Data breaches

Holland & Knight and Squire Patton Boggs: law-firm data breaches

Several US law firms disclose unauthorised access to confidential data. Confirmed details differ between firms.

Conceptual illustration: Holland & Knight and Squire Patton Boggs: law-firm data breaches
Conceptual illustration · SecurCheck

What is confirmed

Reuters reported on October 9 that Holland & Knight, Squire Patton Boggs and Nelson Mullins disclosed incidents involving sensitive information.

Holland & Knight described social engineering that enabled remote access to a firm computer. Some exposed files contained Social Security numbers.

Squire Patton Boggs reported unauthorised access to limited client information. The firms said client services were not disrupted.

What it means

Confidential client documents and workstation access make law firms attractive targets.

These are separate incidents and must not be presented as a single intrusion or attributed to the same attacker without evidence.

How the incident unfolded

Reuters reported on October 9 that Holland & Knight, Squire Patton Boggs and Nelson Mullins disclosed incidents involving sensitive information.

Holland & Knight described social engineering that enabled remote access to a firm computer. Some exposed files contained Social Security numbers.

What it means for affected people

Confidential client documents and workstation access make law firms attractive targets.

These are separate incidents and must not be presented as a single intrusion or attributed to the same attacker without evidence.

Practical safeguards

Independently verify requests to share sensitive documents before granting remote access.

Restrict client-file access and protect remote sessions with strong authentication.

What to do

Independently verify requests to share sensitive documents before granting remote access.

Restrict client-file access and protect remote sessions with strong authentication.

Watch for phishing that refers to genuine legal matters.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Reuters — 9 octobre 2026
  2. Law360 — 9 octobre 2026