Law report No. GLW-3677 · filed September 29, 2026
Legal PracticeReported case
Seyfarth Shaw Discloses Social Engineering Breach Exposing SSNs
Seyfarth Shaw says an attacker impersonating its IT help desk tricked an employee into emailing client documents, exposing Social Security numbers of at least 300 people.
By Grace Kim2 min read450 words
Holding
- Seyfarth Shaw discovered in August that a limited number of documents with personal information, including Social Security numbers, were emailed to an unauthorized recipient.
- At least 300 people were affected; the firm notified the California and Texas attorney general offices.
- The firm attributed the incident to a targeted social engineering attack in which someone impersonated its IT help desk; it is offering free credit monitoring and expanding employee training.

Seyfarth Shaw has disclosed a data breach that exposed Social Security numbers belonging to firm clients and opposing parties, according to a draft notification letter the firm filed with the California attorney general's office.
The Chicago-founded firm discovered in August that a "limited number" of documents containing personal information had been emailed to an unauthorized recipient, the draft letter states. The exposed data included Social Security numbers. At least 300 people were affected, according to Law360, which first reported the notification. The firm also filed notice with the Texas attorney general's office.
Seyfarth attributed the incident to a targeted social engineering attack rather than a technical intrusion.
"Seyfarth experienced a targeted social engineering attack in which someone impersonating our IT help desk deceived an employee into emailing a limited number of client documents to an unauthorized outside email account," the firm said in a statement.
"Protecting the confidential information our clients entrust to us is among our highest responsibilities, and we are taking this matter very seriously," the statement read.
According to DataBreachRights, a website that tracks data breaches and offers free case reviews, the compromised data belonged both to Seyfarth's clients and to opposing parties in matters the firm handled. That detail will likely sharpen attention on the incident, since it touches not only the firm's duty of confidentiality to clients but also the personal data of adverse litigants.
In its draft letter, Seyfarth said it is responding on two fronts. The firm is expanding employee training and awareness notifications, and it is offering affected individuals free access to credit monitoring and reporting services.
What this means for practitioners
The breach notification arrives amid heightened regulatory scrutiny of law firm cybersecurity. Firms handling litigation data increasingly hold Social Security numbers and other sensitive identifiers for clients and third parties, which triggers state breach notification statutes in California, Texas and elsewhere. Practitioners should expect the incident to renew pressure on law firms to verify identity protocols for internal IT communications — social engineering schemes that impersonate help desk staff exploit exactly the kind of trust that standard perimeter defenses do not address. Firms that have not yet implemented out-of-band verification procedures for document transfer requests, or that lack vendor and employee training programs addressing impersonation fraud, may face similar exposure, including notification obligations across multiple states and potential exposure to malpractice and regulatory claims.
Seyfarth has not publicly disclosed the identity of the affected clients or the specific matters involved, and the firm's draft letter does not state whether any of the exposed data has been misused. The firm urged recipients of its notification letter to take advantage of the credit monitoring services.
via oag.ca.gov (Original)
More from Grace Kim
Show full bio
Correspondent covering consumer brands and retail at Global Law Wire.
206 articles
Also before the court
- Cyber Attacks on Law Firms Rose 77% in Past Year, Report Finds
- Canada's Parliament Passes Cybersecurity Bill With Privacy Caveats
- Sanctions Compliance Meets Data Privacy: A Structural Tension
- EU's Top Court to Hear Challenge to EU-U.S. Data Privacy Framework
- California Eyes Higher Privacy Fines and Age Assurance Rules