Holland & Knight and Squire Patton Boggs disclose data breaches
TLDR
- Holland & Knight (about 2,200 lawyers) and Squire Patton Boggs (about 2,600 lawyers) have each disclosed data-security breaches that exposed Social Security numbers, according to regulatory filings this week.13
- Holland & Knight said a threat actor used social-engineering techniques to gain remote access to one of its computers; Squire Patton Boggs said an unauthorised third party obtained a limited set of information.3
- Neither firm has disclosed how many people in total were affected, and the disclosures follow a run of law-firm breaches through 2026 at Jones Day, Quinn Emanuel, McDermott Will & Emery and Greenberg Traurig.123
Holland & Knight LLP and Squire Patton Boggs LLP both notified regulators this week that Social Security numbers were exposed in separate cyber incidents.13 Holland & Knight, which has about 2,200 lawyers, said a threat actor used social-engineering techniques to gain remote access to a firm computer, while Squire Patton Boggs, with roughly 2,600 attorneys, said an unauthorised third party obtained a limited set of information.3 A third firm, Nelson Mullins, is separately facing a proposed class action over a cyber incident involving private information.3
Both firms are among the largest law practices globally, handling privileged client data across corporate, litigation and regulatory work, which makes them attractive targets for attackers seeking leverage over well-resourced clients.123 The disclosures land amid a wider pattern of law-firm breaches through 2026, following similar incidents reported at Jones Day, Quinn Emanuel Urquhart & Sullivan, McDermott Will & Emery and Greenberg Traurig earlier in the year.1 Law firms have increasingly become targets precisely because they hold concentrated, high-value data on behalf of corporate clients across mergers, litigation and regulatory matters, often with less mature security tooling than the clients they represent.13
Neither firm has disclosed how many people in total were affected, when the incidents occurred, or whether they are offering credit monitoring.23
Why it matters: two more global law firms joining this year's run of legal-sector breaches, both involving Social Security numbers, shows attackers have identified the profession's privileged, cross-client data as a reliable target, and the firms' silence on scope and root cause makes it hard for clients to judge their own exposure.