---
title: "Smith and Co Solicitors Ipswich Data Breach | Firevault"
description: "An Ipswich solicitors firm with more than 2,000 clients has been hit by a data breach, with hackers gaining access to potentially sensitive data and…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach#webpage",
      "url": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach",
      "name": "Smith and Co Solicitors Ipswich Data Breach",
      "description": "An Ipswich solicitors firm with more than 2,000 clients has been hit by a data breach, with hackers gaining access to potentially sensitive data and…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/3fab02ac-900f-4c91-aef9-d0a6062d3792/smith-and-co-solicitors-ipswich-data-breach-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Smith and Co Solicitors Ipswich Data Breach",
          "item": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Smith and Co Solicitors Ipswich Data Breach",
      "description": "An Ipswich solicitors firm with more than 2,000 clients has been hit by a data breach, with hackers gaining access to potentially sensitive data and persuading one individual to send them money after obtaining her email.",
      "url": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/3fab02ac-900f-4c91-aef9-d0a6062d3792/smith-and-co-solicitors-ipswich-data-breach-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/3fab02ac-900f-4c91-aef9-d0a6062d3792/smith-and-co-solicitors-ipswich-data-breach-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/3fab02ac-900f-4c91-aef9-d0a6062d3792/smith-and-co-solicitors-ipswich-data-breach-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/3fab02ac-900f-4c91-aef9-d0a6062d3792/smith-and-co-solicitors-ipswich-data-breach-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-03-28T09:00:00+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/smith-and-co-solicitors-ipswich-data-breach"
      },
      "inLanguage": "en-GB",
      "articleSection": "Data Breaches",
      "wordCount": 1185,
      "keywords": "Smith, Data Breaches, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "What Happened Smith and Co Solicitors, a well-established law firm based in St Margaret's Green, Ipswich, has confirmed it was the victim of a cyber attack first detected on 19 March 2026. Technicians believe the original breach dates back to 12 March, after clients contacted the business to report suspicious email exchanges between themselves and an unknown third party. The attackers gained acces",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhat Data Was ExposedWho Is AffectedWhy This MattersThe Offline AlternativeLegal Chambers by FirevaultKey TakeawaysMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Data Breaches · 28 March 2026 

# Smith and Co Solicitors Ipswich Data Breach

An Ipswich solicitors firm with more than 2,000 clients has been hit by a data breach, with hackers gaining access to potentially sensitive data and persuading one individual to send them money after obtaining her email.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsmith-and-co-solicitors-ipswich-data-breach)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsmith-and-co-solicitors-ipswich-data-breach&text=Smith%20and%20Co%20Solicitors%20Ipswich%20Data%20Breach%0A%0AAn%20Ipswich%20solicitors%20firm%20with%20more%20than%202%2C000%20clients%20has%20been%20hit%20by%20a%20data%20breach%2C%20with%20hackers%20gaining%20access%20to%20potentially%20sensitive%20data%20and%20persuading%20one%20individual%20to%20send%20them%20money%20after%20obtaining%20her%20email.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsmith-and-co-solicitors-ipswich-data-breach)[](mailto:?subject=Smith%20and%20Co%20Solicitors%20Ipswich%20Data%20Breach&body=An%20Ipswich%20solicitors%20firm%20with%20more%20than%202%2C000%20clients%20has%20been%20hit%20by%20a%20data%20breach%2C%20with%20hackers%20gaining%20access%20to%20potentially%20sensitive%20data%20and%20persuading%20one%20individual%20to%20send%20them%20money%20after%20obtaining%20her%20email.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fsmith-and-co-solicitors-ipswich-data-breach)

![A traditional English solicitors office on a quiet cobblestone street at blue hour, warm light spilling from windows](/__l5e/assets-v1/3fab02ac-900f-4c91-aef9-d0a6062d3792/smith-and-co-solicitors-ipswich-data-breach-2x.jpg)

A traditional English solicitors office on a quiet cobblestone street at blue hour, warm light spilling from windows

Why it matters

## What this means for organisations holding critical data

An Ipswich solicitors firm with more than 2,000 clients has been hit by a data breach, with hackers gaining access to potentially sensitive data and persuading one individual to send them money after obtaining her email.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [What Data Was Exposed](#section-1)
3.  03 [Who Is Affected](#section-2)
4.  04 [Why This Matters](#section-3)
5.  05 [The Offline Alternative](#section-4)
6.  06 [Legal Chambers by Firevault](#section-5)

**On this page**[What Happened](#section-0)[What Data Was Exposed](#section-1)[Who Is Affected](#section-2)[Why This Matters](#section-3)[The Offline Alternative](#section-4)[Legal Chambers by Firevault](#section-5)

## What Happened

Smith and Co Solicitors, a well-established law firm based in St Margaret's Green, Ipswich, has confirmed it was the victim of a cyber attack first detected on 19 March 2026. Technicians believe the original breach dates back to 12 March, after clients contacted the business to report suspicious email exchanges between themselves and an unknown third party.

The attackers gained access to the firm's email systems, obtaining client email addresses and potentially any correspondence containing sensitive personal data. In the firm's own words:

> "Unfortunately, we have been the victim of a security breach, but it appears that the criminals behind the attack have managed to access email addresses and potentially any email that contains sensitive data. We are notifying you as we are aware your email address may have been obtained and to warn you that there is a possibility that you could receive an email from the criminals."

In one confirmed case, the criminals successfully persuaded a client to transfer money after obtaining her email and impersonating the firm. The amount has not been disclosed.

The attackers have also created fraudulent email addresses designed to impersonate the firm, and the practice has urged all clients to carefully verify the sender address on any communication purporting to come from Smith and Co.

_Source: [Ipswich Star](https://www.ipswichstar.co.uk/news/25975147.smith-co-solicitors-ipswich-faces-data-breach/), reporting by Will King, 28 March 2026._

## What Data Was Exposed

The firm has confirmed that email addresses were compromised, along with the potential exposure of any sensitive information contained within those email threads. For a solicitors practice handling conveyancing, family law, wills, and commercial matters, this could include:

-   **Financial information** shared during property transactions or business dealings
-   **Personal identification documents** submitted as part of client onboarding
-   **Confidential legal correspondence** relating to ongoing cases
-   **Contact details** of over 2,000 registered clients

## Who Is Affected

The breach is understood to have directly impacted approximately 25 per cent of the firm's client base. High-priority individuals were contacted first, with a broader communication sent to all remaining clients on Thursday 27 March.

Managing partner Vicky Hosking described the situation as "frightening" but praised her team's response:

> "Falling victim to a cyber attack, whether a law firm or an individual, is devastating. We follow best practice protocols, including telephone calls and email to reach all affected clients. We really care about keeping the clients' data and their money safe."

> "It feels frightening, because it feels like you can never do enough to help. As a local business, we care about our clients. We really love running a law firm in our local community, and we just want to reassure people."

One client, who chose not to be named due to security reasons, said:

> "It is terribly concerning to find out from a circular email that my personal details and data have been the subject of a seemingly successful hack. I cannot help but wonder how serious the consequences of this could be for a considerable number of people."

The incident has been reported to both the Information Commissioner's Office and Action Fraud.

## Why This Matters

This breach is far from an isolated case. The Solicitors Regulation Authority has warned of a significant rise in cyber attacks targeting law firms, with a recent investigation finding that three quarters of the firms they visited had been the target of a cyber attack.

Law firms are particularly attractive targets for cybercriminals because they routinely handle high-value financial transactions and hold large volumes of sensitive personal data. A successful email compromise can lead directly to financial fraud, as demonstrated in this case, where a client was deceived into sending money to the attackers.

## The Offline Alternative

The Smith and Co breach highlights a fundamental vulnerability in modern legal practice: sensitive client data stored in internet-connected email systems is only as secure as the weakest link in the chain. Once an attacker gains access to a networked system, every piece of data within reach is exposed.

Physically offline storage, such as [Firevault's Layer 1 air gap solution](/our-difference/offline-secure-storage), removes this attack vector entirely. By disconnecting sensitive archives from all network infrastructure, client files, identification documents, and confidential correspondence become physically inaccessible to remote attackers, regardless of how sophisticated the breach.

For solicitors handling conveyancing funds, estate documents, and privileged legal correspondence, the ability to vault completed matter files in a physically disconnected environment would ensure that even a full email system compromise could not expose historical client data.

## [Legal Chambers by Firevault](/solutions/legal)

Firevault's [Legal Chamber Model](/solutions/legal) offers law firms a structured governance framework purpose-built for the way solicitors practices actually operate. Rather than treating all data equally, the chamber model separates firm data into distinct isolation zones with independent access controls and audit trails.

The model is structured around two core areas:

**[Inner Stewardship Chambers](/solutions/legal)** govern the firm's own leadership data, including partnership agreements, financial records, regulatory correspondence, and strategic documents. These chambers are restricted to named partners and compliance officers, ensuring that sensitive firm governance material is never exposed to the wider practice.

**[Outer Wings](/solutions/legal)** handle client matter files, regulatory evidence, and completed case archives. Each wing operates as an independent vault with its own permissions, meaning a breach of one client matter cannot cascade into another. Completed matters can be physically disconnected and archived offline, removing them entirely from any networked attack surface.

This structure directly addresses the vulnerability exposed in the Smith and Co breach. Had the firm's completed client files been vaulted in physically disconnected Outer Wings, the email system compromise would have exposed only active correspondence, not the full historical archive of 2,000 clients' sensitive documents.

The Legal Chamber Model also supports SRA compliance by providing verifiable audit trails for data access, enabling firms to demonstrate precisely who accessed what data and when. For practices that bill for document custody and secure archiving, the model creates a revenue stream from data governance rather than treating it as a pure cost centre.

Built on the [VPPP framework (Vault, Policy, Permissions, Purpose)](/platform), each chamber enforces identity-locked access where every retrieval requires deliberate, authorised action. There is no shared network drive, no open email attachment, and no free cloud tool where sensitive files can leak. The intentional friction of governed access replaces the uncontrolled data sharing that made the Smith and Co breach possible.

## Key Takeaways

-   **Law firms remain prime targets**, the SRA reports that 75 per cent of firms visited had experienced a cyber attack, making the legal sector one of the most targeted industries
-   **Email compromise leads directly to financial fraud**, attackers used stolen credentials to impersonate the firm and successfully extract money from a client
-   **Small firms are not exempt**, community practices with just 2,000 clients face the same sophisticated threats as large corporate firms
-   **Connected systems mean connected risk**, any data accessible via a networked email system is vulnerable once that system is breached
-   **The [Legal Chamber Model](/solutions/legal) isolates exposure**, by separating firm governance from client matters in physically disconnected vaults, a single breach cannot cascade across the entire practice
-   **[Physical disconnection](/our-difference/offline-secure-storage) eliminates remote access**, offline, air-gapped storage ensures that archived client files cannot be reached by remote attackers under any circumstances

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.ipswichstar.co.uk/news/25975147.smith-co-solicitors-ipswich-faces-data-breach/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Major Telco Breach: 6.2 Million Users Exposed](/__l5e/assets-v1/c391abb7-1d63-4655-a868-207cdc238211/telco-breach-bright-1771247564376-2x.jpg)

Data Breaches 

### Major Telco Breach: 6.2 Million Users Exposed

Dutch telecommunications company Odido has confirmed a cyberattack exposing personal data of 6.2 million customers, including names, dates of birth, and contact details from a customer contact system.

13 Feb 2026 3 min 







](/news/major-telco-breach-6-2-million-users-personal-info-leaked)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)[

![Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Insight 

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min 







](/news/beacon-charity-database-breach-hiv-charity-health-data-2026)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)