TechNewsReel
Live

Quinn Emanuel and McDermott Law Firms Hit by Social Engineering Breaches

Two prominent legal firms reported data exposures after attackers compromised individual user accounts.

TechNewsReel Newsroom · September 4, 2026

Prominent law firms Quinn Emanuel and McDermott have both suffered data breaches resulting from social engineering attacks. The incidents highlight the ongoing vulnerability of high-stakes legal environments to targeted credential theft.

According to reports, the breaches were isolated events involving the compromise of single user accounts. At Quinn Emanuel, the breach occurred on August 14, when unauthorized access was gained to stored files for one specific software application. This exposure included files related to the short seller Muddy Waters. Similarly, McDermott reported its breach to the Vermont state attorney general, confirming that the exposed data included health information and Social Security numbers.

The Vulnerability of Legal Data

Law firms are increasingly viewed as high-value targets for cybercriminals because they serve as central repositories for sensitive client data, intellectual property, and confidential litigation strategies. Unlike direct attacks on corporate infrastructure, social engineering targets the human element, tricking employees into revealing credentials to bypass technical security perimeters. This method allows attackers to enter a network with legitimate permissions, making detection more difficult until data has already been exfiltrated.

Industry Implications

Breaches at top-tier firms like Quinn Emanuel and McDermott carry significant risks due to the nature of attorney-client privilege. The exposure of privileged communications or corporate secrets can jeopardize active legal proceedings and damage the trust between firms and their high-profile clients. When Social Security numbers and health data are involved, as seen in the McDermott case, the risk extends beyond corporate espionage to identity theft and personal privacy violations for the individuals involved.

Current Status

Both firms have stated that the incidents were limited to single users and that their systems are now secure. While the immediate technical gaps have been closed, the incidents serve as a reminder of the persistent threat posed by social engineering. Industry observers will be watching for further disclosures regarding the full scope of the data accessed and whether these breaches were part of a broader campaign targeting the legal sector.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.