One of the Country's Largest Law Firms Just Got Fooled by a Fake Identity – Not a Hack
WilmerHale's 2026 breach and a $3.1M Holland & Knight wire fraud case show the real BEC threat isn't hacking – it's a convincing fake identity. Here's what closes the gap.
In July 2026, WilmerHale – one of the most recognized law firms in the country – began notifying clients that their names and Social Security numbers may have been exposed. There was no ransomware. No network intrusion. No dramatic breach headline about firewalls failing.
According to the firm's own notification, an employee simply gave information to someone who was not who they claimed to be.
If a firm with WilmerHale's resources can be fooled by a convincing fake identity, size and budget were never the real defense. The real defense is whether your firm can verify who it's actually talking to before it acts – and that's a much smaller, much more solvable problem than "prevent every hack."
In this article:
- What's publicly known about the WilmerHale incident, and what's still just allegation
- Why this fits a documented pattern going back years – not an isolated event
- What actually would have stopped it, and what that costs to put in place
What Actually Happened at WilmerHale
Based on WilmerHale's own breach notification and subsequent court filings, the sequence looks like this: on May 8, 2026, a firm employee provided sensitive client information to a third party who had misrepresented their identity. WilmerHale discovered the incident on June 25, 2026, and began mailing notification letters on July 10. Regulatory filings show the exposure reached residents in at least five states, with Social Security numbers among the data involved.
A proposed federal class action followed in late July, alleging the firm failed to implement reasonable safeguards. WilmerHale disputes the claims, no class has been certified, and the case remains unresolved – so the legal outcome is still an open question. What isn't in dispute is the mechanism: someone impersonated an authorized party convincingly enough that a trained professional at a sophisticated firm acted on it.
That's the part every firm – regardless of size – should sit with. This wasn't a technical failure. It was a trust failure, and trust failures don't check your firm's headcount before they happen.
This Isn't New – Ask Holland & Knight
If WilmerHale sounds like an outlier, it isn't. In 2020, Holland & Knight was sued after allegedly wiring more than $3.1 million to a fraudulent account during a stock transaction. According to the lawsuit, a fraudster intercepted the firm's email correspondence with the actual sellers, impersonated them, and provided new wiring instructions to a Hong Kong-based account. Holland & Knight has stated its own systems were never compromised – the firm says it acted on instructions that arrived through the client's side of the correspondence, which is precisely what makes this style of attack so effective: the firm didn't need to be hacked at all.
Six years, and the pattern hasn't changed. Only the sophistication of the impersonation has – attackers researching a deal for weeks, matching writing style and timing, and stepping into a thread at exactly the moment funds are supposed to move.
The Pattern Underneath Both Cases
Strip away the details and WilmerHale and Holland & Knight are the same story:
- Someone the firm trusted – or believed it was dealing with – asked for something sensitive: data in one case, a wire in the other.
- Nothing about the request looked technically wrong. No malware, no obvious spoofed domain, no broken login.
- The request arrived with urgency, inside a plausible context, from what appeared to be a legitimate party.
- Someone acted on it before anyone verified through a second channel.
The FBI's Internet Crime Complaint Center attributed close to $2.8 billion in losses to business email compromise in its most recent annual report – the second-costliest category of cybercrime it tracks. Law firms are disproportionately represented in that total because they sit at the intersection of urgency, money, and trust: real estate closings, M&A escrow, settlement disbursements, and client data all move through email, and a message that looks like it came from a partner or a client tends to get acted on quickly.
What Actually Closes This Gap
Neither of these incidents required a sophisticated intrusion to prevent. They required specific, checkable controls – the kind that either exist at your firm today or don't:
- Domain authentication (SPF, DKIM, DMARC) enforced, not just configured. This is what stops someone from sending a convincing email that appears to come directly from your firm's real domain.
- A mailbox check for hidden forwarding rules. Attackers who've already gained quiet access to an inbox often set up rules to keep reading everything without tipping anyone off – this is how they get the writing style and timing right in the first place.
- A verification step that doesn't run through the same channel as the request. If a wire instruction or a data request changes, a known phone number – not a reply-to-the-same-thread – confirms it before anyone acts.
Those first two items are exactly what we bundled together as Lock Down Your Firm's Email – full DMARC enforcement plus a check of your firm's inbox rules and forwarding settings, in one fixed-scope engagement, with before/after evidence you can hand to a client or an insurer. It's $1,950 for firms of 1–3 people and $2,450 for firms of 4–10, with founding-client pricing currently applied.
If you're not sure where your firm stands before committing to anything, start with the free Proprietary Exposure Review – it shows you the public spoofing and impersonation signals attackers can already see, in minutes, with no access to your systems required.
For the fuller walkthrough of how these attacks unfold and what Microsoft 365 does and doesn't protect against out of the box, see How Law Firms Get Hit by Wire Fraud – Even When No One Was Hacked.
The Question Worth Asking This Week
WilmerHale and Holland & Knight both had resources most small and mid-sized firms don't. Neither had this problem solved. That should reframe the question from "are we big enough to be a target" to a simpler one:
If someone convincingly pretending to be a partner, a client, or an opposing counsel emailed your firm right now asking for sensitive data or a wire change, would anyone at your firm be able to catch it – and does your firm's email even stop an attacker from sending that message as you in the first place?
If you're not confident in the answer, that's exactly what the free Proprietary Exposure Review is built to check.
This article is informational and does not constitute legal or compliance advice. Details regarding the WilmerHale and Holland & Knight matters are drawn from public court filings, breach notifications, and news reporting; both matters involve contested allegations and neither firm has been found liable.
