Two of the legal industry’s best-known names disclosed data-security incidents within days of each other this month, putting fresh scrutiny on how law firms protect the Social Security numbers, financial records, and litigation files that sit on their servers. Holland & Knight LLP, a 2,000-lawyer firm with offices across the United States, said an attacker used social engineering to gain unauthorized remote access to a firm computer and viewed a small number of files containing sensitive client data. Separately, Squire Patton Boggs LLP confirmed that an unauthorized third party obtained a limited set of information, including Social Security numbers, in an incident reported on October 8, 2026.

Neither firm has said the two incidents are connected, and nothing in the public record ties them together. But the near-simultaneous disclosures land at a moment when breach counts across the legal sector are already climbing. According to Law360 Pulse, 2025 saw more than 200 law-firm data breaches, the highest annual total since 2020. For a profession that trades on confidentiality as its core product, that trend line is becoming impossible to ignore.

What Holland & Knight Disclosed

Holland & Knight, which describes itself as one of the largest law firms in the United States, said an attacker used social engineering, rather than a software exploit, to obtain unauthorized remote access to a firm computer. Social engineering typically means tricking an employee or help-desk worker into granting access, handing over credentials, or approving a login request, rather than breaking through a technical defense. The firm said the intrusion affected a small number of files, and that those files contained information including Social Security numbers.

Holland & Knight identified 14 clients as affected by the incident and said those clients were promptly notified. The firm also said it contacted law enforcement and that its systems remained operational throughout the incident, meaning the firm did not experience the kind of ransomware-driven outage that has hit other professional-services companies this year, including EY’s own breach disclosure earlier in 2026.

What the firm has not disclosed publicly is just as notable. Holland & Knight has not released the date the intrusion occurred, how long the attacker retained access, or the total number of individuals whose data appeared in the exposed files. Those gaps are common in early-stage breach notices, where firms often wait for a forensic review to finish before quantifying scope, but they also mean outside observers cannot yet judge how serious the incident was relative to other 2026 cases.

Squire Patton Boggs’ Separate Breach

Squire Patton Boggs LLP, a global firm with roughly 1,500 lawyers across more than 20 countries, filed its own breach notice describing the event in narrower terms. The firm stated that an unauthorized third party obtained a limited set of information, a phrase it repeated in its regulatory filing. That information included Social Security numbers, according to the disclosure.

The regulatory filing, reported on October 8, 2026, named two Vermont residents as affected individuals. Vermont’s breach-notification statute is one of the stricter state laws in the country and often surfaces in national breach trackers because the state requires detailed disclosures even when the number of affected residents is small. Firms with any Vermont-connected clients or employees frequently end up filing with the Vermont Attorney General’s office even when the breach’s overall footprint is concentrated elsewhere, which is one reason a filing can name a tiny resident count while the true scope of a breach remains undisclosed in other jurisdictions.

Squire Patton Boggs said client services were not disrupted during the incident, language that mirrors Holland & Knight’s assurance that its systems stayed operational. Both firms are, in effect, drawing a line between “we lost some data” and “we lost control of our network,” a distinction that increasingly matters to clients deciding whether to stay with a firm after a breach.

Side-by-Side: The Two Disclosures

The two incidents share a common thread, exposed Social Security numbers, but differ in nearly every detail that has been made public so far. The table below lines up what each firm has confirmed.

DetailHolland & Knight LLPSquire Patton Boggs LLP
Reported attack methodSocial engineering, unauthorized remote accessNot specified; “unauthorized third party obtained a limited set of information”
Data types involvedSocial Security numbers, among other file contentsSocial Security numbers and other limited information
Affected clients/individuals named14 clients, “promptly notified”2 Vermont residents named in filing
Disclosure date reportedEarly October 2026October 8, 2026
Law enforcement contactedYes, firm says it contacted law enforcementNot specified in available disclosure
Operational impactSystems remained operationalClient services not disrupted
Incident date/durationNot publicly disclosedNot publicly disclosed

Reading the two filings side by side, the gaps are as informative as the confirmed facts. Neither firm has said when the unauthorized access began, how it was discovered, or the full population size behind each number. That is standard practice at this stage of a breach response, when counsel is still weighing what state and federal notification laws require versus what a firm chooses to volunteer.

Why Law Firms Keep Showing Up on Breach Trackers

Law firms sit on an unusual concentration of sensitive data without the security budgets that banks or hospitals typically carry. A single corporate law firm can hold Social Security numbers, bank account details, trade secrets, merger plans, and litigation strategy for dozens of clients at once, all protected by attorney-client privilege but not necessarily by the kind of layered defenses a Fortune 500 company runs internally. Attackers who cannot breach a target company directly have learned they can sometimes reach the same data by going through outside counsel instead.

The numbers back up that shift. The Privacy Rights Clearinghouse‘s 2026 Midyear Data Breach Report found that law firms and legal-services providers logged 207 breach events in 2025, up from 137 in 2022. The first half of 2026 alone produced 113 breach events in the sector, compared with 64 in the first half of 2022. As a share of all breach activity tracked by the organization, legal-sector incidents rose from 3.8% of events in 2022 to 5.7% in 2025, a meaningful climb for an industry that was rarely a top-five target a decade ago.

Social engineering specifically, the method Holland & Knight says was used against it, is not a niche tactic. Verizon’s 2026 Data Breach Investigations Report, which examined incidents from November 2024 through October 2025, found the human element present in 62% of breaches, up from 60% the year before, and classified social engineering as the third-most-common breach pattern at 16% of incidents. Ransomware appeared in 48% of breaches studied, up from 44% previously, while exploitation of software vulnerabilities accounted for 31% of incidents. Those figures, drawn from Verizon’s own report summary, make clear that tricking a person remains at least as productive for attackers as finding an unpatched server.

The Help-Desk Problem

Social engineering attacks against large organizations increasingly target IT help desks and remote-access workflows rather than individual employee inboxes. An attacker impersonating staff can call a help desk, claim a forgotten password or a locked multi-factor authentication device, and talk a support technician into resetting credentials or approving a new device. Holland & Knight has not described the specific mechanics of the social-engineering attempt that succeeded against it, but the broad category fits a pattern security researchers have flagged repeatedly across 2025 and 2026: attackers probing the weakest link in an otherwise hardened network, which is frequently a person on the other end of a support call rather than a firewall rule.

A Pattern Bigger Than Two Firms

Holland & Knight and Squire Patton Boggs are not isolated cases within the legal industry this year. Law360 Pulse reported that Seyfarth Shaw disclosed a 2026 breach exposing the names and Social Security numbers of more than 300 people, part of what the outlet described as a broader wave tied partly to the growing role of AI-assisted attack tooling in the sector. None of those incidents has been publicly linked to the Holland & Knight or Squire Patton Boggs disclosures, and nothing in the available record suggests a shared campaign, but the clustering of law-firm breach notices in a short window is itself a signal worth tracking.

This also is not the legal industry’s first brush with mass data exposure. The 2023 MOVEit file-transfer breach, one of the largest supply-chain compromises in recent memory, affected more than 2,700 organizations and exposed personal information tied to more than 93 million people, with Kirkland & Ellis and K&L Gates among the law firms named on the attacker’s leak site at the time. That incident showed how a single vulnerable piece of shared software could pull dozens of firms into one breach narrative at once, a dynamic also visible in large-scale government exposures like the Pentagon’s own Social Security number breach earlier in 2026. The Holland & Knight and Squire Patton Boggs cases look different on their face, each firm describing an isolated intrusion rather than a shared software flaw, but the underlying lesson is the same: law firms are now treated by attackers as a reliable path to the data of companies that have otherwise locked their own networks down.

To put the current moment in context, it helps to look at how legal-sector breach reporting has grown over the past several years using the figures available from Privacy Rights Clearinghouse and Law360 Pulse.

PeriodLegal-sector breach eventsShare of all tracked breach eventsSource
Full year 20221373.8%Privacy Rights Clearinghouse
Full year 2025207 (also described as 200+ by Law360 Pulse)5.7%Privacy Rights Clearinghouse / Law360 Pulse
First half 202264Not separately reportedPrivacy Rights Clearinghouse
First half 2026113Not separately reportedPrivacy Rights Clearinghouse

The first-half 2026 figure of 113 events already outpaces the full first-half 2022 count by a wide margin, and if the second half of the year tracks anything close to the first, 2026 could challenge or exceed 2025’s record total once final numbers are tallied. Holland & Knight and Squire Patton Boggs are now part of that running count, alongside Seyfarth Shaw and whichever firms disclose next.

What Clients Can Actually Do About It

For the 14 clients named in the Holland & Knight notice and the two Vermont residents named by Squire Patton Boggs, the practical next steps look similar to those recommended after any breach involving Social Security numbers: placing a credit freeze with the major bureaus, enrolling in any credit-monitoring service the firm offers, and watching for unfamiliar credit inquiries or tax-filing attempts under their name. Firms typically offer free monitoring for a defined period, often 12 to 24 months, after a breach notice, though neither Holland & Knight nor Squire Patton Boggs has published the specific terms of any remediation offer in the portions of their disclosures available publicly.

State attorneys general publish breach notification letters as a matter of public record in many jurisdictions, which is often the fastest way for an affected individual to confirm whether their state has received a formal notice and what remedies the filing describes. California’s data breach notification list is one widely used example, and residents of states with active notification requirements can usually search their own attorney general’s site directly rather than waiting for a firm’s public statement.

How Firms Typically Respond After Disclosure

Both firms followed a response pattern that has become fairly standard across the legal and professional-services industry since 2024: confirm the breach occurred, describe the data categories involved in general terms, state that client services were not disrupted, and contact law enforcement. Holland & Knight explicitly said it reported the incident to law enforcement, a step that can trigger parallel review by agencies such as the FBI’s Internet Crime Complaint Center, though there is no public indication yet of a formal law enforcement investigation outcome in either case.

What neither firm has done, at least in the information available so far, is attribute the attack to a named criminal group or state actor. That restraint is typical early in an investigation. Firms generally avoid naming an attacker until forensic investigators have higher confidence, both because premature attribution can be wrong and because it can complicate any eventual law enforcement action.

The Regulatory Exposure Law Firms Now Face

Breach notification law in the United States is a patchwork of state statutes rather than one federal standard, which is part of why a filing naming only two Vermont residents can coexist with a much larger, undisclosed national footprint. Firms doing business across many states have to track separate notification deadlines, content requirements, and, in some states, mandatory free credit-monitoring periods. A firm the size of Squire Patton Boggs, operating in more than 20 countries, also has to weigh notification obligations outside the United States, including requirements under data-protection regimes in the European Union and United Kingdom if any client data tied to those jurisdictions was affected, something the available disclosure does not address either way.

This regulatory complexity is one reason breach notices from large multinational firms often arrive in stages: an initial, narrowly scoped filing in one jurisdiction, followed weeks or months later by supplemental notices as the investigation widens or as other states’ deadlines come due. Readers tracking similar staged disclosures elsewhere, such as the GDPR-driven timeline in the Denmark CPR breach or the extended notice gap in EY’s own disclosure, will recognize the pattern: the first public notice is rarely the last word on scope.

Market and Reputational Impact

Unlike publicly traded breach targets, neither Holland & Knight nor Squire Patton Boggs has a stock price that can move on the news, since both are private partnerships. The real-world consequence for a law firm after a breach tends to show up less in headlines and more in client retention over the following renewal cycle. Corporate general counsel offices increasingly run their own vendor-security reviews of outside law firms, and a breach disclosure, even a contained one, can trigger a formal security questionnaire or, in some cases, a client decision to diversify work across additional firms rather than concentrate sensitive matters with one that has just reported an incident.

That dynamic has pushed large firms to invest more visibly in cybersecurity credentials, from SOC 2 reports to dedicated chief information security officer roles, treating security posture as a competitive differentiator in client pitches rather than a back-office cost center, particularly as data-theft and extortion activity keeps climbing industry-wide. Whether the Holland & Knight and Squire Patton Boggs incidents accelerate that trend further, or simply blend into an already-crowded 2026 breach count, will likely become clearer as more firms report their own fourth-quarter numbers.

What to Watch Next

A handful of open questions will shape how seriously these two disclosures are ultimately judged. First, whether either firm updates its public notice with a firmer total count of affected individuals once forensic review concludes, since 14 clients and two named residents likely understate the full population in at least one of the two cases. Second, whether other state attorneys general receive filings beyond Vermont and whatever jurisdiction Holland & Knight’s 14 notified clients reside in, which would clarify the true geographic reach of each breach. Third, whether either firm or law enforcement eventually attributes the intrusions to a known criminal group, which would place these incidents within a broader campaign narrative rather than as standalone events.

It is also worth watching whether other large firms follow with their own disclosures in the coming weeks. Clustered breach reporting in the legal sector has become common enough in 2026 that a single incident rarely stays isolated for long, a pattern visible in other industries too, including the wave of related filings that followed ShinyHunters’ breach claims earlier this year.

Predictions: Where This Goes From Here

  • Expect at least one more named law firm to disclose a breach before the end of 2026, given the sector’s accelerating pace of incidents tracked by Privacy Rights Clearinghouse and Law360 Pulse.
  • Expect Holland & Knight’s “14 clients” figure to be revised upward if the firm files supplemental notices in additional states, a common pattern when a single social-engineering intrusion touches files tied to clients across multiple jurisdictions.
  • Expect more law firms to publish named chief information security officer roles and SOC 2 attestations in business-development materials over the next two quarters, using security credentials as a client-retention tool.
  • Expect state attorneys general, particularly in stricter-disclosure states like Vermont and California, to keep surfacing small but specific breach counts that hint at larger, still-undisclosed totals elsewhere.
  • Expect continued ambiguity on attribution in both cases for at least several more weeks, since neither firm has named a specific threat actor and law enforcement investigations of this type typically take months to reach public conclusions.

The takeaway from this week’s disclosures is not that two firms failed at security while their peers succeeded. It is that the legal sector’s data-breach count has been climbing steadily for several years, and two well-known names landing on that list in the same week is now closer to expected than exceptional. Privacy Rights Clearinghouse’s count of 207 legal-sector breach events in 2025, against 137 just three years earlier, describes an industry that has become a target of choice rather than a target of opportunity.

For clients, the practical response is the same regardless of which firm sent the notice: freeze credit where Social Security numbers were involved, read the specific notification letter rather than relying on news coverage alone, and ask outside counsel directly what security controls, such as phishing-resistant multi-factor authentication and help-desk verification procedures, are in place to prevent a repeat. For the firms themselves, the pressure to answer that question convincingly is only going to grow as the 2026 breach count climbs further.

Frequently Asked Questions

What happened at Holland & Knight?
An attacker used social engineering to gain unauthorized remote access to a firm computer, according to the firm’s disclosure. A small number of files containing information such as Social Security numbers were viewed, and 14 clients were identified as affected and promptly notified.

What happened at Squire Patton Boggs?
The firm disclosed that an unauthorized third party obtained a limited set of information, including Social Security numbers, in an incident reported on October 8, 2026. A regulatory filing named two Vermont residents as affected.

Are the two breaches connected?
There is no public confirmation that the Holland & Knight and Squire Patton Boggs incidents are related. Available reports do not establish a connection between them.

How many people were affected in total?
Holland & Knight has not disclosed a total individual count beyond the 14 clients it says were notified, and Squire Patton Boggs’ filing names only two Vermont residents. Neither firm has published a comprehensive total affected-individual count publicly.

Did either firm’s systems go down?
No. Holland & Knight said its systems remained operational throughout the incident, and Squire Patton Boggs said client services were not disrupted.

Why do law firms keep getting breached?
Law firms hold concentrated amounts of sensitive client data, including Social Security numbers and financial records, often without the same security budgets as banks or hospitals. Privacy Rights Clearinghouse recorded 207 legal-sector breach events in 2025, up from 137 in 2022, reflecting a sustained increase in attacker interest in the sector.

What should affected clients do?
Clients named in a breach notice involving Social Security numbers should place a credit freeze with major credit bureaus, enroll in any monitoring service offered by the firm, and watch for unfamiliar credit inquiries. State attorneys general, including California’s and Vermont’s, publish breach notification filings that can confirm the scope of what was formally reported.

What is social engineering, in this context?
Social engineering describes an attack that manipulates a person, rather than exploiting a software flaw, into granting access. Common tactics include impersonating staff to a help desk, phishing for login credentials, or persuading an employee to approve a fraudulent access request. Verizon’s 2026 Data Breach Investigations Report found social engineering behind 16% of breaches studied, making it the third-most-common breach pattern identified.