Breaking NewsUpdated as information becomes available
News·Breach Analysis·8 September 2026·Breaking

Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Illustration of a sealed legal document folder being opened by a hand made of network lines, representing law firm data breaches through social engineering
Illustration of a sealed legal document folder being opened by a hand made of network lines, representing law firm data breaches through social engineering

Why it matters

What this means for organisations holding critical data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

What happened

Quinn Emanuel and McDermott Will & Emery, two of the most prominent law firms in the United States, both confirmed data breaches on 3 September 2026 and said they had notified law enforcement. It is not clear who was responsible for either incident, or whether the two were connected.

Quinn Emanuel described "a data security incident involving unauthorized access to stored files for a single software application through one temporarily compromised user account". The firm said a limited number of client documents were affected, that affected parties have been informed, and that there is no ongoing unauthorised access.

In a letter dated 25 August, seen by Reuters, Quinn Emanuel told a lawyer for the short seller Muddy Waters that an unauthorised third party had obtained access through social engineering on 14 August, and that some of the exposed material involved Muddy Waters files the firm had obtained through a lawsuit in Florida.

McDermott reported its breach to the Vermont attorney general and said the exposed files included Social Security numbers and health data. The firm called it "an isolated social engineering incident involving a single user and a limited number of documents", said it worked with external cyber security experts and law enforcement, and that the matter has been resolved.

Not isolated incidents

The two disclosures follow a run of similar cases. Herbert Smith Freehills Kramer and Goodwin Procter both disclosed breaches to US state regulators in August, and WilmerHale was sued in a proposed class action in July over a breach affecting the firm.

Law firms hold what attackers actually want: merger plans, litigation strategy, regulatory exposure, personal data of executives and, as McDermott's filing shows, Social Security numbers and health records. They hold it on behalf of hundreds of clients at once, which makes a single firm a more efficient target than any one of those clients.

The pattern worth noticing

Both firms used the same phrase: social engineering. Neither described a zero-day exploit or a failure of encryption. In each case a person was persuaded, one account was taken, and documents left the building.

That has three consequences for anyone who instructs outside counsel:

  1. Your data leaves your control the moment you send it. Your own segmentation, monitoring and patching stop at your perimeter. Your legal files do not.
  2. One account is enough. Both firms stressed that a single user was involved. That is offered as reassurance, but it is also the finding: document stores are commonly reachable in full by ordinary accounts.
  3. "The matter has been resolved" rests on evidence. Scope statements, notification decisions and any later class action all depend on records of who accessed what and when.

The Firevault view

Offline Secure Storage® does not prevent social engineering. A convincing message to a busy lawyer is a people and process problem, answered by verification habits, phishing-resistant authentication and tighter document permissions.

What Offline Secure Storage® changes is the scope of the loss and the reliability of the record. A firm that keeps its complete document estate live and reachable will lose whatever a compromised account can see. A firm that holds closed matters, archived client files and audit logs offline and immutable narrows the reachable surface to current work, and keeps the access records that determine notification duty beyond the reach of anyone still inside the estate.

Mark Fermor, Director and Co-Founder of Firevault, said: "Every one of these firms is well resourced and well advised, and still lost documents to a single borrowed account. If your archive is online, your archive is in scope. Take the closed matters offline and the same intrusion costs a fraction of what it costs today."

Source

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker