Global law firms Quinn Emanuel and McDermott Will & Emery have confirmed unauthorized access to client files due to social engineering. Both firms have notified authorities, highlighting rising cybersecurity vulnerabilities in the legal sector. These incidents underscore the growing risks for professional service firms handling sensitive and high-stakes confidential data.
Global law firms Quinn Emanuel Urquhart & Sullivan and McDermott Will & Emery have disclosed that they were recently subjected to data security breaches. Both organizations confirmed that unauthorized third parties gained access to certain client information through social engineering attacks. These incidents have raised renewed concerns regarding the cybersecurity defenses of high-profile legal practices that manage vast amounts of confidential and sensitive business data.
In the case of Quinn Emanuel, the firm reported that an unauthorized party accessed files through a compromised user account in mid-August. The breach specifically impacted documents related to a court case in Florida involving short-seller Muddy Waters. McDermott Will & Emery also confirmed a separate security incident involving unauthorized access to a restricted set of documents. In this instance, the exposed information reportedly included sensitive identifiers such as Social Security numbers and personal health information. Both firms have confirmed that they have notified law enforcement and secured their internal systems.
Escalating Cyber Risks in the Legal Sector
The legal sector is increasingly becoming a primary target for cybercriminals. Law firms are viewed as high-value repositories for information involving corporate mergers, intellectual property disputes, high-stakes litigation, and financial strategy. Because these firms hold significant volumes of non-public, material information, they are often seen as strategic targets for both state-sponsored actors and organized criminal groups.
The recent breaches at Quinn Emanuel and McDermott are not isolated events but part of a broader, systemic trend across the professional services industry. Throughout 2026, multiple legal organizations have reported similar security challenges, forcing many to re-evaluate their reliance on third-party software and internal employee verification protocols. Security experts note that social engineering—where attackers manipulate individuals into divulging confidential information—remains a highly effective tactic, often bypassing even sophisticated technical firewalls.
Impact on Clients and Corporate Governance
For corporate clients, these incidents serve as a critical reminder of the importance of conducting thorough due diligence regarding the data security practices of their legal representatives. A breach at a law firm can lead to the exposure of trade secrets, pending litigation strategies, and regulatory filings, which can have downstream effects on a client’s valuation, market position, and compliance standing. As legal firms continue to move more of their document management and discovery processes to cloud-based systems, the attack surface for potential vulnerabilities is expanding.
Moving forward, the primary monitorable for the industry will be how these firms and their peers strengthen their digital infrastructure. The focus is expected to shift toward more rigorous multi-factor authentication, enhanced employee training to detect social engineering attempts, and stricter third-party vendor audits. While these firms are private entities and not publicly traded, the reputational and operational impact of such breaches remains a significant factor for the organizations and their corporate partners worldwide.
