NEW YORK, United States: Data breaches at law firms Quinn Emanuel and McDermott exposed sensitive files following separate social engineering incidents, the firms said on September 3.
Quinn Emanuel Urquhart & Sullivan said an unauthorised third party gained access to stored files for one software application. The attacker used a temporarily compromised user account on August 14.
The firm disclosed the incident in an August 25 letter to a lawyer for short seller Muddy Waters. Reuters reported that some exposed files concerned Muddy Waters and came from a Florida lawsuit.
Quinn Emanuel said the attacker obtained access through social engineering. The firm also notified law enforcement. McDermott Will & Emery separately reported an incident involving one user and a limited number of documents
. A filing with the Vermont Attorney General said the exposed information included Social Security numbers and health data. McDermott said cybersecurity specialists helped investigate the breach.
Read: Jensen Huang AI Regulation Advice Targets Actual Harm
The firm also contacted law enforcement and said it had resolved the incident. “The matter has been resolved,” McDermott said, adding that its systems remained secure.
Social engineering attacks typically rely on manipulating people into revealing information or granting access to protected systems.
Other major law firms have disclosed similar incidents in recent months. Herbert Smith Freehills, Kramer and Goodwin Procter reported breaches to U.S. state regulators in August.
Read: Musk AI Prediction Sees Superhuman Digital Skills by 2027
Wilmer Hale also faced a proposed class-action lawsuit in July over a separate data breach. Reuters said it was unclear who carried out the attacks on Quinn Emanuel and McDermott, or whether the two incidents were connected.