Cybersecurity in law firms: the human remains the gateway
The reported breaches at Quinn Emanuel and McDermott once again bring law firm cybersecurity to the fore: the information they hold is valuable, and access is typically gained by deceiving a person, not by breaking encryption.

News summary
Reuters reported security incidents at two major law firms, Quinn Emanuel and McDermott. Beyond the names of the firms, the interest lies in the type of organisation affected: entities that centralise confidential information from numerous clients within a single system.
A law firm safeguards procedural strategies, unannounced corporate transactions, sensitive personal data, and privileged communications. For an attacker, this dataset is worth more than the infrastructure itself. And the shortest path to reaching it is almost never technical: it is a credible email, a well-prepared call, or a password reset request that sounds reasonable.
At Seintec, we see the same pattern in Spanish law firms, accountancies, and consultancies. Investment is made in firewalls and antivirus software, yet email access is protected by password alone, mailboxes retain years of unclassified history, and users share documents via links that no one subsequently reviews.
There are three controls that change the outcome disproportionately relative to their cost. First, phishing-resistant MFA for email and remote access. Second, a strict procedure —verified via a secondary channel— for any change in credentials or bank details. Third, limiting access to case files based on genuine necessity, rather than convenience.
Added to this is a sector-specific obligation: the duty of professional confidentiality does not vanish because the failure was IT-related. A firm that cannot demonstrate which files were accessed during an incident faces a deontology problem in addition to a technical one.
Training helps, but it is not sufficient on its own. Social engineering works precisely with competent people acting under pressure. Therefore, controls must be designed to withstand human error, rather than assuming it will not occur.
Source: Reuters — 3 September 2026
What happened
Reuters reported security incidents at two large law firms, Quinn Emanuel and McDermott. The point of interest is the type of organisation affected: entities that concentrate confidential information from many clients in a single system, such as litigation strategy, unannounced corporate deals and privileged communications.
For an attacker, that body of information is worth more than the infrastructure itself, and the shortest way in is almost never technical: a convincing email, a well-prepared phone call or a password-reset request that sounds reasonable.
What it teaches a mid-sized business
The same pattern repeats at Spanish and Catalan law firms, advisory practices and consultancies: money goes into firewalls and antivirus, but email access is protected only with a password, mailboxes hold years of unclassified history, and users share documents via links nobody checks afterwards.
Professional confidentiality duties don't disappear because the failure was technical. An organisation that can't show which files were accessed during an incident has an ethics problem on top of a technical one.
What to review
Controls with an outsized effect relative to their cost:
- Phishing-resistant MFA on email and remote access.
- A strict procedure, verified through another channel, for any change of credentials or banking details.
- Access to case files limited by genuine need, not convenience.
- Ongoing training against social engineering, designed on the assumption that human error will happen.
Frequently Asked Questions
- Why are law firms a frequent target?
- Because they concentrate confidential information from many organisations in a single environment and typically have fewer security resources than their corporate clients.
- Is SMS-based two-factor authentication enough?
- It's better than nothing, but it's the easiest method to bypass. For confidential information an authenticator app or physical security keys are recommended.
- Which firms were affected according to Reuters?
- Quinn Emanuel and McDermott, two large law firms that suffered security incidents reported by Reuters.
Concepts mentioned in this article: Cybersecurity · Antivirus · Phishing · Firewall
If your organisation safeguards third-party confidential information, email and document access security is not a technical detail. At Seintec, we reinforce identity, access, and traceability without complicating the team's daily operations. Consult us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.