Two major global law firms, Holland & Knight LLP and Squire Patton Boggs LLP, have separately reported data security incidents, adding to a growing list of law firms targeted by cyberattacks in 2026. The breaches, disclosed in early October 2026, resulted in the exposure of sensitive personal information, including Social Security numbers (SSNs). Holland & Knight identified a social engineering attack as the root cause, which led to unauthorized remote access and the compromise of files related to 14 clients. Squire Patton Boggs' disclosure was less specific, stating a limited set of information was obtained by an unauthorized party. These events underscore the significant risk faced by the legal sector, which holds vast amounts of confidential client and corporate data.
Holland & Knight, a firm with over 2,200 professionals, revealed that an attacker used social engineering to gain remote access to a firm computer. This access was then used to exfiltrate a small number of files containing sensitive data, including SSNs. The firm has notified the 14 affected clients and engaged law enforcement. The attack vector points to a targeted effort against a specific individual to gain an initial foothold within the network.
Squire Patton Boggs, a firm with around 1,500 lawyers, reported its breach on October 8, 2026. A filing with the Vermont Attorney General's office indicates that at least two Vermont residents were among those whose SSNs were compromised. The firm has not publicly detailed the attack vector but confirmed that client services were not disrupted.
There is no evidence to suggest the two incidents are related. They are, however, part of a clear trend of attacks against the legal industry, which is often seen as a soft target with highly valuable data for extortion or corporate espionage.
The attack on Holland & Knight was explicitly attributed to social engineering. This is a broad term, but it likely involved phishing or a pretexting phone call to trick an employee into revealing credentials, installing malware, or granting remote access.
T1566 - Phishing: (Assessed) The most common form of social engineering, likely used to deliver a malicious link or attachment to gain initial access.T1078 - Valid Accounts: Once credentials were stolen via social engineering, the attacker used them to gain legitimate remote access to the firm's systems.T1021 - Remote Services: The attacker leveraged a remote access capability to connect to a firm computer, indicating that remote access ports or services were likely exposed.T1048 - Exfiltration Over Alternative Protocol: After accessing the files, the attacker exfiltrated them. This could have been done via encrypted channels or common protocols to blend in with normal traffic.Data breaches at law firms are particularly damaging due to the nature of the information they hold. The compromised data can include privileged client communications, M&A details, intellectual property, and litigation strategies, in addition to PII like SSNs. The exposure of SSNs creates a risk of identity theft for the affected individuals. For the firms, the impact includes reputational damage, loss of client trust, potential regulatory fines, and the cost of incident response and litigation. The growing number of such attacks could lead to increased cybersecurity insurance premiums for the entire legal sector and may result in class-action lawsuits from affected clients and individuals.
No specific IOCs were provided in the source articles.
To detect activity related to law firm targeting, security teams should monitor for the following:
log_sourceVPN/Remote Access Logscommand_line_patternpowershell.exe -encnetwork_traffic_patternUnusual access to document management systemsemail_addresslookalike-domain.comTraining employees to recognize and report social engineering and phishing attempts is the first line of defense.
MFA on remote access services would have prevented the attacker from using stolen credentials to gain access.
Enforcing the principle of least privilege would limit the data accessible to an attacker who compromises a standard user account.
Using EDR/UEBA to detect anomalous behavior, like unusual file access or remote logins, can help spot a compromise in progress.
The Holland & Knight breach was predicated on an attacker gaining unauthorized remote access. The single most effective countermeasure against the abuse of stolen credentials is the enforcement of Multi-factor Authentication (MFA). All remote access points, including VPNs, RDP gateways, and cloud services like Microsoft 365, must be protected by MFA. This creates a critical barrier; even if an attacker successfully tricks an employee into revealing their password via social engineering, they cannot complete the login without the second factor (e.g., a code from an authenticator app, a push notification, or a hardware token). For a high-value target like a law firm, phishing-resistant MFA (such as FIDO2/WebAuthn) should be the standard.
Since social engineering was the confirmed vector for the Holland & Knight breach, a robust and continuous security awareness training program is essential. This goes beyond annual compliance training. It should include regular, simulated phishing campaigns to test and train employees' ability to spot malicious emails. Training should specifically cover pretexting (vishing) calls and how to verify requests for sensitive information or remote access. A clear, simple process for employees to report suspicious activity to the security team without fear of reprisal is critical. A well-trained workforce acts as a human firewall and is a vital sensor in the detection network.
Once an attacker gains access, their behavior often deviates from the normal patterns of the compromised user. Law firms should deploy User and Entity Behavior Analytics (UEBA) to monitor access to their document management systems (DMS). A lawyer typically works on a specific set of client matters. An attacker, however, will likely start enumerating multiple client folders to find valuable data. A UEBA system can baseline normal access patterns for each user and flag anomalies, such as a user suddenly accessing hundreds of files across dozens of client matters in a short time, or accessing files late at night. This can provide an early warning of an active compromise before significant data exfiltration occurs.
Squire Patton Boggs reports a data breach.
Holland & Knight discloses a data breach caused by social engineering.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.