Quinn Emanuel Urquhart & Sullivan and McDermott Will & Schulte each said they suffered recent data breaches and notified law enforcement. Reuters reported the disclosures on September 3. It was not clear who was behind the two incidents or whether they were connected.
McDermott reported its incident last week to the Vermont attorney general. The filing said Social Security numbers and health data were among the firm files involved. McDermott called it “an isolated social engineering incident involving a single user and a limited number of documents.” It said it worked with cybersecurity specialists and law enforcement and that systems were secure again.
Law.com later put the two notices at the end of a rough stretch: at least ten large U.S. firms reported breaches between Memorial Day and Labor Day, many of them starting with a person rather than a smashed perimeter.
Why a law firm breach is not a generic SaaS incident
The files in these shops are other people’s secrets: litigation strategy, deal drafts, medical facts produced in discovery, tax identifiers sitting in a matter workspace. Privilege does not disappear because the copy lived on a firm server. A notice to “affected parties” is also a notice that opposing counsel, a regulator, or a plaintiff’s firm may soon ask what left the room.
Quinn’s Muddy Waters letter makes that concrete. The short seller is already in a fight with the firm over loyalty and conflicts in other matters. A breach letter that names the client’s litigation files becomes part of that docket whether anyone wants it there or not. Quinn has denied Muddy Waters’ conflict claims and said one attorney briefly represented the fund on a different matter.
McDermott’s Vermont filing is the other typical path. State AG portals are how many firms satisfy multi-state notice when SSNs or medical information are in the mix. Health data in a law-firm store is still health data under state breach statutes. “Limited number of documents” does not shrink the category.
What other firms should copy from the statements, and what they should not
Both firms used the same skeleton: one user, one application or a limited document set, outside help, law enforcement, systems now locked. That language is now standard. It does not answer how long the account was live, whether the same play was tried on other users, or whether matter-level access controls would have stopped a single mailbox from opening a Florida production set.
Clients that keep large productions at outside counsel should ask which application held their files, whether the compromised account had standing access or a one-off grant, and whether the firm’s logging shows what was copied. Ethics rules on safeguarding client property and confidentiality do not wait for a ransomware note. A social-engineering incident is still a competence and supervision problem under the rules that already govern the firm.
Reuters was careful not to treat the two events as one campaign. Firms should be just as careful before they assume their summer was unique. Ten shops in one season is a pattern. The shared fact is not a named gang. It is that one person with access to the document store remains enough.