Two major U.S. law firms recently reported data breaches.
The firms are Quinn Emanuel and McDermott Will & Emery. Both firms said hackers used social engineering in separate cases.
In addition, both firms told law enforcement about the breaches. They also took steps to check their systems.
The two events do not appear linked. So far, no one has named those behind the attacks.
At the same time, the breaches show a wider risk for law firms. Firms hold large amounts of private client data. As a result, they can attract cybercriminals.
Key Takeaways
- Quinn Emanuel reported a breach on Aug. 14.
- A stolen user account gave an attacker file access.
- Some files tied to Muddy Waters were affected.
- McDermott reported a separate breach.
- Some McDermott files held Social Security numbers.
- Other files held health data.
- Both firms called the breaches limited.
- Overall, the cases show the cyber risks for law firms.
Quinn Emanuel Data Breach
Quinn Emanuel said an attacker accessed files on Aug. 14.
According to the firm, the attacker used social engineering. The attacker also used one user account to reach the files.
Quinn Emanuel shared details in an Aug. 25 letter to a lawyer for Muddy Waters.
Some files involved Muddy Waters. Quinn Emanuel had those files from a case in Florida.
However, the firm said the attacker no longer had system access.
Limited Client Files Affected
Quinn Emanuel said the breach affected a limited number of client files.
The firm also told the people linked to the affected data. Furthermore, it said the attacker lost access.
Meanwhile, Quinn Emanuel faces a separate dispute with Muddy Waters.
Muddy Waters asked a Texas judge to remove the firm from a case. The company said Quinn Emanuel had worked for it in related matters.
However, Quinn Emanuel rejected that claim. The firm said one lawyer had worked for Muddy Waters on another matter.
Muddy Waters Objects
Muddy Waters criticized Quinn Emanuel after learning about the breach.
The company said the firm failed to protect its sensitive data. However, Quinn Emanuel did not comment on that claim.
Meanwhile, the firm still denies the conflict claim from Muddy Waters.
Therefore, the breach adds another issue to the dispute.
McDermott Reports Breach
McDermott reported a separate breach to the Vermont attorney general in late August.
According to the firm, the breach involved files with Social Security numbers. Some files also held health information.
McDermott called the event an isolated social engineering attack. The firm said one user and a small number of files were involved.
In response, McDermott hired cybersecurity experts. It also worked with law enforcement.
McDermott said it fixed the issue. In addition, the firm said its systems remain secure.
Sensitive Data Was Involved
The type of data makes the McDermott breach serious.
For example, Social Security numbers can increase identity theft risks. Likewise, health data can create privacy risks.
For that reason, firms must act fast after a data breach.
First, they must find the data the attacker accessed. Next, they must identify affected people.
Finally, firms must check if the law requires notices.
What Is Social Engineering?
Social engineering means tricking people into giving access to data or systems.
For example, an attacker may pretend to be a client. The attacker may then ask an employee to share data.
As a result, the attack can work even when a firm has strong security tools.
Therefore, staff training remains vital.
The two breaches show this risk. In other words, attackers can target people instead of the firm’s main systems.
Why Hackers Target Law Firms
Law firms hold a lot of private data.
For example, their files may include court records, financial data and client details. They may also hold private emails and business plans.
In addition, lawyers handle many cases at once. One account may therefore open files from several matters.
Cybercriminals may use this data for fraud or other crimes.
As a result, law firms must protect each user account.
More Law Firms Face Cyber Risk
The Quinn Emanuel and McDermott breaches are not the only recent cases.
In August, at least three other law firms reported data breaches to state regulators. They included Herbert Smith Freehills Kramer and Goodwin Procter.
Meanwhile, WilmerHale faced a proposed class-action case in July after a data breach.
Taken together, these cases show that cyber risk remains a major issue for law firms.
Cybersecurity Can Create Legal Jobs
The rise in cyber threats also creates work for lawyers.
Today, attorneys handle more privacy and data security cases. Therefore, lawyers with these skills may find new career paths.
Law firms also need lawyers who can help clients after a cyber attack.
For example, these lawyers can review legal duties and help with breach response. They can also help clients deal with regulators.
As demand grows, cybersecurity law may offer more work for legal professionals.
Lessons for Law Firms
The two breaches offer clear lessons for law firms.
1. Protect User Accounts
One stolen account can expose private files.
Therefore, firms should use strong login tools. They should also review user access often.
2. Limit File Access
Not every worker needs access to every file.
Instead, firms can give access based on job duties. They can also limit access to active cases.
As a result, firms can reduce harm from a stolen account.
3. Train Lawyers and Staff
Training can help workers spot social engineering attacks.
For example, staff should learn to spot fake emails. They should also learn how to report odd requests.
In turn, better training can lower the risk of a breach.
4. Plan for Data Breaches
Law firms should create a breach plan before an attack.
For this reason, the plan should name the people who lead the response. It should also cover evidence, clients and law enforcement.
With a clear plan, firms can respond faster.
5. Protect Client Trust
A data breach can harm a firm’s reputation.
Clients expect firms to protect private data. Therefore, firms should provide clear updates after an attack.
More importantly, a fast response can help protect client trust.
Impact on Law Firms
The two cases show how one account can create a serious risk.
Both firms called their incidents limited. However, the data included client files and personal information.
Neither firm has said that its wider systems remain under attack.
Even so, the cases show why firms must improve cyber defenses.
Going forward, firms should secure user accounts and limit file access. They should also train staff to spot social engineering.
Most importantly, cybersecurity must remain a core business issue.
FAQs
What happened at Quinn Emanuel?
Quinn Emanuel reported unauthorized file access on Aug. 14.
According to the firm, an attacker used social engineering and one user account. As a result, a limited number of client files were affected.
What data did the Quinn Emanuel breach involve?
Some affected files involved Muddy Waters.
The firm had obtained those files during litigation in Florida. However, Quinn Emanuel said only a limited number of client documents were affected.
What happened at McDermott?
McDermott reported a separate social engineering incident.
The firm said one user and a limited number of files were involved. In addition, some files contained Social Security numbers and health information.
Were the two breaches connected?
There is no public evidence that the incidents were connected.
Instead, the firms reported separate events. So far, authorities have not named those behind the attacks.
What does social engineering mean?
Social engineering involves tricking people into giving access to data or systems.
For example, attackers may pretend to be clients or co-workers. They then try to make employees take unsafe actions.
Why do hackers target law firms?
Law firms hold large amounts of valuable data.
For example, their files can contain financial records, legal documents and personal data. In addition, they may hold private client communications.
Therefore, cybercriminals may see law firms as valuable targets.
Are other law firms facing cyber attacks?
Yes. Other firms have also reported recent cyber incidents.
For instance, Herbert Smith Freehills Kramer and Goodwin Procter reported breaches to state regulators in August. Meanwhile, WilmerHale faced a proposed class action after a July data breach.
Overall, these cases show why law firms must keep improving their cybersecurity.
Looking for your next legal career move?
LawCrossing connects legal professionals with current attorney and law firm jobs. Explore new opportunities and find roles that match your skills and career goals.
See Also:
Trump’s Bold Push to Punish Race-Conscious SchoolsThe post
Sensitive Data Exposed in Law Firm Cyber Breaches first appeared on
JDJournal Blog.