BlackTree Security · Infrastructure · Automation · AI

One User Was Enough: Two Law-Firm Breaches Exposed Client Files, SSNs and Health Data

One temporarily compromised account at Quinn Emanuel and one socially engineered user at McDermott were enough to expose sensitive legal and personal data. Client documents, Social Security numbers and health information were among the affected material.

The incidents are not known to be connected, and neither firm described a firm-wide compromise. That makes the lesson more uncomfortable, not less: an attacker may not need the whole network when one trusted path already reaches valuable information.

At Quinn Emanuel, a temporarily compromised user account reached stored files in one software application, including a limited number of client documents. At McDermott, a user inadvertently provided copies of a limited number of documents to an unauthorised person; regulatory filings identify Social Security numbers and health information among the affected data.

A breach can be narrow in infrastructure terms and still be severe in information terms. At a law firm, the value of access is defined by the matters, evidence and personal records it can reach, not by how many systems the attacker touched.

These were separate incidents

Reuters reported the two disclosures together on 3 September 2026, but the available evidence does not establish a shared campaign.

Quinn Emanuel said an unauthorised third party obtained access through social engineering on 14 August. The attacker used a temporarily compromised account to reach files stored in one software application. Some of the affected material related to short seller Muddy Waters and had been obtained through litigation in Florida.

The firm said a limited number of client documents were affected, that the relevant parties had been notified and that unauthorised access had ended. Quinn Emanuel has not publicly described the exact social-engineering technique, the affected application or whether the attacker obtained credentials, an active session or assistance through an account-recovery process.

McDermott separately said it responded to an isolated social-engineering incident involving one user and a limited number of documents. The firm engaged cybersecurity specialists and law enforcement and says the matter has been resolved.

Regulatory records add important context. McDermott’s filing with Vermont lists Social Security numbers and health records and counts 15 Vermont residents. A Massachusetts breach tracker lists 1,658 Massachusetts residents. Those state-specific figures should not be treated as a nationwide total, and the public notices do not establish that every affected person had every listed data element exposed.

The phrase limited can hide the real risk

Incident reports often use system scope as shorthand for severity. One account sounds better than an entire identity platform. One application sounds better than the whole network. A limited number of documents sounds better than a bulk database extraction.

For legal services, that framing can be misleading. A single matter workspace can contain privileged communications, litigation strategy, witness details, medical evidence, financial records, acquisition material or information produced under a protective order. The account does not need broad administrative privileges if it already has legitimate access to the files an attacker wants.

The two incidents illustrate different forms of information sensitivity. Quinn Emanuel’s disclosure concerns client material associated with active litigation. McDermott’s regulatory filings concern personal information that can support identity theft, medical fraud or highly tailored impersonation. The records are not interchangeable, but both demonstrate why document-level exposure matters more than a simple device or account count.

Social engineering is a control-path failure

Calling an incident social engineering can imply that one employee made a mistake. That is too narrow a lesson.

Attackers can manipulate password resets, help desks, multifactor authentication prompts, remote-support workflows and trusted collaboration channels. Training remains useful, but it cannot be the only control between a convincing conversation and confidential client files.

Law firms should assume that an attacker will eventually reach a busy employee with a credible pretext. The more important question is what happens after the employee responds. The same access-first pattern appears in BlackTree’s analysis of the Jack Henry vishing incident, where the critical boundary was trusted identity rather than an exploited software flaw.

  • Use phishing-resistant authentication. Passkeys and hardware-backed security keys reduce dependence on passwords, codes and push approvals that can be relayed or socially engineered.
  • Harden account recovery. Password and multifactor resets need strong identity verification, dual control for high-risk users and alerts that reach the employee through a separate channel.
  • Restrict access by matter. An account should reach the cases and document repositories required for current work, not every historical file associated with a practice group.
  • Watch sessions, not only logins. New devices, unusual downloads, bulk file access, token reuse and access outside normal working patterns can expose an intrusion after authentication succeeds.
  • Retain application audit evidence. Identity logs are not enough. Firms need document-level records showing what was viewed, downloaded, shared or deleted inside legal and collaboration platforms.
  • Revoke access comprehensively. Resetting a password does not necessarily invalidate existing sessions, application tokens, delegated permissions or files copied to a synchronised device.

Client notification depends on knowing which files moved

Legal repositories rarely contain one consistent data schema. A database breach may expose predictable fields. A document breach can involve contracts, correspondence, exhibits, employee records and case-specific evidence with different legal and practical consequences.

That makes scoping slower and more important. The affected firm must determine which documents were accessible, which were actually opened or downloaded, whose information they contained and which contractual, ethical or regulatory duties apply. A statement that only a limited number of documents were involved does not answer those questions.

Clients should ask for evidence relevant to their own material: the affected application, access window, document names or categories, confirmed download activity, containment actions and whether the compromised account had access to other matters. The consequences of exposing legal records are also visible in BlackTree’s coverage of the Thomson Reuters C-Track court-records breach.

The BlackTree view

These incidents are not evidence that every system at either firm failed. They show something more operationally useful: one successful identity compromise can be enough when the account already sits beside concentrated, high-value information.

The right measure is not how many accounts were compromised. It is how much authority each account carried, which repositories trusted it and whether the firm can prove what happened after authentication.

In professional services, least privilege must reach the document and matter layer. Otherwise, the organisation can truthfully describe a breach as isolated while clients still face consequences that are anything but limited.

Sources and publication details

Leave a Reply

Your email address will not be published. Required fields are marked *