Published September 15, 2026 - Washington. Quinn Emanuel Urquhart & Sullivan and McDermott have confirmed data breaches that exposed client files, Social Security numbers and health data, capping a summer in which at least 10 major US law firms disclosed cyber incidents, most of them involving social engineering.
At a glance
- Quinn Emanuel says an unauthorized third party accessed stored files for a single software application through one temporarily compromised user account, with a limited number of client documents impacted.
- An August 25 letter says files related to short seller Muddy Waters, obtained in a Florida lawsuit, were among the exposed material after an August 14 social engineering intrusion.
- McDermott reported its breach to the Vermont attorney general and said affected files included Social Security numbers and health data.
- Reuters says it is unclear who was responsible or whether the two breaches are related; Law.com counts at least 10 Big Law breaches between Memorial Day and Labor Day.
- Social engineering of individual users - not exotic zero-days - is the common thread across the legal industry this summer.
Data last verified September 15, 2026 from Reuters, Law360, Law.com and Cybernews.
Quick Answer
Two of the most prominent US law firms have confirmed breaches built on social engineering, and they are the tail end of a broader wave. Quinn Emanuel says a single temporarily compromised user account exposed stored files in one software application, including material tied to Muddy Waters litigation. McDermott says an isolated social engineering incident involving a single user exposed a limited number of documents including Social Security numbers and health data. Neither firm has attributed the incidents, and Reuters reporting indicates it is unclear whether they are connected. For clients, the practical takeaway is that confidential legal material may now be in unauthorized hands, and notifications should be taken seriously.
What happened at the two law firms
The firms went public with statements on Thursday, September 3, 2026. Quinn Emanuel told reporters it identified a data security incident involving unauthorized access to stored files for a single software application through one temporarily compromised user account, that a limited number of client documents were impacted, that affected parties have been informed, and that there is no ongoing unauthorized access to its systems.
The backstory emerged through litigation correspondence. In an August 25 letter to a lawyer for short seller Muddy Waters, viewed by Reuters, Quinn Emanuel said an unauthorized third party obtained access through social engineering on August 14, and that some of the information exposed involved Muddy Waters files the firm had obtained in a lawsuit in Florida. The letter surfaced amid a separate fight in which Muddy Waters had asked a judge to bar Quinn from a lawsuit against the short seller in Texas over prior representation. Muddy Waters did not hold back, saying the firm had failed to protect its sensitive information from social engineering hacking. Quinn Emanuel declined to comment on that statement.
McDermott, meanwhile, had reported its breach to the Vermont state attorney general the week before, saying affected files included Social Security numbers and health data. In its statement, the firm described an isolated social engineering incident involving a single user and a limited number of documents, investigated with assistance from cybersecurity experts and with law enforcement engaged. The firm says the matter has been resolved and its systems remain secure.
Who is affected
Directly affected are clients of both firms whose documents sat in the compromised files - potentially including litigation material, deal documents and, at McDermott, personal data such as Social Security numbers and health information of individuals connected to the firm. Under state breach notification laws, affected individuals should receive direct notices, and the Vermont filing signals that process is underway.
The wider context is more alarming than any single incident. Law.com counts at least 10 Big Law firms reporting data breaches between Memorial Day and Labor Day 2026, many involving social engineering. At least three other firms, including Herbert Smith Freehills Kramer and Goodwin Procter, disclosed breaches to US state regulators in August, and WilmerHale was sued in a class action following its own breach. Large law firms hold exceptionally concentrated stores of confidential business and personal data - trade secrets, M&A terms, witness statements, health records - which makes them attractive targets for cybercriminals and, potentially, nation-state collectors.
How to check if you are affected
If you are a client or adverse party in matters handled by either firm, watch for formal breach notification letters, which typically arrive by mail and describe the categories of data involved. If you were an individual whose personal data was in McDermott files, the notice should explain exposure of Social Security numbers and health data and any remediation offered, such as credit monitoring.
Even without a letter, anyone litigating active matters should assume that confidential filings could circulate more widely than usual this year, given the volume of law firm incidents in 2026. Ask your attorneys directly what document management and verification controls their firm uses.
What to do next
For law firms and their clients, the summer of 2026 points to a short list of priorities:
- Treat social engineering as the primary attack vector: train staff on manipulation attempts by phone, email and messaging, and verify unusual document requests out of band.
- Enforce least privilege on document management systems so one compromised account cannot reach broad stores of client files.
- Require phishing-resistant multi-factor authentication for lawyers and staff, and use a business-grade password manager to eliminate reused credentials.
- Prepare breach response playbooks now, including state attorney general notification timelines and outside forensics counsel.
- Clients receiving notices should accept credit monitoring where offered, monitor financial accounts, and be alert for phishing that references real case details.
- Boards should ask their firms for evidence of cyber insurance and incident response retainers, not just assurances.
The Quinn Emanuel and McDermott breaches are a reminder that in professional services, the weakest link is rarely the firewall - it is a single person being tricked at the right moment. Firms that rehearse for that moment will fare better than firms that only patch servers.






