WASHINGTON — Two of America’s most prominent law firms have disclosed separate cybersecurity breaches involving sensitive information, adding to mounting evidence that the legal industry has become one of the most attractive targets for criminals who may not need sophisticated malware to get inside.
Quinn Emanuel Urquhart & Sullivan and McDermott Will & Schulte confirmed that unauthorized parties gained access to data in recent incidents involving social engineering, a technique in which attackers manipulate people into providing access, credentials or other information rather than relying solely on technical vulnerabilities. Both firms said they contacted law enforcement.
What makes the incidents particularly significant is not only the prestige of the firms involved, but the type of information law firms routinely possess: confidential corporate records, litigation documents, financial information, personal data and potentially privileged communications.
And the Quinn Emanuel breach has an additional twist — some of the accessed material was connected to short seller Muddy Waters, which is already locked in a separate legal dispute involving the law firm.
Quinn Emanuel says one user account was temporarily compromised
According to Reuters, Quinn Emanuel told a lawyer representing Muddy Waters in an August 25 letter that an unauthorized third party obtained access through social engineering on August 14.
Some of the affected material involved Muddy Waters files that Quinn Emanuel had obtained through litigation in Florida.
Quinn Emanuel subsequently said the security incident involved stored files associated with one software application and one temporarily compromised user account.
The firm said only a limited number of client documents were affected, that impacted parties had been notified and that there was no continuing unauthorized access to its systems.
The disclosure nevertheless arrives during an already tense period between Quinn Emanuel and Muddy Waters.
Muddy Waters has sought to prevent Quinn Emanuel from participating in litigation against the short seller in Texas, arguing that the firm had previously represented Muddy Waters in related matters. Quinn Emanuel disputes those conflict-of-interest allegations and has said the prior representation involved one lawyer and a different matter.
The cybersecurity incident therefore adds a new layer to an existing legal fight: the question is no longer limited to who Quinn Emanuel can represent, but also how information tied to a former client came to be accessed by an unauthorized third party.
McDermott breach involved Social Security numbers and health information
McDermott Will & Schulte separately notified the Vermont attorney general about a security incident involving files containing Social Security numbers and health information.
The firm described the episode as an isolated social-engineering incident involving a single user and a limited number of documents. McDermott said cybersecurity specialists assisted with the investigation and that law enforcement was contacted.
McDermott said the matter had been resolved and its systems remained secure.
Public reporting has not established who carried out the attack, whether the Quinn Emanuel and McDermott incidents involved the same group, or whether the attackers attempted to extort either firm. Reuters specifically reported that the identity of those responsible and any connection between the incidents remained unclear.
That distinction matters because several cybercrime groups are currently targeting professional-services companies, but the Quinn Emanuel and McDermott incidents should not be attributed to any particular hacking group without additional evidence.
It is becoming a much bigger law-firm problem
The two breaches are not isolated examples.
In August, Reuters reported that Herbert Smith Freehills Kramer, Goodwin Procter and Taft Stettinius & Hollister had also disclosed cybersecurity incidents to U.S. regulators.
Herbert Smith said attackers obtained unauthorized access to a limited part of its U.S. technology environment. Categories of affected information included Social Security numbers, government identification data and health records. The firm said a small number of people were affected and notified.
Goodwin Procter similarly described its incident as limited and said affected clients and individuals had been notified, while Taft reported unexpected activity involving a single system and said it was notifying people whose information was included in the affected data.
Other prominent firms, including WilmerHale, Jones Day and Wiley Rein, have faced cybersecurity incidents or litigation connected with breaches this year.
Bloomberg Law reported in July that WilmerHale was sued over a breach in which plaintiffs alleged that client personal information had been compromised. The proposed litigation sought damages over the firm’s handling of sensitive data.
Why hackers increasingly want law-firm data
The appeal is straightforward.
A major law firm can effectively function as a warehouse for information belonging to hundreds or thousands of companies and individuals. Its systems can contain merger documents, intellectual property, financial records, litigation strategies, contracts, employment records and personal identifying information.
That means attackers who successfully steal law-firm data may obtain leverage not only over the firm itself but potentially over its clients.
The FBI has warned specifically about cybercriminals targeting U.S. law firms through social engineering.
In an advisory concerning the Silent Ransom Group, also known as Luna Moth, Chatty Spider and UNC3753, the FBI said the group had consistently targeted U.S.-based law firms because of the sensitive nature of legal-industry information. Its tactics have included impersonating IT personnel and attempting to trick employees into providing access to computers.
Again, there is no confirmed public link between Silent Ransom Group and the Quinn Emanuel or McDermott breaches. The FBI warning is significant because it illustrates the broader threat environment in which the latest incidents occurred.
Cybersecurity reporting this summer has shown that criminals are increasingly relying on surprisingly simple methods.
Reuters reported in August that hackers targeting financial institutions, private-equity companies and law firms were using phone calls and fake corporate login pages to persuade employees to surrender passwords or multifactor-authentication codes.
Google researchers said attackers had recently shifted attention toward private equity firms, law firms and ratings agencies. More than 200 companies had been targeted through malicious web infrastructure examined in the investigation, although Reuters could not determine how many attempted intrusions were successful.
That broader campaign demonstrates the uncomfortable lesson behind the latest law-firm breaches: cybersecurity does not always fail because attackers discover an exotic software vulnerability.
Sometimes they simply convince someone to open the door.
The bigger question for major law firms
The Quinn Emanuel and McDermott incidents may ultimately prove limited in scope. Both firms say the unauthorized access was contained, involved limited information and is no longer continuing.
But their disclosures arrive amid a steady stream of incidents across the legal sector, suggesting that the larger issue will not disappear with the resolution of two individual breaches.
For law firms, cybersecurity has increasingly become inseparable from the promise of client confidentiality.
The industry can invest in stronger networks, multifactor authentication and sophisticated security software. Yet social engineering targets something technology cannot completely remove from the equation: human trust.
And as attackers increasingly realize that one compromised law-firm account can potentially unlock information involving numerous companies, cases and individuals, the question facing the legal industry is becoming more urgent:
How many other firms are being targeted — and how many breaches have not yet become public?

Leave a Reply