Skip to main content

Law Firm Data Breaches in 2026: The Entry Point Was a Person

Neetusha
Neetusha · Founder & CEO of RedactifyAI ·

On May 8, 2026, an employee at WilmerHale provided information to someone who had misrepresented their identity. The firm discovered it seven weeks later, on June 25. It began mailing notification letters on July 10. Four days after that, it was a defendant in a proposed class action in the U.S. District Court for the District of Columbia.

At least 95,804 people had their names and Social Security numbers exposed.

No firewall was defeated. No zero-day was exploited. Someone was deceived, and the material that person could reach contained Social Security numbers.

That pattern repeated twice more in 2026. It is the most useful thing law firms can learn from this year, and it points at a variable most firms are not managing.

Quick answer: Do law firms need redaction software? The short version, in about 400 words.


What happened in the three 2026 law firm breaches

Three separate incidents disclosed in 2026 exposed client and employee data held by law firms or the software they run on. None of them required sophisticated technical exploitation. Each began with a human being or a working set of credentials, and in every case the damage was measured by what happened to be sitting in the documents the intruder reached.

Three 2026 law firm data breaches compared

IncidentHow it startedWhat was exposedScale
WilmerHaleEmployee gave information to a person who misrepresented their identityNames, Social Security numbersAt least 95,804 people across six reporting states
McDermott Will & SchulteSocial engineering compromised a single user accountSSNs, health records, dates of birth, addresses, wage data, tax return information, direct deposit details, correspondenceNational total not disclosed
DocketWiseValid credentials used to clone partner repositories in a data migration pipelineNames, SSNs, government ID numbers, contact details, financial account data, health information116,666 individuals

WilmerHale: a pretexting call, then a class action

The WilmerHale incident is the cleanest illustration. The entry point was a conversation. An employee handed over information to a third party who had claimed to be someone else. The firm disclosed the incident to the California Attorney General on July 10, 2026, and offered affected individuals 24 months of Experian IdentityWorks monitoring.

The 95,804 figure is a floor rather than a total. It is the sum of the counts WilmerHale reported to six states that publish breach numbers: 80,528 in Texas, 14,496 in South Carolina, 692 in Washington, 42 in Massachusetts, 35 in New Hampshire, and 11 in Vermont. Residents of states that do not publish counts are not included in it.

The proposed class action landed on July 14, 2026, seeking negligence and contract damages. Bloomberg Law reported that the suit was brought on behalf of thousands of firm clients.

McDermott Will & Schulte: one account, a cluster of documents

McDermott Will & Schulte reported its incident to the Vermont Attorney General on August 28, 2026. According to the firm's preliminary disclosures, a targeted social engineering attack compromised a single user account, which gave the attacker brief access to a limited cluster of documents.

Brief access to a limited cluster of documents still produced this list: Social Security numbers, health records, full names, dates of birth, home addresses, wage and compensation information, tax return information, direct deposit account details, and confidential correspondence.

The attacker did not get long. The attacker did not get everywhere. The attacker got a folder, and the folder was full.

DocketWise: the vendor your matter data lives in

The third incident did not happen at a law firm at all. DocketWise, an immigration case management platform used by law firms, discovered in October 2025 that an unauthorized actor had used valid credentials to clone third-party partner repositories, some of which were part of a data migration pipeline.

That exposure reached 116,666 individuals and included names, Social Security numbers, government-issued identification numbers, contact details, financial account data, and health-related information. Notification did not begin until around April 2026, roughly six months after discovery.

Immigration clients are among the most vulnerable populations a firm serves. Their files contain passport numbers, immigration status, financial sponsorship records, and medical examinations, all in one place.


Why the entry point keeps being a person

Attackers target people because people are the reliable path in. The 2026 Verizon Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches, found that 62 percent of breaches involved the human element, up from 60 percent the year before. Social engineering accounted for 16 percent of breaches, making it the third most common incident pattern.

The channel is widening too. Verizon found that 41 percent of social engineering breaches now arrive through vectors other than email, with roughly a quarter coming through social media or phone-based contact. In phishing simulations, voice-based attempts produced a median click rate of 2 percent against 1.4 percent for email.

This is why the firewall framing fails. Security awareness training is worth doing, and every firm should do it, but no training program takes the success rate of pretexting to zero. A sufficiently convincing phone call will eventually work on a busy person on a deadline.

Detection is not keeping pace either. IBM's 2026 Cost of a Data Breach Report, released July 29, 2026 and based on 602 breached organizations, found that the mean time to identify and contain a breach rose to 247 days, reversing five consecutive years of improvement. The global average cost reached a record $4.99 million, up 12 percent, with the United States average at $11.5 million.

WilmerHale's own timeline fits that pattern almost exactly: 48 days from incident to discovery.


The variable you actually control

You cannot reduce social engineering success to zero. You can reduce what a successful attempt reaches.

That is the whole argument, and it is worth being precise about its limits. Redaction would not have stopped any of these three incidents. The employee would still have been deceived. The credentials would still have worked. What changes is the answer to the question every breach lawyer asks on day one: what was actually in the files?

A folder of employment records with full Social Security numbers produces one kind of notification obligation. The same folder with those numbers permanently removed produces a different one. The intrusion is identical. The consequences are not.

This is a data minimization control, not a breach prevention control, and we have written about that distinction in more detail in our analysis of whether AI redaction helps prevent data breaches. The point is not that redaction is a security perimeter. The point is that it changes the size of the loss when the perimeter fails.

Three questions worth asking about your own document stores:

  1. How many of your closed matters still contain full Social Security numbers, account numbers, and dates of birth? Closed files are rarely revisited once the work is billed, so identifiers collected at intake tend to stay exactly where they were put.
  2. How long does a completed matter sit in accessible storage before it is archived or destroyed? Retention policy is a security control, though it usually gets managed as a records question rather than a security one.
  3. When you produced redacted copies, did the redaction actually remove the underlying text? A black box drawn over text in many PDF editors leaves the text in the file. Our QA checklist for reviewing redactions before court production covers the verification steps, and the free PDF Redaction Checker tests any file for recoverable text and lingering metadata in a few seconds.

The one document store where redaction has no tradeoff

For an active matter, redaction involves a real tradeoff. You cannot remove a client's Social Security number from a file your team still needs it in. Access controls, encryption, and least-privilege permissions are the right controls there.

Closed matters are different, and they are where the argument becomes unambiguous.

Bar rules require firms to keep closed client files, and the periods are long. ABA Model Rule 1.15 sets five years after the termination of representation as a minimum for records. Most U.S. jurisdictions land between five and seven years for closed files. Civil litigation files often warrant eight to ten. Criminal defense files may need to be kept indefinitely where appeals or post-conviction relief remain possible, and estate planning files are commonly held until the client's death plus a buffer.

Here is the distinction that matters: the obligation is to retain the file, not to keep every identifier inside it legible.

A matter closed in 2019 can satisfy a ten-year retention requirement with the Social Security numbers removed. The record survives. The identifier does not. Nobody needs that number to answer a malpractice question in 2029. An intruder who reaches the archive in 2029 will find a use for it.

This is also where the scale sits. The archive is usually the largest and longest-lived document store a firm has, and the least monitored. Active matters get attention because people work in them daily. Closed matters just accumulate.

Two caveats worth taking seriously before touching anything:

  • Do not alter documents subject to a litigation hold or any preservation obligation. A hold overrides a retention schedule, and modifying held material creates a worse problem than the one you are solving.
  • Some records need their identifiers intact. Trust account and financial records, tax documents, and anything that may later be needed to verify identity are the obvious examples. Scope the work by record type rather than running it across the whole archive.

Within those limits, a closed-matter pass is the highest-value redaction work most firms have available, because there is no operational cost to removing data nobody will use again.


What "reasonable efforts" means under ABA Formal Opinion 483

The professional responsibility standard for law firms is not perfection. It is reasonable effort, and that distinction matters enormously after an incident.

ABA Formal Opinion 483, issued October 17, 2018, addresses a lawyer's obligations after a breach involving client data. It reads Model Rule 1.6(c) as a reasonable-efforts standard rather than strict liability. As the opinion frames it, Rule 1.6 is not violated even if data is accessed, provided the lawyer made reasonable efforts to prevent that access.

The opinion also imposes affirmative duties: monitor for breaches, stop ongoing unauthorized access, restore the integrity of affected systems, and notify current clients whose confidential information was or may have been compromised. It implicates Rules 1.1, 1.4, 1.6, 1.15, 5.1, and 5.3.

Read that standard alongside the 2026 incidents and the practical question becomes clear. After an incident, your firm has to show what it had done in advance. Documented data minimization, an enforced retention schedule, and an audit trail showing which documents were processed and when are all evidence of reasonable effort. The absence of any of them is evidence of the opposite.

Litigation follows this reasoning quickly. BakerHostetler's 2026 Data Security Incident Response Report, its twelfth annual and drawn from more than 1,250 incidents handled in 2025, found that class actions were filed in 14 percent of incidents, up from 9 percent in 2024.


How to reduce document-level exposure

None of this requires a security program overhaul. It requires deciding that sensitive data should not sit in accessible documents longer than the work requires.

  1. Inventory where full identifiers actually live. Start with employment files, client intake records, and closed matters. These are the three stores that accumulate Social Security numbers and financial account details, and the three that rarely get revisited once the work is done.
  2. Redact before archiving, not just before sharing. Redaction usually gets triggered by a disclosure event: a production, a filing, a records request. Running it again before a matter enters long-term storage is the closed-matter pass described above, and it is where the exposure reduction is permanent.
  3. Set and enforce a retention schedule. A document destroyed on schedule cannot be exposed. Map the obligations by matter type, then automate deletion where your document management system supports it.
  4. Confirm your redactions are permanent. Visual overlays leave the underlying text in the file. Test finished documents by attempting to copy text from a redacted region and by running a text extraction pass. Our guide on why law firms keep exposing PII in PDFs covers the specific failure modes.
  5. Ask your vendors what they retain. DocketWise was not a law firm. It was software that law firms trusted with matter data. The questions to put to any vendor holding your documents are covered in our guide to what happens to documents after AI redaction processing.
  6. Keep an audit trail. After an incident, the record of what was redacted, by whom, and when is what converts a claim of reasonable effort into evidence of it.

RedactifyAI handles the redaction step in that sequence. It detects and permanently removes more than 40 entity types across PDF, Word, and scanned image files, strips metadata in the same pass, and logs every processed document with a timestamp and user reference. It does not stop a pretexting call. It changes what that call can reach.


Frequently asked questions

How many law firms had data breaches in 2026?

Three significant incidents affecting law firm client and employee data became public in 2026: WilmerHale, disclosed in July; McDermott Will & Schulte, reported to the Vermont Attorney General on August 28; and DocketWise, a legal software vendor whose April 2026 notifications covered 116,666 individuals. Each involved social engineering or misused credentials rather than technical exploitation.

What caused the WilmerHale data breach?

On May 8, 2026, a WilmerHale employee provided information to an unauthorized third party who had misrepresented their identity. The firm discovered the incident on June 25, began notifying affected individuals on July 10, and was named in a proposed class action on July 14 in the U.S. District Court for the District of Columbia. Names and Social Security numbers were exposed.

Should law firms redact closed client files?

Yes, within limits. Bar retention rules require keeping the file, not keeping every identifier inside it legible, so a closed matter can satisfy a five to ten year retention obligation with Social Security numbers removed. Two exceptions matter: never alter documents under a litigation hold, and leave identifiers intact in trust account, tax, and identity verification records.

Does redaction prevent data breaches?

No. Redaction is a data minimization control, not a breach prevention control. It does not stop credential theft, social engineering, or unauthorized access. What it changes is the scope of exposure when an incident occurs, because permanently removed identifiers are not in the files an attacker reaches. It works alongside access controls and encryption, not instead of them.

Are law firms liable when client data is exposed?

ABA Formal Opinion 483 reads Model Rule 1.6(c) as a reasonable-efforts standard rather than strict liability, meaning a lawyer does not violate the rule simply because data was accessed, provided reasonable preventive efforts were made. Separately, civil liability is a real exposure: BakerHostetler's 2026 report found class actions were filed in 14 percent of the incidents it handled.

How long does it take to detect a law firm data breach?

IBM's 2026 Cost of a Data Breach Report found the mean time to identify and contain a breach across all industries rose to 247 days, reversing five years of improvement. WilmerHale's disclosed timeline was 48 days from the May 8 incident to discovery on June 25. Longer detection windows increase the volume of data an intruder can reach.

What should law firms do about vendor data breaches?

Treat vendor storage as your exposure. The DocketWise incident exposed 116,666 individuals through a legal software platform, not a law firm. Ask vendors how long they retain documents after processing, whether they keep originals as well as outputs, where data is processed geographically, and whether they will sign a data processing agreement covering those commitments.


If you want to see how much of the sensitive data in your own files could be permanently removed before it ever reaches an archive, upload a PDF to our free redaction tool and look at what gets flagged. No account required.

Stop redacting documents manually

RedactifyAI detects PII automatically and redacts it permanently. Not just a black box overlay. Try it free, no credit card required.

Learn more about AI redaction software and how it compares to manual redaction tools.