|
|
Yet another class action lawsuit against BigLaw:
"Seyfarth Shaw failed to guard client data from cyber hack"
__________
|
| |
Project Counsel Media is a division of Luminative Media. We cover the areas of cyber security, digital technology, legal technology, media, and mobile technology.
About Luminative Media: our intention is to delve deeper into issues, at greater length and with more historical and social context, in order to illuminate pathways of thought that are not possible to pursue through the immediacy of daily media. For more on our vision please click on our logo:
| | |
Seyfarth Shaw LLP has been with a proposed class action lawsuit in Illinois federal court, following disclosures that a social engineering cyber attack exposed the personal information of thousands of individuals.
The incident, which occurred on August 18, 2026, reportedly involved a hacker impersonating the law firm's IT help desk. The attacker successfully deceived a single employee into emailing client documents to an unauthorized outside account.
But it's a widening issue for both law firms and the legal tech community.
| | |
________________
BY:
Anthony Conforti
Cybersecurity Reporting Team
Member of the Luminative Media / Project Counsel Media teams
_______________________________
| | |
25 September 2026 (Washington, DC) - On Thursday, Seyfarth Shaw LLP was hit with a proposed class action in Illinois federal court accusing it of failing to protect its current and former clients' personal information after the Chicago-based law firm this month disclosed a recent data breach.
Seyfarth disclosed the data breach in a September 18th notice, saying that on August 18th it identified the "unauthorized acquisition of a limited number of documents containing personal information". It added that an investigation later confirmed that there was "no evidence of unauthorized access" to the firm's network and that "the event was limited to a small number of documents sent by email to an unauthorized recipient".
The notice, posted on the website of the California Attorney General's Office, didn't specify the total number of affected people across the country. But a separate notice to the Texas Attorney General's Office stated that 305 Texans had their information exposed, including names and Social Security numbers.
Note to readers: based on one of our cybersecurity partners, the Seyfarth Shaw data breach was more extensive than publicly disclosed, and caused by a targeted social engineering attack in which a "threat actor" successfully impersonated the law firm's internal IT help desk.
Our partner said "it has all the hallmarks of a Russian agent attack, and I assume the Silent Ransom Group which keeps hitting U.S. law firms at will".
According to official statements from Seyfarth Shaw LLP and reports filed with state regulators, the attacker deceived a single employee into emailing a limited number of client documents to an unauthorized external email account on August 18, 2026. The compromised data contained personally identifiable information (PII), specifically the names and Social Security numbers of clients and opposing parties.
Lauren DeLong, whose information was exposed in the breach, alleges in a Thursday complaint that Seyfarth "had no effective means" to prevent or mitigate infiltrations of its computer systems, where it "stores a litany of highly sensitive personal identifiable information" about its clients.
The suit alleges that the cybercriminals were able to breach Seyfarth's systems because the law firm didn't adequately train its employees on security and didn't maintain reasonable security safeguards to protect clients' data. Said De Long:
"The exposure of one's PII to cybercriminals is a bell that cannot be unrung. Before this data breach, its current and former clients' private information was exactly that - private. Not anymore. Now, their private information is forever exposed and unsecure".
The suit alleges that the private information of more than 56,000 people was exposed in the data breach, including the current and former employees of Seyfarth's client AAA Mountain West Group. DeLong is one of those former employees and says she was injured by the data breach.
Seyfarth has offered free credit monitoring services, as well as fraud assistance, but the suit asserts that this is not enough to compensate DeLong and others injured in the data breach.
Note to readers: she's right. Free credit monitoring services doesn't work. See our postscript below.
DeLong wants to represent a nationwide class of people whose personal identifiable information was compromised in the breach.
The suit asserts claims for negligence, breach of implied contract, unjust enrichment and breach of fiduciary duty. It seeks damages, restitution, litigation costs and attorney fees, among other relief.
In a press release Seyfarth said:
"To be clear, there was no malware and our network and systems were not breached. Our security controls prevented the attacker from ever accessing them. Someone impersonating our IT help desk targeted a single employee, and a limited number of documents were sent to an unauthorized email account.
We notified law enforcement, engaged outside forensic experts, contacted the affected clients and provided notices, and continue to take this matter very seriously".
Seyfarth's is just the latest in a growing number of data breaches at law firms. Dozens of firms have been hit in 2026, including:
- Last week Tarter Krinsky & Drogin LLP revealed a data breach last year "that compromised significant protected health information the firm possessed due to its representation of [an unnamed] healthcare provider"
- Also last week, Greenberg Traurig LLP and Eckert Seamans Cherin & Mellott LLC, both disclosed attacks earlier this month
- Quinn Emanuel Urquhart & Sullivan LLP and McDermott Will & Schulte LLP reported breaches affecting client documents, Social Security numbers and health records
They joined the likes of these firms who were also breached over the past year:
- Goodwin Procter LLP
- Herbert Smith Freehills Kramer LLP
- Lewis Brisbois Bisgaard & Smith LLP
- Mayer Brown
- Moses & Singer LLP
- Riker Danzig LLP
- Taft Stettinius & Hollister LLP
- Troutman Pepper Locke LLP
- WilmerHale
That's hardly exhaustive. Merely samples. Law360's Law Firm Data Breach Tracker (considered definitive of the industry) said there were at least 105 data breaches during the first half of the year alone, "though even that is partial due to the non-uniformity of breach disclosure by law firms". See our postscript below for further explantion.
| | |
As Delong points out, the credit monitoring service proposed by Seyfarth does not adequately address the lifelong harm that victims will face. Already claimants are reporting an influx of spam communications, and other unwanted communications, as have others in the proposed class action. The complaint is correct: their private information is forever exposed and unsecure.
The sentiment that standard law firm monitoring services fail to mitigate the lifelong harm victims face from cyber attacks is gaining traction in court. Legal analysts say this case (and a similar case working through the courts) could be an excellent test cases.
Because legal practices hoard so much highly sensitive data, downstream a cyber breach/attack will create a cascade of risks, often severe and often hidden, and the standard credit monitoring provided is an inadequate defense against the permanent weaponization of exposed personal histories.
Standard breach responses typically provide one to two years of basic credit monitoring or dark web identity scanning. Analysts say such standard monitoring falls short for several reasons:
-
Permanent data exposure. Once sensitive data - such as medical records, business contracts, or Social Security numbers - is dumped online, it is permanently accessible. Credit monitoring expires, but the stolen data can be utilized by bad actors indefinitely.
-
Non-Financial Consequences. Standard services heavily focus on financial fraud, neglecting the emotional, psychological, and professional damage caused by identity theft, extortion, or the public release of intimate legal records.
-
Third-Party Risk. Because many law firms have smaller cybersecurity budgets than the corporate clients they serve, they are increasingly targeted by hackers specifically looking for a backdoor.
So legal experts and class-action attorneys are saying the time has come to demand broader settlements. Instead of just offering short-term credit alerts, plaintiffs are pushing for:
-
Lifetime identity restoration services. Moving away from basic scanning toward dedicated professionals who can actively assist victims whenever their compromised data surfaces.
-
Longer monitoring windows. Extending monitoring periods well beyond the standard one-year window to compensate for the lifelong risks associated with compromised Social Security and identity numbers.
-
Stricter firm compliance. Increasing regulatory pressure, such as rules enforced by the state bar to ensure firms have take proactive, protective cyber protection measures, rather than only reacting to breaches after the fact. And for those that have been breached, proof that they have upped their game and put true cybersecurity measures in action.
| | |
As we have reported, the public rarely sees the full scale of BigLaw cyber incidents because data breach disclosure is governed by an intricate, inconsistent patchwork of legal standards rather than a single, universal reporting law. While many of the major firms like the ones I listed above have recently made headlines for cyberattacks, many other breaches remain entirely confidential due to statutory loopholes, high harm thresholds, and private ransom settlements.
One of our cybersecurity vendors who works with many law firms, and who tracks breaches through its "brotherhood" of fellow cybersecurity analysts, says the Law360 number of 105 breaches quoted above is way too low. It's more like at least 160 data breaches, if not more. And counting.
A combination of legal, regulatory, and tactical factors allows many BigLaw data breaches to fly under the radar:
1. The patchwork of state laws
- In the U.S., breach notification is dictated by a messy web of all 50 states, Washington D.C., and U.S. territories. A firm must follow the specific rules of the state where the impacted individual resides, not where the firm is headquartered.
- Many state statutes contain a "harm threshold" provision. If a lawfirm conducts an internal forensic investigation and determines the breach is unlikely to cause financial or identity harm to the consumers, they are legally permitted to bypass public or individual notification entirely.
- Most states exempt businesses from reporting a breach if the stolen data was safely encrypted—assuming the encryption keys themselves were not also compromised.
2. Public vs. Private notification requirements
- In several jurisdictions, public disclosure via an online state database is only triggered if a breach affects a large number of residents (e.g., more than 500 or 1,000 people). If a BigLaw breach targets highly specific, high-value corporate files affecting only a few individuals, the firm is only required to notify those specific parties privately.
- Under the American Bar Association's ABA Formal Opinion 483, lawyers have a professional ethics obligation to notify current clients of a breach. However, this is only required if "material client confidential information" is compromised. If a hacker breaches an administrative system but doesn't touch core case files, the firm may conclude the incident isn't material enough to report.
3. Financial and tactical suppression
- Cybercriminals frequently leverage "double extortion" tactics, stealing sensitive files (such as corporate trust agreements, entity charts, and M&A documents) and threatening to leak them. In response, several top-tier firms have quietly paid millions of dollars to extortion groups like the Silent Ransom Group explicitly to purchase non-disclosure agreements and force the deletion of the data, successfully keeping the events out of the public eye.
And the attacks will continue. As we have noted ad nauseum, lawfirms are uniquely vulnerable to cyber threats due to weak security infrastructure. If you attended the RSA Security Conference earlier this year you probably attended at least one of the sessions that took down law firms' weak standard operating cyber protection procedures, which seem to be universal.
In brief, hackers know a few things:
1. Many work under/through an elaborate tracking system that monitors BigLaw through media coverage, public announcements, and by attending legal/legal tech conferences - the latter especially where vendors love to brag about their clients to verify their street creds.
They know many legal practitioners operate under strict deadlines and rigid confidentiality expectations, making them highly susceptible to paying hefty multi-million dollar ransoms to prevent leaks. Or simply to steal data. So they strike at those firms.
2. There are many core security vulnerabilities exploited by attackers. Many of the recent high-profile breaches at prominent global firmshighlight how threat actors consistently exploit systemic operational gaps. Here are just a few:
- That old standby: social engineering and phishing. Human manipulation remains the primary entry point. As recent BigLaw attacks revealed, attackers use sophisticated phishing and Business Email Compromise (BEC) to deceive employees into granting system access or exposing credentials.
-
Oh, that lagging infrastructure. While larger firms have scaled up their security budgets, it's no where near enough. As one cyber analyst told me who was called in to advise a BigLaw firm: "These guys are hard pressed to do what's needed for something they see as a pure cost, something not being used to generate revenue. GenAI? Almost an open budget. Proper cybersecurity? 'Eh'. You encounter that mindset again and again". And small and mid-sized firms frequently operate without dedicated cybersecurity personnel, 24/7 network monitoring, or robust incident response plans.
- A growing favorite: third-party vendors. The rapid adoption of cloud-based eDiscovery tools, document management systems (DMS), and external client portals creates an expansive, difficult-to-secure attack surface. Three of the recent BigLaw attacks were executed by simply gaining access through legal industry vendors, who have worse cybersecurity than BigLaw.
- And weak access controls. A widespread lack of enterprise-wide multi-factor authentication (MFA), weak password policies, and delayed software patching leave doors wide open for automated exploits.
| | |
Go to any cybersecurity event and you'll hear the same thing: law firm and legal tech cybersecurity "best practices" are a sham because compliance checklists all fail against human error, fragmented legalsoftware, and sophisticated AI phishing attacks.
There hasn't been a real headline whopping cybersecurity story in the legal tech community since the Epiq Global/Ryuk ransomware cyber attack in 2020, and the Casepoint/BlackCat ransomware group attack in 2023. There was the Chinese attack on an eDiscovery document review in 2020, but that was more a hacking group that infiltrated systems and adjacent email archives at a law firm to exfiltrate data. It was an intelligence gathering mechanism rather than executing an attack on the eDiscovery review process itself.
But as one cyber analyst noted:
"The legal industry is low-hanging fruit, the easiest industry to hack. An industry beset by outdated legacy systems, weakaccess/identity control, and lack of a documented or tested cyber incident response plan to isolate a breach. They are the weakest link. They don't want to spend the money".
In the Reuters report on why the legal sector struggles with spending on proper cybersecurity, three points were made:
- Law firm management often views IT and security through the lens of cost rather than revenue generation, prioritizing billable hours over infrastructure updates
- Smaller and mid-sized practices frequently lack dedicated in-house security teams or round-the-clock monitoring
- Many firms outsource their IT or use third-party legal software without auditing those vendors for security gaps.
And, as we noted, law firms are notorious for not divulging data breaches, despite their obligations to do so. Their reasons are usually three-fold:
- Risk of malpractice: law firms risk facing expensive professional malpractice and class-action lawsuits if a breach highlights their own cybersecurity negligence; and
- Attorney-Client Privilege: law firms often struggle to navigate the delicate balance between reporting a breach to authorities and accidentally waiving protected client privilege during an investigation
- The erosion of client trust. Firms rely entirely on confidentiality; admitting a breach can cause major clients to take their business elsewhere.
And so, what happens? Law firms quietly pay ransom demands (if made) in the hopes that the hackers will destroy the stolen data, keeping the event entirely out of the public eye. And many of those incidents do not become public until months after they occurred.
And worse, attackers can remain inside law firm systems for weeks or even months before being detected, leaving firms more vulnerable to data theft or unauthorized access.
| | |
The real boogie man? The Domain Name System (DNS). It is the "phonebook of the internet." It is a hierarchical, distributed system that translates human-readable domain names (like google.com) into machine-readable IP addresses (like 142.250.190.46).
Because computers and servers communicate entirely through numbers, they require these IP addresses to route your web requests to the correct destination. DNS spares you from having to memorize long strings of numbers every time you want to visit a website.
DNS security is notoriously weak at law firms and legal tech companies primarily due to a culture that prioritizes usability and billable hours over robust IT hygiene, compounded by an “exemption culture” where clients rarely audit their lawyers' technical infrastructure.
While law firms hold dense concentrations of highly sensitive data (M&A details, trade secrets, and intellectual property), their foundational internet routing protocols are often left unsecured, exposing them to phishing, business email compromise (BEC), and data exfiltration.
One of our cybersecurity partners, Andy Jenkinson (recognized as an expert on DNS in the security industry), looked at the DNS for 17 legal tech companies and found vulnerabilities in all but 2.
No, we are not broadcasting them. We will meet with each vendor separately to suggest solutions.
These vulnerabilities stem from a unique mix of cultural, operational, and technical structural flaws. Just a few points:
1. The "Exemption Culture" and lack of oversight
Historically, law firms have been treated differently than standard software vendors. According to a security analysis by Recorded Future (the world's largest cyber threat intelligence company) only about 30% of law firms report clients asking them to complete rigorous security questionnaires, compared to the near-universal requirements imposed on SaaS vendors. Because of relationship bias and the misconception that a law firm is "not a tech vendor," firms operate massive, unmonitored data concentrations without traditional technical oversight.
2. Convenience over compliance (partner resistance)
Law firm leadership - namely partners and owners - frequently reject security friction. Legal tech providers report that a sizable majority of law firms actively decline to enable basic security features (like multi-factor authentication or strict DNS configurations) because firm leaders deem them too cumbersome. When core infrastructure settings are customized to maximize convenience, advanced domain defenses are skipped entirely.
3. The technical blind spot: blind trust in the DNS Protocol
Many legal IT departments and legal tech companies treat the DNS as a passive utility ("the phonebook of the internet") rather than an active attack surface. By default, standard DNS does not provide data privacy or validation. Without specific cryptographic protocols, firms are susceptible to:
- DNS cache poisoning: attackers intercept and modify DNS packets in transit, silently rerouting staff to spoofed login portals to harvest credentials.
- Email spoofing and phishing: legal professionals are 40% more likely to fall victim to phishing than other industries. Yet, many legal industry lawyers and IT administrators lack the technical literacy to properly configure and read domain authentication protocols like SPF, DKIM, and DMARC, allowing hackers to perfectly impersonate a firm's domain name to clients.
- DNS tunneling: Malicious insiders or external hackers use DNS as a hidden side-channel to exfiltrate proprietary data right past standard Data Loss Prevention (DLP) filters.
4. Fragmented vendor and legal tech supply chains
Modern law firms rely heavily on a web of third-party legal tech tools for e-discovery, case management, and transcription. Security experts note that a firm's defense is only as strong as its weakest opposing counsel or vendor.
In the list of law firm cyber attacks above, at least 6 were executed via a legal technology provider.
And now, especially with the surge of AI, legal tech companies are rushing features to market to capture market share, prioritizing AI-enabled efficiency over baseline domain and network resilience - and not security. Right now, 2 legal tech companies are hawking their AI agents - both creating severe cybersecurity risks because they execute actions, make independent decisions, and cross digital boundaries rather than just generating text.
5. "Retention Amnesia" and aggregated data targets
Law firms suffer from severe retention amnesia, archiving and keeping data from closed cases indefinitely. When an attacker successfully exploits a weak DNS entry or sub-domain to gain access, they do not just breach active files - they gain access to decades of legacy corporate secrets.
While firms traditionally kept archives to comply with regulations or protect against malpractice claims, holding onto legacy data indefinitely now poses a severe cybersecurity and legal liability.
| | |
Yes, law firms and legal tech providers are slooooowly improving their cybersecurity, but a major gap remains between acknowledging the risks and executing strong defenses.
But the gap will persist. Law firms hold high-value assets like intellectual property, financial disclosures, and privileged client files, making them lucrative targets for hackers.
And there is the AI "Threat Multiplier" : cybercriminals increasingly use generative AI to write advanced ransomware and launch automated, evasive attacks that catch traditional security tools off guard.
A big issue is many firms still sequester cybersecurity strictly inside the IT department instead of treating it as an enterprise-wide business risk managed by firm leadership.
And the old "third-party blind spots": smaller and mid-sized firms frequently adopt cloud software and legal tech tools without properly vetting vendor security.
I think this is a big reason why many law firms are increasingly partnering directly with the new AI legal tech players - Harvey, Lawhive, Legora, etc. - to co-develop secure, custom operational tools rather than buying off-the-shelf legacy legal tech software with unknown vulnerabilities.
And it is probably why you see corporate clients now routinely auditing their outside counsel's digital resilience and data governance before signing retainers, forcing firms to take security upgrades more seriously.
| | |
* * * * * * * * * * * * * * *
For the URL link to this post, please click here
If post was forwarded to you and you'd like to subscribe.
please email us at lumintive.media@gmail.com
* * * * * * * * * * * * * * *
| | | | |