One Device, 57,000+ Records, and a Lawsuit That's Still Growing
Fox Rothschild's breach came from a single compromised device in May. The resulting class action is still expanding in August. Here's what that gap says about incident response planning.
In late May, one attorney at Fox Rothschild – an AmLaw 100 firm – fell for a social engineering call. Firm partner Mark McCreary later described the incident as limited to a single device, with no broader access to the firm's systems or network. By most technical measures, that's a contained incident.
It hasn't stayed contained.
A small technical footprint, a large and growing legal one
At least 57,554 individuals were ultimately affected and were not notified until the end of June – roughly a month after the incident occurred. On June 9, a proposed class action, Trotter v. Fox Rothschild, filed in the U.S. District Court for the Eastern District of Pennsylvania, alleged that the firm failed to adequately protect sensitive personal data, including Social Security numbers, entrusted to it. Fox Rothschild is reviewing the matter.
What makes the story worth revisiting now is what happened on August 11 – nearly three months after the original incident. A California resident asked the court to add a new subclass claim under the California Consumer Privacy Act to the same case. The lawsuit is not winding down. It is still picking up scope.
Fox Rothschild is one entry in a wider pattern this year. Weil Gotshal, WilmerHale, Goodwin Procter, and others were hit by the same group – tracked as Silent Ransom Group, Luna Moth, or Chatty Spider – in the same general window. Google's Mandiant and Threat Intelligence Group reported in August 2026 that the group's targeting had expanded beyond law firms into professional services and financial services more broadly. That suggests this is not a legal-industry-specific problem so much as a legal-industry-prominent one right now.
Why the gap between incident and outcome matters
A single compromised device is the kind of failure that can happen at a firm of any size. It does not take a sophisticated network intrusion, just one person answering a convincing phone call. What determines how costly that moment becomes afterward often has less to do with the initial technical scope and more to do with what happened next: how quickly the incident was identified, how notification was handled, and what the firm can point to as evidence of reasonable safeguards beforehand.
That is not a statement about Fox Rothschild's specific conduct, which remains a contested allegation in active litigation. It is a general pattern worth every firm's attention: the technical incident is usually smaller and faster than the legal and reputational tail that follows it. The firms best positioned to manage that tail are the ones that already had an incident response plan, breach notification procedure, and documentation of their safeguards before they needed them – not documents assembled after the fact under pressure.
What smaller firms can prepare before they need it
Incident response planning is not just a document for a crisis binder. It should answer practical questions while everyone is still calm:
- Who gets called first? Name the internal decision-maker, IT contact, outside counsel, cyber insurer, and forensic contact before an incident occurs.
- What gets preserved? Define how the firm will preserve logs, devices, emails, call records, and other evidence without destroying useful information during cleanup.
- Who decides whether notification is required? Establish the handoff between firm leadership, counsel, the insurer, and any forensic team so deadlines are not discovered in the middle of the crisis.
- What can the firm prove? Keep current evidence of safeguards such as access controls, email protections, staff training, device restrictions, and vendor procedures.
- Has anyone practiced the plan? A short tabletop exercise can expose unclear responsibilities long before a real incident makes those gaps expensive.
The goal is not to promise that a firm can prevent every social engineering call. It is to make sure one successful call does not become an improvised legal, client-notification, and reputational response.
Where to start
Our Documentation & Compliance services cover incident response plans, tabletop exercises, cybersecurity documentation, and related readiness work for law firms. The work is fixed-scope and designed to give partners a clear picture of what exists, what is missing, and what can be shown to insurers or clients.
If you want to start with the public side of the problem, the free Proprietary Exposure Review uses public DNS and web records only. It requires no credentials or private-system access, sends results only to the verified work inbox that requested them, and retains your submitted domain only during the verification window, typically up to 60 minutes. The report is never saved, and we only keep the requesting work email for follow-up purposes.
This article is informational and does not constitute legal advice. Details regarding the Fox Rothschild matter are drawn from public court filings and news reporting, including Law360 and DataBreaches.net; the litigation involves contested allegations, and Fox Rothschild has not been found liable.
