showing 50% of data broker emails come from Outlook burner accounts
Where the data brokers hide: 50% use Outlook burner accounts. Analysis based on a sample of 118 emails from a total of 2,218+ received since 2017.

Because for them, it is.

These emails aren’t new, either. The earliest one I can find dates back to 2017:

2017 data broker email offering legal software user lists
The earliest evidence: a data broker email from 2017, already offering to sell legal software user lists. This has been going on for nearly a decade.

And they don’t take “no” for an answer. Here’s a follow-up from 2018, pressuring for a response:

Aggressive data broker follow-up email from 2018
A 2018 follow-up email from a different broker. They don’t stop.

What Are Law Firm Data Brokers Selling, and Who’s Buying?

Let’s be clear about what these brokers are offering. This is directly from their emails:

“The data fields include: Company Name, Contact First & Last Name, Job Title, Direct Email Address, Phone Number, Fax Number, Mailing Address, Employee Count, Revenue Size, Industry Classification, and Website URL.”

That’s not aggregated, anonymized market research. That’s your name, your direct phone number, your firm’s revenue, and your office address, all packaged and sold to anyone with a credit card.

These emails are highly personalized. The brokers know exactly who they’re targeting: using your name, your firm’s name, and even referencing your specific software:

Data broker email addressed to specific person and company by name
Personalized targeting: this broker knows the recipient’s name and company. They’re not guessing, they have the data.

They’re also shamelessly opportunistic. When AffiniPay acquired MyCase and LawPay, brokers immediately used the M&A news as a hook to sell user lists:

Email from data broker piggybacking on LawPay MyCase acquisition to sell user data
M&A ambulance chasing: this broker piggybacked on the LawPay/MyCase acquisition news to pitch user data sales. (Identifying details redacted)

Who’s buying?

  • Competing software vendors looking to poach customers
  • Marketing agencies running targeted campaigns
  • “Consultants” selling overpriced services to lawyers
  • Bad actors using the data for social engineering, phishing, or fraud

If someone knows your name, your firm, your software, your revenue, and your phone number, they can craft a very convincing phishing email. Or an impersonation call. Or a targeted attack that looks like it came from your bar association.


18 Platforms. One Industry. Zero Accountability.

From our sample of 118 analyzed broker emails, here’s how often each platform’s users are being sold:

Chart showing Clio mentioned in 70 of 118 analyzed broker emails
Software platforms being sold by data brokers, based on analysis of 118 emails (sampled from 2,218+). Clio leads the pack at 70 mentions — appearing in 59% of all analyzed emails.

Clio leads the pack at 70 mentions — appearing in 59% of all broker emails. But Smokeball, MyCase, CosmoLex, PracticePanther, and 13 others are all on the menu. This isn’t a problem with one vendor. It’s an industry-wide failure.

Every platform on this list stores your data in their cloud. And somehow, that data is ending up in the hands of overseas brokers who sell it to strangers. It’s one more reason to break free from cloud dependency entirely.

And here’s a 2021 email showing the range of platforms being offered, from LexisNexis to Clio to everything in between:

2021 data broker email targeting legal software users
A 2021 data broker email offering users of LexisNexis, Clio, and other platforms. The breadth of platforms being targeted has only grown over time. (Identifying details redacted)

Your State Bar is Part of the Pipeline

Here’s where it gets truly disturbing.

Smokeball (the #2 most-mentioned platform in data broker emails) has partnered with 22 state and local bar associations to offer free software licenses to their members:

Alabama, Arizona, California (two separate programs), Colorado, DC, Florida, Georgia, Illinois, Minnesota, Missouri, Nebraska, New Hampshire, New York, Oklahoma, Oregon, Texas, Utah, Wisconsin. Plus local bars in Beverly Hills, DuPage County, and St. Petersburg.

Each partnership funnels thousands of lawyers into Smokeball’s cloud platform. The New York State Bar Association alone represents over 70,000 members.

Think about what happens:

Diagram showing how bar association partnerships funnel lawyer data to brokers
The Bar Association → Data Broker Pipeline: How your professional licensing organization becomes the on-ramp to having your data sold.
  1. Your state bar says “Free Smokeball license included with your membership!”
  2. You sign up: name, email, phone, firm details
  3. Your data enters the cloud ecosystem
  4. Data brokers start selling lists of “Smokeball users”
  5. Spam arrives in your inbox from Dorothy Gale

Your own professional licensing organization — the entity charged with protecting the legal profession — is a major on-ramp to the data broker pipeline.

We’re not saying Smokeball (or any specific vendor) is intentionally selling your data. But when 22 bar associations funnel their members onto a platform whose users routinely appear in data broker lists, someone should be asking hard questions about where the leak is.


Law Firm Data Brokers Never Stop

As recently as yesterday (February 19, 2026) another one of these emails landed in my inbox:

Recent data broker email showing the problem continues in 2026
Received February 2026. Nine years after the first one, the emails keep coming. The problem isn’t going away, it’s getting worse.

Nine years. 2,218+ emails. And counting.


Where is the Data Leaking From?

There are four primary vectors:

1. The Vendor Themselves

Cloud platforms collect extensive user data. Their privacy policies (which nobody reads except me apparently) often permit sharing with “partners,” “service providers,” or “affiliated companies.” After Clio’s acquisition spree (acquiring Lawyaw, Calendly integration, Clio Payments via Stripe, and others), user data flows through an increasingly complex web of third-party relationships.

2. Third-Party Integrations

Every integration your cloud software connects to: email sync, calendar, payment processing, document storage, it’s another entity with access to your data. Each has its own privacy policy, its own data practices, and its own vulnerabilities.

3. Data Enrichment Companies

Companies like ZoomInfo, Apollo, Clearbit, and dozens of others scrape, buy, and aggregate business data from multiple sources. Once your information exists in any cloud platform, it becomes part of the data enrichment ecosystem. Bought, sold, combined, and resold endlessly.

4. Employee and Contractor Access

Cloud platforms employ hundreds or thousands of people who can potentially access customer data. Offshore support teams, contractors, and departed employees all represent potential leak points that simply don’t exist with locally-installed software.


The ABA Has Already Warned You

This isn’t hypothetical legal theory. The American Bar Association has issued clear guidance:

ABA Formal Opinion 477R (2017) requires lawyers to make “reasonable efforts” to prevent unauthorized access to client information when using technology. This includes understanding how your software vendor handles data.

ABA Model Rule 1.6(c) states: “A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client.”

ABA Model Rule 5.3 extends your ethical obligations to anyone you’ve retained to assist in providing legal services — including your software vendors.

If your client data lives on a cloud platform whose users’ information regularly appears in data broker databases, can you honestly say you’ve made “reasonable efforts” to protect it?

Multiple state bars have issued their own opinions reinforcing these obligations. Florida Bar Opinion 12-3, California Formal Opinion 2010-179, and New York State Bar Opinion 842 all address the ethical obligations of lawyers using cloud computing. The consensus: you are responsible for understanding where your data goes and who has access to it.


The Cloud “Convenience” Tax

The irony of cloud-based legal software is that you’re paying more every year for less privacy.

Clio (the #1 platform being sold by data brokers) has raised prices at least twice in three years:

Plan 2022 Price 2025 Price Increase
EasyStart $39/mo $49/mo +25.6%
Essentials $69/mo $89/mo +29.0%
Advanced $99/mo $119/mo +20.2%
Complete $129/mo $149/mo +15.5%

On top of that, they’ve quietly raised credit card processing fees from 2.8% to 2.95% (3.5% to 3.75% for Amex), increased the Clio Grow add-on from $49 to $59 per user, and locked more features behind expensive add-on tiers.

You’re paying 30% more for the privilege of having your data sold to strangers. That’s not a convenience tax, it’s a shakedown.

There’s an alternative to the SaaS treadmill: software you buy once and own forever — no recurring fees subsidizing the data broker ecosystem.


How to Protect Your Firm from Law Firm Data Brokers

1. Audit Your Cloud Footprint

Make a list of every cloud service that has access to your firm data. Read their privacy policies. Actually read them. Look for language about “sharing with partners” or “affiliated companies.”

2. Ask Your Vendor Directly

Send your cloud software provider a written request: “Please confirm whether any of our firm’s data, including usage data, account information, or metadata, has been shared with third parties, data aggregators, or marketing partners.” Watch how they respond. Or don’t.

3. Question Your Bar Association

If your state bar has a partnership with a cloud software vendor, ask them: “What due diligence was performed on this vendor’s data handling practices before recommending them to members? Has the bar reviewed whether users of this platform appear in data broker databases?”

4. Consider Local-First Software

The simplest way to prevent your data from being sold? Don’t put it in someone else’s cloud in the first place.

Software that runs locally on your machine, like TimeNet Law, keeps your data on hardware you control. There are no third-party integrations siphoning your information. No cloud servers for brokers to harvest. No employee with access to your client files from the other side of the world.

Your data stays yours because it never leaves your building.


The Bottom Line

Over 2,218 data broker emails. 57 different senders. 18 platforms being sold. 222% growth in six years. And it never, ever stops.

I’ve replied to some of these emails in frustration. I’ve reported them. I’ve flagged them. None of it matters. They just keep coming — from new names, new burner accounts, new domains. The data is out there, and once it’s out, it never comes back.

Every lawyer using cloud-based practice management software should be asking one question: Where is my data going?

Because right now, the answer is: everywhere. To anyone. For a price.

And the people who are supposed to protect you (your software vendors, your bar associations, etc.) are the ones who helped put you in this position.


Methodology note: Year-over-year email counts (2,218+ total) are actual totals from the full inbox. Platform mention counts, sender domain analysis, and other forensic breakdowns are based on a detailed analysis of 118 emails sampled from the full set.


Perry Fjellman is the developer of TimeNet Law, a desktop-native legal practice management application that keeps your data where it belongs: on your computer.

Categories
Industry Analysis

Looking for a Tabs3 Alternative? Here’s What 46 Years of Independence Gets You When PE Comes Knocking

Tabs3 isn’t broken. That’s what makes this story so tragic.

If you’re searching for a Tabs3 alternative, you probably aren’t doing it because the software crashed or support hung up on you. Tabs3 still works. The reviews are still good. Dan Berlin, who’s been CEO since 1984, is still there.

So why would you leave?

Because you’ve done the math. You’ve noticed who owns Tabs3 now. And you know how this story ends.

Let me tell you about the 46-year-old company that was supposed to be the safe choice — and what happens when private equity comes knocking.


The Company That Should Have Been Untouchable

Tabs3 was founded in 1979. That’s not a typo. They’ve been making legal billing software for 46 years — longer than most attorneys have been practicing law.

Dan Berlin became CEO in 1984 and has been running the company ever since. Forty-one years of leadership. That kind of tenure is almost unheard of in tech.

For decades, Tabs3 was exactly what small and mid-sized law firms needed: stable, reliable, built by people who understood the legal profession. Over 50,000 attorneys at nearly 10,000 law firms trusted them with their billing.

They were the safe choice. The “it’s been around forever” choice. The “they’re not going anywhere” choice.

Then private equity came calling.


December 2016: The Beginning of the End

After 37 years of independence, Tabs3 (operating as Software Technology, Inc.) was “recapitalized” by Thompson Street Capital Partners, a private equity firm based in St. Louis.

At the time, Dan Berlin said all the right things:

“We are proud of our history of providing reliable software and trusted service, and with TSCP as a partner, we couldn’t be more optimistic about our future.”

Sound familiar? Every founder says this when they take PE money. And they probably believe it — at first.

Thompson Street promised the usual: resources, expertise, “long term perspective on growing the business.” The press release talked about supporting continued growth and maintaining the company’s “well-earned reputation.”


What Actually Happened

Here’s what Thompson Street did during their ownership, according to their own announcement:

  • “Expanding direct and indirect sales channels” — more aggressive sales tactics
  • “Improving customer retention” — harder to leave
  • “Optimizing pricing” — that’s PE code for raising prices
  • “Executing the transformative add-on acquisition of CosmoLex” — buying competitors to eliminate alternatives

In October 2018, Tabs3 acquired CosmoLex, a cloud-based practice management platform. This wasn’t about innovation or serving customers better. It was about portfolio building — consolidating the market to prepare for the real endgame.


March 2021: The Flip

After four years, Thompson Street did what private equity always does: they sold.

On March 5, 2021, Thompson Street announced they had “completed the sale of Tabs3 Software to a new capital partner.”

But here’s the thing: they didn’t say who bought it.

The press release deliberately omitted the buyer’s name. It was a “stealth acquisition” — a deal so quiet that legal tech journalists had to investigate to figure out who now owned one of the oldest practice management companies in the industry.

The answer? ProfitSolv, a company created by Lightyear Capital specifically to roll up legal software brands.

By the time the dust settled, ProfitSolv owned:

  • Tabs3 (est. 1979)
  • CosmoLex (came with Tabs3)
  • TimeSolv
  • Rocket Matter
  • LexCharge
  • ImagineTime

Four competing legal billing products, all under one roof. All owned by the same PE firm.

Four competing legal billing products, all under one roof. All owned by the same PE firm.


The Portfolio Trap

If you’re a Tabs3 user and you’re unhappy, where do you go?

The illusion of choice in legal billing software is exactly that — an illusion. ProfitSolv can let these brands “compete” with each other while extracting maximum value from the entire market.

This is the consolidation playbook:

  1. Acquire multiple competing brands
  2. Keep them looking separate to maintain the illusion of choice
  3. Align pricing across the portfolio (read: raise prices together)
  4. Cut costs on development and support (shared infrastructure)
  5. Prepare for the next flip to the next PE firm

And sure enough, by late 2024, Lightyear Capital was actively shopping ProfitSolv for sale. In June 2025, they brought in FTV Capital as a co-investor. More PE hands in the pot. More pressure to extract returns.


“I’m Not Going Anywhere”

After the ProfitSolv acquisition became public, Dan Berlin told reporters: “I’m not going anywhere. I’m very excited about the partnerships and relationships we have with the other companies under the ProfitSolv umbrella.”

And maybe he means it. Maybe he’ll stay until retirement. But here’s the brutal truth:

Dan Berlin doesn’t own Tabs3 anymore. Private equity does.

Every decision — pricing, staffing, support, product direction — ultimately answers to investors whose only metric is return on capital. The same investors who are already bringing in new PE partners and preparing for the next transaction.

Dan Berlin’s 41-year tenure is a selling point, not a safeguard. When he eventually leaves, the institutional knowledge walks out with him. And PE firms don’t replace founders with founders. They replace founders with operators whose job is to squeeze.


The Reviews Tell the Story (So Far)

Here’s what makes Tabs3 different from the other ProfitSolv brands: the reviews are still good.

Tabs3 has a 4.6 rating on Capterra (187 reviews) and a 4.7 for customer service. Users praise the software’s reliability, the integration between modules, and the knowledgeable support team.

“I have been using Tabs3 for over 20 years. As a consultant, I am familiar with many of the other legal software packages, and the one I use for my business is Tabs3.”

“This is a company that understands ‘if it ain’t broke, don’t fix it’ because it works!”

“Tabs3 has flawless integration between all the modules… and their tech support is second to none!”

These aren’t reviews of a broken product. They’re reviews of a product that hasn’t been broken yet.

But compare this to the CosmoLex reviews, which show a clear decline starting in 2021 — right when ProfitSolv took over. Users explicitly say “it’s been going downhill since 2021.” The same pattern is emerging at Rocket Matter and TimeSolv.

Tabs3’s loyal team and established processes have insulated it from the worst PE effects — so far. But the playbook is the same. It’s just a matter of time.


Warning Signs

Some Tabs3 users are already noticing changes:

The maintenance fee squeeze: “Every year, the price went up. The service I received was exactly the same, but they decided to charge me more and more for it with each passing year.”

One user reported prices nearly doubling over three years, with the company refusing to lock in rates even for long-term commitments.

The upsell pressure: “System crashes and they seem to be more concerned about upselling to the better system. Why would anyone spend more for the better system with a company that can’t get the basic system to work?”

The learning curve excuse: Multiple reviews mention that Tabs3 is complex and difficult to learn. For 46-year-old software that’s had decades to improve its interface, “steep learning curve” shouldn’t still be a top complaint — unless development resources are going elsewhere.

These aren’t catastrophic failures. They’re early indicators. The foundation is cracking before the house comes down.


The Tragedy of Tabs3

Here’s what makes this story different from CosmoLex, Rocket Matter, or TimeSolv:

Tabs3 was supposed to be the exception.

They had 37 years of independence. A founder who’d been there since 1984. A reputation built on reliability and trust. They served small and mid-sized firms — exactly the attorneys who can’t afford to gamble on unstable software.

And they gave it all away.

When Thompson Street came calling in 2016, Software Technology, Inc. had options. They could have stayed independent. They could have said no to PE money that came with strings attached. They could have protected the legacy they’d spent four decades building.

Instead, they took the check. Four years later, they got flipped. Now they’re just another brand in a portfolio optimized for investor returns, not attorney outcomes.

The 46-year legacy? It’s a marketing asset now. Something to put in press releases while new ownership “optimizes pricing” and “expands sales channels.”


What Tabs3 Could Have Been

Imagine if Tabs3 had stayed independent.

After 46 years, they’d be the gold standard for legal billing software. The company that proved you don’t need venture capital or private equity to build something that lasts. The company where the founder’s successor would be chosen for their commitment to the mission, not their ability to hit quarterly targets.

They could have been proof that the old way of building software — slowly, carefully, in service of customers rather than investors — still works.

Instead, they’re a cautionary tale.


⚡ 60-Second Firm Hack: The “Maintenance Audit” That Saves Thousands

Most firms pay maintenance or subscription fees automatically without ever reviewing what they’re getting. Once a year, run a Maintenance Audit:

  1. List every software subscription your firm pays
  2. Note the original price when you signed up vs. current price
  3. Calculate the percentage increase year-over-year
  4. For each one, ask: “What new value did we get to justify this increase?”

If prices have climbed 50-100% while features stayed flat, you’re funding someone’s PE returns, not your firm’s growth. That’s your signal to explore alternatives that let you own your software instead of renting it — while you still have leverage.

Set a calendar reminder: first week of January, every year. Twenty minutes that can save thousands.


The Alternative Exists

There are still independent legal billing companies out there. Companies that haven’t taken PE money. Companies where the founder still owns the business and answers to customers, not investors.

TimeNet Law is one of them.

We’ve been building legal billing software for over 20 years. No PE ownership. No investor board meetings. No preparation for “exit.” When you call us, you might reach the person who wrote the code — because we’re a team that’s chosen to stay small, stay independent, and stay focused on what actually matters: software that works and support that helps.

We’re not trying to consolidate the market. We’re not optimizing pricing. We’re not preparing to flip the company to the next buyer.

We’re just building good software for attorneys who want stability, transparency, and a partner they can trust for the long haul.

The kind of company Tabs3 used to be.


Making the Switch

If you’re considering leaving Tabs3 — whether now or as a contingency plan — here’s what to expect:

Data migration: We’ve helped firms migrate from Tabs3, CosmoLex, TimeSolv, and other platforms. We know the data formats, the quirks, and how to make the transition as smooth as possible.

Learning curve? Our software is designed to be intuitive from day one. You shouldn’t need weeks of training to enter time and generate bills.

Support: Real people, real answers, same day. No ticket numbers, no “we’ll get back to you in 3-5 business days.” We actually pick up the phone.

Pricing: Transparent, stable, and no surprises. We don’t “optimize pricing” because we’re not trying to impress investors.

No lock-in: We don’t need long-term contracts to keep you around. If our software stops earning your business, you should be free to leave.


The Real Question

Tabs3 still works today. Dan Berlin is still at the helm. The support team is still helpful.

But in five years? Ten years?

Private equity doesn’t invest in 46-year-old software companies to keep them running the same way for another 46 years. They invest to extract value and exit.

The question isn’t whether Tabs3 will change. It’s when.

And when it does, will you have a backup plan? Will your data be portable? Will you have an alternative lined up that doesn’t lead right back to the same PE portfolio?

The time to answer those questions is now — while you still have options.


Ready to See What Independence Looks Like?

Curious about legal billing software that’s still built the old-fashioned way? No PE ownership, no portfolio games, no preparation for the next transaction?

We’ll show you exactly what you’re getting — and what you’re not getting. No pressure, no sales theatrics.

Schedule a Demo →

Or join Off the Record, our private newsletter for attorneys who want the inside scoop on what’s really happening in legal tech — without the corporate spin.

Subscribe to Off the Record →


Tabs3 was built over 46 years by people who cared. Don’t let private equity make those years mean nothing. Reach out — we’re real people who actually respond, the same day, every time.