WilmerHale Data Breach: What Law Firm Leaders Should Learn
What the WilmerHale data breach teaches law firms about impersonation, sensitive data requests, and independent verification.
In July 2026, WilmerHale – a large, nationally recognized law firm – began notifying affected individuals that names and Social Security numbers may have been exposed. The firm's notification filed with the New Hampshire Department of Justice describes an employee providing information to a person who had misrepresented their identity.
For small and midsize law-firm leaders, the lesson is practical: a trusted request for sensitive information needs an independent verification step. The public notification supports an impersonation-based disclosure, but it does not establish every detail about the underlying systems, communication channel, or sequence.
If a firm with WilmerHale's resources can be fooled by a convincing fake identity, size and budget are not enough by themselves. A separate verification step can reduce the chance that staff act on a false identity, but no single control prevents every form of impersonation.
What Actually Happened at WilmerHale
WilmerHale's New Hampshire notification says the incident occurred on May 8, 2026, was discovered on June 25, and led to notices beginning July 10. It identifies names and Social Security numbers among the information involved. Those are the firm's reported facts; they should not be expanded into an assumption that no technical compromise occurred or that the exact communication sequence is known.
A proposed federal class action followed. The public docket for Perry v. Wilmer Cutler Pickering Hale & Dorr LLP identifies the case and makes clear that the allegations remain contested; no class certification or liability finding should be inferred from the filing.
The defensible takeaway is narrower and more useful: identity verification failed at a point where sensitive information was requested. That risk exists at firms of every size.
This Isn't New – Ask Holland & Knight
If WilmerHale sounds like an outlier, it isn't. The ABA Journal's account of the Holland & Knight litigation describes allegations that more than $3.1 million was sent to a Hong Kong account after email instructions appeared to come from shareholders. The report also notes that the foundations' systems had been breached and that Holland & Knight disputed responsibility. It is a reminder to verify payment changes through a known contact method, not proof that every similar incident follows the same path.
Six years, and the pattern hasn't changed. Only the sophistication of the impersonation has – attackers researching a deal for weeks, matching writing style and timing, and stepping into a thread at exactly the moment funds are supposed to move.
The Pattern Underneath Both Cases
Strip away the details and WilmerHale and Holland & Knight are the same story:
- Someone the firm trusted – or believed it was dealing with – asked for something sensitive: data in one case, a wire in the other.
- The request may not look technically wrong to a busy recipient. A plausible identity, urgent context, or familiar thread can be enough to trigger action.
- The request arrived with urgency, inside a plausible context, from what appeared to be a legitimate party.
- Someone acted on it before anyone verified through a second channel.
The FBI's Internet Crime Complaint Center guidance on business email compromise recommends secondary-channel verification for changes to account information and cautions against sending personally identifiable information in response to email requests. Law firms sit at the intersection of urgency, money, and trust: real estate closings, M&A escrow, settlement disbursements, and client data all move through email.
What Actually Closes This Gap
These incidents point to specific, checkable controls – the kind that either exist at your firm today or don't:
- Domain authentication (SPF, DKIM, DMARC) enforced, not just configured. This can reduce direct spoofing from your firm's domain, but it does not prevent lookalike domains, compromised accounts, or every other form of impersonation.
- A mailbox check for hidden forwarding rules. An authorized assessment can inspect private mailbox rules and forwarding settings; a public-only review cannot.
- A verification step that doesn't run through the same channel as the request. If a wire instruction or a data request changes, a known phone number – not a reply-to-the-same-thread – confirms it before anyone acts.
Those first two items are exactly what we can scope through Email & Microsoft 365 Security for Law Firms: domain authentication work plus a check of your firm's inbox rules and forwarding settings, with before/after evidence for the agreed scope.
For the plain-English evidence checklist behind the domain-authentication question, see DMARC for Law Firms: Check Your Email Domain Protection.
If you're not sure where your firm stands before committing to anything, start with the free Zero-Access Exposure Review™ – it shows you the public spoofing and impersonation signals attackers can already see, in minutes, with no access to your systems required.
For the fuller walkthrough of how these attacks unfold and what Microsoft 365 does and doesn't protect against out of the box, see How Law Firms Get Hit by Wire Fraud – Even When No One Was Hacked.
What should your firm verify?
- Independently verify sensitive data requests and changes to payment instructions using a known contact method.
- Check email authentication and, within an authorized engagement, mailbox forwarding and account controls through Email & Microsoft 365 Security for Law Firms.
- Test whether staff recognize and report impersonation attempts through Managed Phishing Testing & Staff Training.
For a broader review of identity, sharing, forwarding, and recovery evidence, use the Microsoft 365 Security Checklist for Law Firms.
For a focused review of sign-in protection, see how to verify MFA enforcement and account coverage. That guide explains why a registered authenticator does not by itself prove coverage across every account or application.
For practical staff exercises that do not assume how a named firm was breached, see the Law Firm Ransomware Phishing Readiness Guide.
The free Zero-Access Exposure Review™ examines public signals such as domain and email-authentication exposure. It cannot inspect private mailbox rules, verify internal Microsoft 365 settings, or measure staff readiness. Authorized assessments and phishing engagements address those separate areas.
WilmerHale and Holland & Knight both show why a public-only check and an authorized internal engagement answer different questions.
Related reading
- Quinn Emanuel and McDermott Breaches: One Account Can Be Enough
- How to Build a Law Firm Data Breach Response Plan
- One Device, 57,000+ Records, and a Lawsuit That's Still Growing
Sources
- WilmerHale notification filed with the New Hampshire Department of Justice
- Perry v. Wilmer Cutler Pickering Hale & Dorr LLP public docket
- FBI IC3 business email compromise guidance
This article is informational and does not constitute legal or compliance advice. Details regarding the WilmerHale and Holland & Knight matters are drawn from public court filings, breach notifications, and news reporting; both matters involve contested allegations and neither firm has been found liable.
