Quinn Emanuel and McDermott Breaches: One Account Can Be Enough
Quinn Emanuel and McDermott reported social engineering breaches involving one user. Here is what smaller law firms should verify now.
One user. One application. A limited number of documents.
That description may sound reassuring. For a law firm, it should still command attention.
Reuters reported on September 3, 2026 that Quinn Emanuel and McDermott each experienced a recent data breach involving social engineering. Both firms said the incident involved a single user and a limited set of documents. Both contacted law enforcement.
At this point, there is no public evidence that the incidents were connected, and the responsible party or parties have not been identified. Even so, the similarities point to the same practical lesson:
What the firms reported
Quinn Emanuel said an unauthorized party gained access on August 14 through social engineering. A temporarily compromised user account allowed access to files stored in one software application, including documents involving short seller Muddy Waters. The firm said affected parties were informed and that no unauthorized access was continuing.
McDermott described a similar, isolated social engineering incident involving one user and a limited number of documents. Its regulatory filing in Vermont identified Social Security numbers and health records among the affected data. The firm said it investigated with outside cybersecurity experts, engaged law enforcement, and secured its systems.
Neither firm disclosed the precise technique used, and neither has been shown to lack any specific safeguard. Claims beyond the public facts would be speculation.
Why "limited" does not mean harmless
Scope and sensitivity are different questions.
A breach can touch relatively few documents and still expose what matters most to a client: litigation strategy, medical records, financial data, personal identifiers, deal documents, or confidential communications.
The consequences also extend past technical remediation. The firm must determine what was accessed, preserve evidence, evaluate regulatory and contractual duties, notify affected clients or individuals, coordinate with insurers and law enforcement, and answer hard questions from clients whose information was entrusted to it.
In the Quinn Emanuel matter, the breach also became part of an existing public dispute involving Muddy Waters – a reminder that a contained security incident can quickly become a client-trust and reputational issue.
Smaller firms should not read this as a BigLaw problem. Small and midsize firms rely on the same email, cloud-storage, document-management, and file-sharing platforms – often with fewer people available to catch a suspicious login.
Social engineering is not just a training problem
Calling an incident "social engineering" can make it sound like one person made a mistake. That framing is incomplete.
Attackers impersonate colleagues, vendors, clients, or IT support. They exploit password-reset flows, MFA fatigue, session tokens, and help-desk workflows. Training helps, but assume a convincing message will eventually reach a busy attorney at the wrong moment.
The better question: What stops one successful interaction from becoming access to sensitive client files?
That requires layers of protection around the user, not just the login:
- Phishing-resistant MFA. Passkeys and hardware security keys beat codes or push approvals. CISA treats phishing-resistant MFA as the standard to aim for.
- Hardened account recovery. A strong login means little if an attacker can talk a help desk into a password or MFA reset.
- Least-privilege access. Staff should reach the matters they work on – not every file the firm has ever stored. A compromised account should not be a master key.
- Risk-based sign-in controls. New devices, unfamiliar locations, and anonymized traffic should trigger extra verification or a block.
- Logging that gets reviewed. The firm needs to spot unusual downloads, new mail-forwarding rules, and abnormal file access – not just collect logs no one reads.
- Session and token revocation. A password reset does not always end an active session. Response plans must revoke sessions and tokens across every affected app.
- A rehearsed incident-response plan. Who preserves logs, calls the insurer, and notifies clients should be decided before an incident, not during one.
These safeguards track the risk-based approach in ABA Formal Opinion 483, which addresses lawyers' obligations after a data breach or cyberattack. The precise obligations depend on the facts and the rules that apply to the firm.
Five questions a managing partner should ask now
You don't need to become a security engineer. You need clear answers.
- Which accounts can reach the firm's most sensitive client files?
- Do those accounts use phishing-resistant MFA – or only passwords and text codes?
- Could a convincing phone call talk your help desk into a password or MFA reset?
- Would anyone notice an unusual login followed by a large file download?
- If one account were compromised today, could the firm revoke access and know what was taken – fast?
If several answers are "we'd need to ask our IT provider," ask this week. An MSP is a valuable partner, but firm leadership still needs evidence that these controls are configured, monitored, and tested – not assumed.
Start with what an attacker can already see
An outside-in review cannot tell you whether one account has phishing-resistant MFA or whether your document permissions follow least privilege. It can show the public-facing conditions attackers use to choose and approach a target – exposed remote-access services, discoverable login pages, weak email authentication, lookalike domains, and forgotten internet-facing assets.
That makes external exposure review a useful first layer, not a complete answer.
Start with the free Zero-Access Exposure Review™ to see what's publicly visible about your firm – no credentials or internal access required. Ready to look inside the firm at identity, access, recovery, and logging controls? Our Security Baseline Assessment covers that ground in a fixed-scope engagement.
The lesson from Quinn Emanuel and McDermott is not that a law firm must be impenetrable. It is that every firm should know how far one compromised account can reach – and have controls in place that keep it from becoming a firmwide crisis.
Related reading
- One of the Country's Largest Law Firms Just Got Fooled by a Fake Identity – Not a Hack
- How to Build a Law Firm Data Breach Response Plan
- One Device, 57,000+ Records, and a Lawsuit That's Still Growing
- A Law Firm Offered $520,000 to Stop the Leak. It Got Posted Anyway.
Sources
This article is informational and does not constitute legal or compliance advice. Details regarding the Quinn Emanuel and McDermott matters are drawn from public reporting and regulatory filings; the responsible party or parties had not been publicly identified at the time of writing.
