---
title: "Quinn Emanuel and McDermott breached as law fir… | Firevault"
description: "Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026#webpage",
      "url": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026",
      "name": "Quinn Emanuel and McDermott breached as law fir…",
      "description": "Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Quinn Emanuel and McDermott breached as law firms become the soft route to client data",
          "item": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Quinn Emanuel and McDermott breached as law firms become the soft route to client data",
      "description": "Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.",
      "url": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-08T12:00:00+00:00",
      "dateModified": "2026-09-08T13:02:31.802171+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 632,
      "keywords": "Quinn, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened Quinn Emanuel and McDermott Will & Emery, two of the most prominent law firms in the United States, both confirmed data breaches on 3 September 2026 and said they had notified law enforcement. It is not clear who was responsible for either incident, or whether the two were connected. Quinn Emanuel described \"a data security incident involving unauthorized access to stored files fo",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Which law firms have disclosed breaches?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Quinn Emanuel and McDermott Will & Emery disclosed breaches on 3 September 2026. Herbert Smith Freehills Kramer and Goodwin Procter disclosed breaches to US state regulators in August, and WilmerHale was sued in a proposed class action in July over a breach."
          }
        },
        {
          "@type": "Question",
          "name": "How did the attackers get in?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Both firms described social engineering. Quinn Emanuel said access came through one temporarily compromised user account to a single software application, and McDermott described an isolated incident involving a single user."
          }
        },
        {
          "@type": "Question",
          "name": "What data was exposed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Quinn Emanuel said a limited number of client documents were affected, including files relating to the short seller Muddy Waters. McDermott told the Vermont attorney general that the exposed files included Social Security numbers and health data."
          }
        },
        {
          "@type": "Question",
          "name": "Why are law firms such attractive targets?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "They hold confidential business and personal data for hundreds of clients in one place, including deal plans, litigation strategy and sensitive personal records. Breaching one firm reaches many organisations at once."
          }
        },
        {
          "@type": "Question",
          "name": "What should clients ask their law firms?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Ask which of your documents remain reachable from ordinary user accounts, how closed matters are archived, whether authentication is phishing-resistant, and how access logs are retained and protected from alteration."
          }
        },
        {
          "@type": "Question",
          "name": "Would Offline Secure Storage have prevented this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Social engineering is a people and process problem. Offline Secure Storage limits how much is reachable when an account is compromised by holding closed matters and archives offline, and keeps audit records immutable so the scope of an incident can be proven."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What happenedNot isolated incidentsThe pattern worth noticingThe Firevault viewSourceMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 8 September 2026 · Breaking 

# Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Flaw-firms-quinn-emanuel-mcdermott-data-breaches-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Flaw-firms-quinn-emanuel-mcdermott-data-breaches-2026&text=Quinn%20Emanuel%20and%20McDermott%20breached%20as%20law%20firms%20become%20the%20soft%20route%20to%20client%20data%0A%0ATwo%20more%20major%20US%20law%20firms%20have%20disclosed%20social%20engineering%20breaches%2C%20joining%20Herbert%20Smith%20Freehills%20Kramer%2C%20Goodwin%20Procter%20and%20WilmerHale.%20One%20compromised%20user%20account%20was%20enough.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Flaw-firms-quinn-emanuel-mcdermott-data-breaches-2026)[](mailto:?subject=Quinn%20Emanuel%20and%20McDermott%20breached%20as%20law%20firms%20become%20the%20soft%20route%20to%20client%20data&body=Two%20more%20major%20US%20law%20firms%20have%20disclosed%20social%20engineering%20breaches%2C%20joining%20Herbert%20Smith%20Freehills%20Kramer%2C%20Goodwin%20Procter%20and%20WilmerHale.%20One%20compromised%20user%20account%20was%20enough.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Flaw-firms-quinn-emanuel-mcdermott-data-breaches-2026)

![Illustration of a sealed legal document folder being opened by a hand made of network lines, representing law firm data breaches through social engineering](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Illustration of a sealed legal document folder being opened by a hand made of network lines, representing law firm data breaches through social engineering

Why it matters

## What this means for organisations holding critical data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [Not isolated incidents](#section-1)
3.  03 [The pattern worth noticing](#section-2)
4.  04 [The Firevault view](#section-3)

**On this page**[What happened](#section-0)[Not isolated incidents](#section-1)[The pattern worth noticing](#section-2)[The Firevault view](#section-3)

## What happened

Quinn Emanuel and McDermott Will & Emery, two of the most prominent law firms in the United States, both confirmed data breaches on 3 September 2026 and said they had notified law enforcement. It is not clear who was responsible for either incident, or whether the two were connected.

Quinn Emanuel described "a data security incident involving unauthorized access to stored files for a single software application through one temporarily compromised user account". The firm said a limited number of client documents were affected, that affected parties have been informed, and that there is no ongoing unauthorised access.

In a letter dated 25 August, seen by Reuters, Quinn Emanuel told a lawyer for the short seller Muddy Waters that an unauthorised third party had obtained access through social engineering on 14 August, and that some of the exposed material involved Muddy Waters files the firm had obtained through a lawsuit in Florida.

McDermott reported its breach to the Vermont attorney general and said the exposed files included Social Security numbers and health data. The firm called it "an isolated social engineering incident involving a single user and a limited number of documents", said it worked with external cyber security experts and law enforcement, and that the matter has been resolved.

## Not isolated incidents

The two disclosures follow a run of similar cases. Herbert Smith Freehills Kramer and Goodwin Procter both disclosed breaches to US state regulators in August, and WilmerHale was sued in a proposed class action in July over a breach affecting the firm.

Law firms hold what attackers actually want: merger plans, litigation strategy, regulatory exposure, personal data of executives and, as McDermott's filing shows, Social Security numbers and health records. They hold it on behalf of hundreds of clients at once, which makes a single firm a more efficient target than any one of those clients.

## The pattern worth noticing

Both firms used the same phrase: social engineering. Neither described a zero-day exploit or a failure of encryption. In each case a person was persuaded, one account was taken, and documents left the building.

That has three consequences for anyone who instructs outside counsel:

1.  **Your data leaves your control the moment you send it.** Your own segmentation, monitoring and patching stop at your perimeter. Your legal files do not.
2.  **One account is enough.** Both firms stressed that a single user was involved. That is offered as reassurance, but it is also the finding: document stores are commonly reachable in full by ordinary accounts.
3.  **"The matter has been resolved" rests on evidence.** Scope statements, notification decisions and any later class action all depend on records of who accessed what and when.

## The Firevault view

[Offline Secure Storage](/offline-secure-storage)® does not prevent social engineering. A convincing message to a busy lawyer is a people and process problem, answered by verification habits, phishing-resistant authentication and tighter document permissions.

What Offline Secure Storage® changes is the scope of the loss and the reliability of the record. A firm that keeps its complete document estate live and reachable will lose whatever a compromised account can see. A firm that holds closed matters, archived client files and audit logs offline and immutable narrows the reachable surface to current work, and keeps the access records that determine notification duty beyond the reach of anyone still inside the estate.

Mark Fermor, Director and Co-Founder of Firevault, said: "Every one of these firms is well resourced and well advised, and still lost documents to a single borrowed account. If your archive is online, your archive is in scope. Take the closed matters offline and the same intrusion costs a fraction of what it costs today."

## Source

-   [Reuters: Data at law firms Quinn Emanuel, McDermott exposed in cyber breaches](https://www.reuters.com/legal/government/data-law-firms-quinn-emanuel-mcdermott-exposed-cyber-breaches-2026-09-03/)

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.reuters.com/legal/government/data-law-firms-quinn-emanuel-mcdermott-exposed-cyber-breaches-2026-09-03/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)