Major US Law Firms Report Data Breaches Exposing SSNs

Law Firms Holland & Knight, Squire Patton Boggs Disclose Breaches

HIGH
October 10, 2026
6m read
Data BreachPhishingOther

Related Entities

Other

Holland & Knight LLP Squire Patton Boggs LLPSheppard MullinGreenberg TraurigSeyfarth Shaw

Full Report

Executive Summary

Two major global law firms, Holland & Knight LLP and Squire Patton Boggs LLP, have separately reported data security incidents, adding to a growing list of law firms targeted by cyberattacks in 2026. The breaches, disclosed in early October 2026, resulted in the exposure of sensitive personal information, including Social Security numbers (SSNs). Holland & Knight identified a social engineering attack as the root cause, which led to unauthorized remote access and the compromise of files related to 14 clients. Squire Patton Boggs' disclosure was less specific, stating a limited set of information was obtained by an unauthorized party. These events underscore the significant risk faced by the legal sector, which holds vast amounts of confidential client and corporate data.

Threat Overview

Holland & Knight, a firm with over 2,200 professionals, revealed that an attacker used social engineering to gain remote access to a firm computer. This access was then used to exfiltrate a small number of files containing sensitive data, including SSNs. The firm has notified the 14 affected clients and engaged law enforcement. The attack vector points to a targeted effort against a specific individual to gain an initial foothold within the network.

Squire Patton Boggs, a firm with around 1,500 lawyers, reported its breach on October 8, 2026. A filing with the Vermont Attorney General's office indicates that at least two Vermont residents were among those whose SSNs were compromised. The firm has not publicly detailed the attack vector but confirmed that client services were not disrupted.

There is no evidence to suggest the two incidents are related. They are, however, part of a clear trend of attacks against the legal industry, which is often seen as a soft target with highly valuable data for extortion or corporate espionage.

Technical Analysis

The attack on Holland & Knight was explicitly attributed to social engineering. This is a broad term, but it likely involved phishing or a pretexting phone call to trick an employee into revealing credentials, installing malware, or granting remote access.

MITRE ATT&CK Techniques

  • T1566 - Phishing: (Assessed) The most common form of social engineering, likely used to deliver a malicious link or attachment to gain initial access.
  • T1078 - Valid Accounts: Once credentials were stolen via social engineering, the attacker used them to gain legitimate remote access to the firm's systems.
  • T1021 - Remote Services: The attacker leveraged a remote access capability to connect to a firm computer, indicating that remote access ports or services were likely exposed.
  • T1048 - Exfiltration Over Alternative Protocol: After accessing the files, the attacker exfiltrated them. This could have been done via encrypted channels or common protocols to blend in with normal traffic.

Impact Assessment

Data breaches at law firms are particularly damaging due to the nature of the information they hold. The compromised data can include privileged client communications, M&A details, intellectual property, and litigation strategies, in addition to PII like SSNs. The exposure of SSNs creates a risk of identity theft for the affected individuals. For the firms, the impact includes reputational damage, loss of client trust, potential regulatory fines, and the cost of incident response and litigation. The growing number of such attacks could lead to increased cybersecurity insurance premiums for the entire legal sector and may result in class-action lawsuits from affected clients and individuals.

IOCs — Directly from Articles

No specific IOCs were provided in the source articles.

Cyber Observables — Hunting Hints

To detect activity related to law firm targeting, security teams should monitor for the following:

Type
log_source
Value
VPN/Remote Access Logs
Description
Look for logins from unusual geographic locations, multiple failed login attempts followed by a success, or logins outside of normal business hours.
Context
VPN concentrator logs, RADIUS logs, SIEM
Confidence
high
Type
command_line_pattern
Value
powershell.exe -enc
Description
Encoded PowerShell commands are frequently used by attackers after initial access to download additional tools or execute commands.
Context
EDR logs, Windows Event ID 4688
Confidence
medium
Type
network_traffic_pattern
Value
Unusual access to document management systems
Description
Monitor for a single user account accessing an abnormally large number of files or client matters in a short period.
Context
Application logs, SIEM
Confidence
medium
Type
email_address
Value
lookalike-domain.com
Description
Be vigilant for phishing emails from domains that mimic the firm's own domain or that of a known client.
Context
Email security gateway logs
Confidence
high

Detection & Response

  • User and Entity Behavior Analytics (UEBA): Deploy UEBA solutions to baseline normal user activity and detect anomalies, such as an account accessing unusual files or logging in from a new location. This directly applies D3FEND User Geolocation Logon Pattern Analysis (D3-UGLPA).
  • Endpoint Detection and Response (EDR): An EDR solution can detect malicious processes or scripts executed after a successful social engineering attack, providing an opportunity to contain the breach before data is exfiltrated.
  • Data Loss Prevention (DLP): Implement DLP policies to monitor and block the unauthorized transfer of sensitive data, such as documents containing multiple SSNs, outside the corporate network.
  • Security Awareness Training: Since the initial vector was social engineering, continuous training for all employees on how to spot and report phishing attempts is crucial. This is a key part of D3FEND User Training.

Mitigation

  • Multi-Factor Authentication (MFA): Enforce MFA on all remote access services (VPN, RDP, etc.) and email accounts. This is the single most effective control against credential theft via social engineering.
  • Principle of Least Privilege: Ensure users only have access to the client files and data necessary for their job function. This can limit the amount of data an attacker can access if a single account is compromised.
  • Email Filtering: Use an advanced email security gateway to block phishing emails, malicious attachments, and links before they reach employee inboxes.
  • Egress Traffic Filtering: Restrict outbound network connections to prevent attackers from easily exfiltrating data. Block traffic to known malicious domains and monitor for large, unexpected data transfers.

Timeline of Events

1
October 8, 2026
Squire Patton Boggs reports a data breach.
2
October 9, 2026
Holland & Knight discloses a data breach caused by social engineering.
3
October 10, 2026
This article was published

MITRE ATT&CK Mitigations

Training employees to recognize and report social engineering and phishing attempts is the first line of defense.

MFA on remote access services would have prevented the attacker from using stolen credentials to gain access.

Enforcing the principle of least privilege would limit the data accessible to an attacker who compromises a standard user account.

Using EDR/UEBA to detect anomalous behavior, like unusual file access or remote logins, can help spot a compromise in progress.

D3FEND Defensive Countermeasures

The Holland & Knight breach was predicated on an attacker gaining unauthorized remote access. The single most effective countermeasure against the abuse of stolen credentials is the enforcement of Multi-factor Authentication (MFA). All remote access points, including VPNs, RDP gateways, and cloud services like Microsoft 365, must be protected by MFA. This creates a critical barrier; even if an attacker successfully tricks an employee into revealing their password via social engineering, they cannot complete the login without the second factor (e.g., a code from an authenticator app, a push notification, or a hardware token). For a high-value target like a law firm, phishing-resistant MFA (such as FIDO2/WebAuthn) should be the standard.

Since social engineering was the confirmed vector for the Holland & Knight breach, a robust and continuous security awareness training program is essential. This goes beyond annual compliance training. It should include regular, simulated phishing campaigns to test and train employees' ability to spot malicious emails. Training should specifically cover pretexting (vishing) calls and how to verify requests for sensitive information or remote access. A clear, simple process for employees to report suspicious activity to the security team without fear of reprisal is critical. A well-trained workforce acts as a human firewall and is a vital sensor in the detection network.

Once an attacker gains access, their behavior often deviates from the normal patterns of the compromised user. Law firms should deploy User and Entity Behavior Analytics (UEBA) to monitor access to their document management systems (DMS). A lawyer typically works on a specific set of client matters. An attacker, however, will likely start enumerating multiple client folders to find valuable data. A UEBA system can baseline normal access patterns for each user and flag anomalies, such as a user suddenly accessing hundreds of files across dozens of client matters in a short time, or accessing files late at night. This can provide an early warning of an active compromise before significant data exfiltration occurs.

Timeline of Events

1
October 8, 2026

Squire Patton Boggs reports a data breach.

2
October 9, 2026

Holland & Knight discloses a data breach caused by social engineering.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachLegal ServicesSocial EngineeringPhishingSSN

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.