Law report No. GLW-3677 · filed September 29, 2026

Legal PracticeReported case

Seyfarth Shaw Discloses Social Engineering Breach Exposing SSNs

Seyfarth Shaw says an attacker impersonating its IT help desk tricked an employee into emailing client documents, exposing Social Security numbers of at least 300 people.

By Grace Kim2 min read450 words

Holding

  1. Seyfarth Shaw discovered in August that a limited number of documents with personal information, including Social Security numbers, were emailed to an unauthorized recipient.
  2. At least 300 people were affected; the firm notified the California and Texas attorney general offices.
  3. The firm attributed the incident to a targeted social engineering attack in which someone impersonated its IT help desk; it is offering free credit monitoring and expanding employee training.
Accidental email results in sharing Social Security numbers of Seyfarth Shaw clients, opposing parties
PlateAccidental email results in sharing Social Security numbers of Seyfarth Shaw clients, opposing parties — AI-generated

Seyfarth Shaw has disclosed a data breach that exposed Social Security numbers belonging to firm clients and opposing parties, according to a draft notification letter the firm filed with the California attorney general's office.

The Chicago-founded firm discovered in August that a "limited number" of documents containing personal information had been emailed to an unauthorized recipient, the draft letter states. The exposed data included Social Security numbers. At least 300 people were affected, according to Law360, which first reported the notification. The firm also filed notice with the Texas attorney general's office.

Seyfarth attributed the incident to a targeted social engineering attack rather than a technical intrusion.

"Seyfarth experienced a targeted social engineering attack in which someone impersonating our IT help desk deceived an employee into emailing a limited number of client documents to an unauthorized outside email account," the firm said in a statement.

"Protecting the confidential information our clients entrust to us is among our highest responsibilities, and we are taking this matter very seriously," the statement read.

According to DataBreachRights, a website that tracks data breaches and offers free case reviews, the compromised data belonged both to Seyfarth's clients and to opposing parties in matters the firm handled. That detail will likely sharpen attention on the incident, since it touches not only the firm's duty of confidentiality to clients but also the personal data of adverse litigants.

In its draft letter, Seyfarth said it is responding on two fronts. The firm is expanding employee training and awareness notifications, and it is offering affected individuals free access to credit monitoring and reporting services.

What this means for practitioners

The breach notification arrives amid heightened regulatory scrutiny of law firm cybersecurity. Firms handling litigation data increasingly hold Social Security numbers and other sensitive identifiers for clients and third parties, which triggers state breach notification statutes in California, Texas and elsewhere. Practitioners should expect the incident to renew pressure on law firms to verify identity protocols for internal IT communications — social engineering schemes that impersonate help desk staff exploit exactly the kind of trust that standard perimeter defenses do not address. Firms that have not yet implemented out-of-band verification procedures for document transfer requests, or that lack vendor and employee training programs addressing impersonation fraud, may face similar exposure, including notification obligations across multiple states and potential exposure to malpractice and regulatory claims.

Seyfarth has not publicly disclosed the identity of the affected clients or the specific matters involved, and the firm's draft letter does not state whether any of the exposed data has been misused. The firm urged recipients of its notification letter to take advantage of the credit monitoring services.

via oag.ca.gov (Original)

Filed under

  • data-breach
  • seyfarth-shaw
  • social-engineering
  • privacy
  • legal-industry
Share this article:

More from Grace Kim

Grace Kim

Show full bio

Correspondent covering consumer brands and retail at Global Law Wire.

206 articles

Also before the court

« Previous articleNext article »