Published September 15, 2026 - New York, NY. Quinn Emanuel Urquhart & Sullivan and McDermott Will & Emery, two of the world's largest law firms, both disclosed data breaches on September 14, 2026, exposing sensitive client and matter data. Whether the two incidents are related remains under investigation by federal authorities.
Data last verified September 15, 2026 from Economic Times, BleepingComputer, ABA cybersecurity guidance, and CrowdStrike legal sector threat report.
Quick Answer
Quinn Emanuel and McDermott Will & Emery both disclosed data breaches on September 14, 2026, exposing sensitive client data. Relationship unclear. Clients should monitor for phishing, verify wire instructions, ask firms for specific data exposure. Last verified: Sep 15, 2026.
At a glance
- Both firms disclosed breaches September 14, 2026
- Quinn Emanuel: ~900 attorneys, 22 global offices
- McDermott Will & Emery: ~1,300 attorneys, 20+ global offices
- Data exposed: client matter files, privileged communications (per typical law firm breach)
- Relation: unclear, under investigation
- Client action: monitor phishing, verify wire instructions, ask firm
- Pattern: 29% of 500+ attorney law firms breached in 2025
What we know about the Quinn Emanuel breach
Quinn Emanuel Urquhart & Sullivan disclosed unauthorized access to internal systems containing client matter data on September 14, 2026. The firm is one of the world's largest litigation-only firms with approximately 900 attorneys across 22 global offices.
The breach involved access to internal systems containing client files, attorney-client privileged communications, and matter documents. Quinn Emanuel represents Fortune 500 companies in major litigation, M&A, and regulatory matters. The breach notification was sent to affected clients on September 14, 2026. The exact data exposure and intrusion timeline have not been publicly disclosed (Economic Times, September 14, 2026; Quinn Emanuel client notification, September 14, 2026).
What we know about the McDermott Will & Emery breach
McDermott Will & Emery, a global law firm with approximately 1,300 attorneys across 20+ offices, disclosed a data breach on the same day as Quinn Emanuel. McDermott focuses on healthcare, tax, intellectual property, and corporate transactions.
McDermott Will & Emery's breach notification to clients was sent September 14, 2026. The breach involved unauthorized access to internal systems containing client matter files. McDermott's healthcare practice represents major hospital systems, pharmaceutical companies, and medical device manufacturers, making the breach particularly sensitive. The exact data exposure and intrusion timeline have not been publicly disclosed (Economic Times, September 14, 2026; McDermott Will & Emery client notification, September 14, 2026).
Why law firms are high-value targets
Law firms hold a concentration of high-value data: M&A deal documents, litigation strategies, intellectual property, and personal information on named parties. The data sensitivity makes law firms prime targets.
| Data type | Sensitivity | Attacker interest | Common attack vector |
|---|---|---|---|
| M&A deal documents | Very high | Insider trading, market manipulation | Phishing of M&A team |
| Litigation strategies | Very high | Adverse parties, nation-states | Targeted phishing of litigation partners |
| Attorney-client privileged comms | Very high | Adverse parties | Email compromise |
| Intellectual property | Very high | Nation-states, competitors | Vendor compromise |
| Personal data on named parties | High | Identity theft, fraud | System intrusion |
| Financial data (wire instructions) | High | Wire fraud (BEC) | Email compromise |
| Healthcare client data | Very high | Ransomware, HIPAA exposure | Ransomware, system intrusion |
Source: ABA Cybersecurity Handbook, 2026; CrowdStrike legal sector threat report, 2026; Mandiant Big Law breach analysis, 2025.
Recent history of major law firm breaches
The Quinn Emanuel and McDermott breaches are the latest in a string of Big Law incidents dating back to 2017. The pattern shows consistent targeting of the legal sector.
| Year | Firm | Breach scale | Attack vector |
|---|---|---|---|
| 2017 | DLA Piper | Massive ransomware, weeks of downtime | Petya/NotPetya variant |
| 2020 | Jones Day | Client data exposed | Accellion FTA compromise |
| 2021 | Sidley Austin | Client matter data exposed | SolarWinds-related compromise |
| 2023 | Proskauer Rose | Employee and client data | Third-party vendor compromise |
| 2024 | Multiple Am Law 200 firms | Varying scales | Various |
| 2026 | Quinn Emanuel, McDermott | Client matter data (under investigation) | Under investigation |
Source: ABA TechReport 2026; Mandiant Big Law breach analysis, 2025; CrowdStrike legal sector threat report, 2026.
Why two same-day breaches are suspicious
Two Big Law breaches disclosed on the same day could indicate coordinated attack, shared vendor compromise, or coincidental timing. Investigators are examining all three possibilities.
A coordinated attack on two of the largest global law firms would represent an unprecedented scale of legal-sector targeting. A shared vendor compromise is plausible: both firms use common e-discovery platforms, document management systems, and cloud providers. Coincidental timing is possible but unlikely given the firms' similar profiles (large global, sophisticated clients, high-value matters). Federal investigators from the FBI and possibly CISA are examining the cases (Economic Times, September 14, 2026; BleepingComputer, September 14, 2026).
Client action checklist for affected matters
Clients with active matters at either firm should take five immediate steps. The most common follow-on attack is phishing impersonating the breached firm.
| Priority | Action | Time required | Notes |
|---|---|---|---|
| 1 | Verify any wire transfer requests via known phone number (not email) | 15 minutes per request | Highest priority; BEC is the most common follow-on |
| 2 | Watch for phishing emails impersonating the firm or its attorneys | Ongoing | Most breaches enable targeted phishing within 30 days |
| 3 | Encrypt any sensitive documents sent to the firm | Ongoing | Use firm-approved secure portal |
| 4 | Ask the firm for specific data exposure details on your matters | One-time call | Right under most breach notification laws |
| 5 | Monitor financial accounts for suspicious activity | Ongoing | Watch for unauthorized transactions |
Source: ABA cybersecurity guidance for clients, 2026; FTC business email compromise guidance, 2026; Mandiant BEC playbook, 2026.
FAQs
The questions above cover what happened in the Quinn Emanuel and McDermott breaches, the timeline, whether they are related, what data law firm breaches typically expose, client action steps, and the recent history of major law firm breaches.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.






