Risk Data — Compensation Survey Deadline (Today), Law Firm Data Breach News
Posted on
SURVEY CLOSING TODAY
The BRB risk compensation survey closes today. If you/your firm haven’t participated and would like to receive a personal benchmark/copy of the report, I encourage you to participate!
“Law firm Seyfarth says breach exposed client documents” —
- “Law firm Seyfarth Shaw said in new disclosures to officials in at least two US states that it suffered a data security breach that exposed documents containing personal information, the latest cybersecurity incident to hit the legal industry.”
- “Seyfarth notified the Texas attorney general this week about the data security incident, saying it involved names and Social Security numbers.”
- “The firm in a statement to Reuters said the breach stemmed from a ‘targeted social engineering attack in which someone impersonating our IT help desk deceived an employee into emailing a limited number of client documents to an unauthorized outside email account.’ The firm said the incident was isolated to a single employee, and that the firm’s security controls prevented access to the firm’s network or systems.”
- “Seyfarth last week reported the incident to the attorney general’s office in California. In a draft notice to a victim, the firm said it ‘identified unauthorized acquisition of a limited number of documents containing personal information.’ It also said that it obtained the person’s information ‘in the course of certain legal services performed by the firm.'”
- “The notice said an investigation of the circumstances ‘confirmed that there was no evidence of unauthorized access to Seyfarth’s network and that the event was limited to a small number of documents sent by email to an unauthorized recipient.'”
- “Cyber incidents involving law firms are on the rise. Law firm BakerHostetler said in a report in March that its digital assets and data management groups responded to nearly 60 law firm incidents last year, almost double the number reported the previous year.”
- “Other law firms including, Quinn Emanuel, McDermott, Goodwin Procter and Herbert Smith, have disclosed data breaches in recent weeks. Law firm WilmerHale was sued in federal court in Washington in July following an alleged data-security breach.”
“Biglaw Firm’s Cybersecurity Headache Just Got Even Worse” —
- “Law firms have spent years warning clients about the dangers of cyberattacks. Unfortunately, hackers seem to have decided that the firms themselves make far more interesting targets.”
- “As reported by Reuters, Greenberg Traurig is now facing two proposed class actions following its disclosure that sensitive personal information was exposed in a recent data breach. The lawsuits are the latest legal fallout from an escalating wave of cyberattacks against Biglaw firms.”
- “Earlier this month, Greenberg Traurig said that an unauthorized actor had accessed a ‘limited’ number of documents and posted them on the dark web. The firm maintained that its systems were not compromised and said that only a small number of clients were affected, but a regulatory notice revealed that Social Security information had been exposed.”
- “Greenberg Traurig joins WilmerHale among the major firms that have been sued after recent breaches, while Quinn Emanuel, McDermott, HSF Kramer, and Goodwin have also disclosed cyber incidents.”
- “Biglaw may be great at protecting client confidences in court, but protecting them from hackers is becoming another matter entirely. “
“Tarter Krinsky Data Breach May Have Affected Health Info” —
- “Tarter Krinsky & Drogin LLP said in a letter this month that a data breach last year may have compromised protected health information the firm possessed due to its representation of an unnamed healthcare provider.”
- “The partially redacted Sept. 4 letter published by the California Attorney General’s Office said Tarter Krinsky became aware of suspicious activity on Sept. 10, 2025, and has recently completed its review of the materials affected by the breach. The types of information found in the potentially affected files include medical record numbers, dates of birth and treatment information.”
- “According to the letter, an investigation found that someone accessed Tarter Krinsky’s servers at various points between July 9, 2025, and Sept. 9, 2025. The firm said it isn’t aware of any identity theft, fraud or misuse of personal information stemming from the incident.”
- “‘Late last year, we identified suspicious activity on our network and immediately took steps to secure our systems and investigate the matter with the assistance of external cybersecurity professionals,’ a firm spokesperson told Law360 Pulse in an email Wednesday. ‘We have used the findings of that investigation to identify who was affected, and we’ve notified affected individuals and clients directly.'”
- “‘Unauthorized access to systems or files maintained by a law firm can create significant privacy and security concerns,’ Federman & Sherwood said. ‘Federman & Sherwood is investigating whether Tarter Krinsky & Drogin LLP implemented reasonable cybersecurity safeguards to protect sensitive information and whether additional security measures could have prevented or reduced the impact of the data breach.'”








