Two Major Law Firms Hit by Cyber Breaches
Hackers used social engineering tricks to break into systems at Quinn Emanuel and McDermott, putting sensitive client data at risk.
Two well-known U.S. law firms, Quinn Emanuel and McDermott, announced on Thursday that hackers had broken into their computer systems and stolen private data. Both firms told law enforcement about the breaches. Law firms hold a lot of sensitive information about their clients, which makes them popular targets for cybercriminals. It is not yet known who carried out the attacks or whether the two incidents were connected.
Quinn Emanuel said that on August 14, an unauthorized third party gained access to its systems through a trick called social engineering. In a letter dated August 25, the firm told a lawyer for a company called Muddy Waters that some of its files had been accessed. Quinn Emanuel later confirmed that only one user account was temporarily compromised, and that a limited number of client documents were affected. The firm said there is no longer any unauthorized access to its systems.
Muddy Waters is a company that bets against stocks, known as a short seller. It had already asked a judge to remove Quinn Emanuel from a lawsuit in Texas, claiming the firm had a conflict of interest. When Muddy Waters learned about the breach, it was furious, saying Quinn Emanuel failed to protect its sensitive information. The two sides clearly disagree on what happened and what it means.
McDermott reported its breach to Vermont's state attorney general last week. The firm said the hack affected files that included Social Security numbers and health data. McDermott called it an isolated social engineering incident involving a single user and a limited number of documents. The firm said it brought in cybersecurity experts to help investigate and also worked with law enforcement.
Both Quinn Emanuel and McDermott described the attacks as social engineering hacks. This type of attack works by tricking people into giving away passwords or granting access to secure systems, rather than breaking through technical defenses. McDermott said the problem has been fully resolved and its systems are now secure. The firm stressed that protecting client and firm information remains its top priority.
These two firms are not alone in facing such threats. At least three other law firms — Herbert Smith Freehills Kramer, Goodwin Procter, and WilmerHale — also reported data breaches recently. WilmerHale was sued in July in a class action lawsuit over its breach, meaning a large group of people joined together to take legal action. The wave of attacks shows that law firms across the country are facing growing cybersecurity dangers.
The confidentiality and privacy of our client and firm information continue to be our highest priority.
Comprehension quiz preview
1. Which two law firms announced data breaches on Thursday?
2. What type of attack was used to break into both law firms' systems?
3. What kind of personal data was found in McDermott's breached files?