By Mike Scarcella
WASHINGTON, Sept 3 (Reuters) – Prominent U.S. law firms Quinn Emanuel and McDermott said on Thursday that they suffered recent data breaches and had notified law enforcement, amid heightened cyber risks for firms that hold sensitive client and personal information.
It was not clear who was responsible for the two breaches or whether they were related. Large law firms’ extensive holdings of confidential business and personal data have made them attractive targets for cybercriminals.
Quinn Emanuel said in an August 25 letter to a lawyer for short seller Muddy Waters that some files related to the company were accessed in a breach less than two weeks earlier.
The letter, which was viewed by Reuters, said an “unauthorized third party obtained access through social engineering” on August 14, and that some of the information exposed involved Muddy Waters files that Quinn Emanuel obtained in a lawsuit in Florida.
Quinn in a statement on Thursday said it identified “a data security incident involving unauthorized access to stored files for a single software application through one temporarily compromised user account.”
Quinn said “a limited number of client documents were impacted and affected parties have been informed.” There is no ongoing unauthorized access to systems, it said.
Muddy Waters had previously asked a judge to bar Quinn’s involvement in a lawsuit against the short seller in Texas, saying the firm had earlier represented Muddy Waters on related matters.
In a statement on Thursday, Muddy Waters said “just when we thought Quinn couldn’t be more outrageous than eagerly representing new clients who want to sue old ones, we learned that Quinn failed to protect our sensitive information from social engineering hacking.”
Quinn Emanuel declined to comment about Muddy Waters’ statement. The firm has denied Muddy Waters’ conflict-of-interest claims and said a single attorney at the firm briefly represented Muddy Waters on a different matter.
McDermott reported its breach last week to the Vermont state attorney general and said it affected Social Security numbers and health data among its files.
McDermott in a statement said it responded to “an isolated social engineering incident involving a single user and a limited number of documents,” and that it investigated with assistance from cybersecurity experts and engaged with law enforcement.
“The matter has been resolved, and the firm’s systems remain secure. The confidentiality and privacy of our client and firm information continue to be our highest priority,” McDermott said.
“Social engineering” hacks can involve manipulating people into revealing sensitive information or granting access to secure systems.
At least three other law firms, including Herbert Smith Freehills Kramer and Goodwin Procter, disclosed data breaches to U.S. state regulators last month. Another firm, WilmerHale, was sued in July in a proposed class action over a data breach that affected the firm.
Read more:
Law firms Herbert Smith, Goodwin hit by data breaches
Law firm WilmerHale sued in class action after data breach
(Reporting by Mike Scarcella)


Comments