All articles

US law firm data breaches expose Social Security numbers

Holland & Knight and Squire Patton Boggs reported breaches involving Social Security numbers. Here is what is known and how firms can reduce remote-access risks.

October 11, 2026·5 min read·Posted in: Cybercrime
DanishLæs på dansk
Share this article
X (Twitter)LinkedInFacebook
US law firm data breaches expose Social Security numbers

What the two law firms disclosed

Holland & Knight and Squire Patton Boggs have reported separate data breaches involving Social Security numbers, the US identifiers used for purposes including tax and credit records. Both disclosures appear in Vermont's breach register with a reporting date of 8 October 2026.

The Vermont Attorney General's register lists one affected Vermont resident for Holland & Knight and two for Squire Patton Boggs. Those are state-level figures, not the total number of people affected. The reporting date also does not establish when either intrusion happened.

According to Cybernews' account of the firms' statements, Holland & Knight said social engineering allowed an attacker to obtain remote access to a firm computer. It reported that a small number of files were involved and that it had notified 14 affected clients. The firm said it contacted law enforcement and kept its systems operational.

Squire Patton Boggs said an unauthorized party obtained a limited set of information and that client services continued without disruption, Cybernews reported.

Fourteen clients should not be read as fourteen individuals. A client may be an organization, and a file may contain information about several people. The sources reviewed for this article do not establish the overall number of affected individuals or show that the two incidents were connected.

Why remote access deserves attention

Holland & Knight's reported account puts the initial focus on social engineering: manipulating someone into taking an action that gives an attacker access. The public details do not explain the precise exchange, the software used or the attacker's identity. Squire Patton Boggs' entry method is not established in the cited reporting.

A hypothetical example helps explain the risk. Someone claiming to be IT support calls about an urgent computer problem and asks an employee to approve a remote session. If the employee trusts the caller, the attacker may gain access through software that also has a legitimate business use. This is an illustration, not a reconstruction of either incident.

The joint guide to securing remote access software from CISA, the FBI and partner agencies describes how attackers misuse legitimate administration tools. It recommends auditing installed tools, controlling which can run and monitoring for unauthorized use.

For employees, the difficult part is often judging a plausible request during an ordinary working day. Our guide to social engineering explains how impersonation and pressure can influence that decision.

Continued service does not settle the privacy question

Both firms reportedly maintained their services. That tells clients something useful about availability, but it does not establish what happened to the information accessed.

For a firm handling client records, the next questions are specific: which files were accessible, what information did they contain, and whose details were involved? Counting documents alone cannot answer them. A single spreadsheet can contain many people's information.

The disclosures reviewed here establish that Social Security numbers were involved. They do not establish that every client file was exposed, that stolen data was published or that identity theft has occurred. Keeping those distinctions clear helps affected people understand what a notification actually says.

Put a verification step before remote access

Firms can review how staff approve support requests without waiting for the full investigation results. Start with the moment someone asks to see or control a computer:

  • Verify unexpected support requests independently. Contact IT through the help desk or number already listed in the firm's directory. A number supplied by the caller does not provide an independent check.
  • Use approved remote-support tools. IT should maintain an inventory, restrict unapproved tools and review session logs for unusual activity, in line with the joint agency guidance.
  • Limit access to client records. Give staff access to the matters they work on and review permissions as responsibilities change. This can reduce how much information one compromised account can reach.
  • Make reporting easy. Employees should know whom to contact immediately if they approved an unexpected session. A report is useful even when someone is unsure whether a request was fraudulent.

Practice the verification step with realistic support scenarios. Staff need a procedure they can follow under pressure, and managers need to make time for that check.

If you receive a breach notification

Read the notice for the information involved and the assistance offered. Verify unexpected follow-up messages through an established contact at the firm before sharing more personal details.

For people with US credit records, the Federal Trade Commission explains how credit freezes work. A freeze can help prevent someone from opening new credit in your name. It is free, and you must contact Equifax, Experian and TransUnion separately to freeze all three reports. The FTC also recommends checking credit reports for unfamiliar accounts. These are US procedures, rather than instructions for other countries' credit systems.

For firms, a useful first action is to check whether every employee can verify a remote-support request through a known channel. If that route is unclear or slow, fix it before the next urgent call arrives.

Sarah Krarup

Sarah Krarup

Sarah studies innovation and entrepreneurship with a deep interest in IT and how cybersecurity impacts businesses and individuals. She has extensive experience in copywriting and is dedicated to making cybersecurity information accessible and engaging for everyone.

View all posts by Sarah Krarup
Get started

See how your team can reduce human risk

Explore how Moxso helps your team identify employee risk, target training and assess progress. Tell us where you want to reduce exposure.

  • Explore how training, simulations and follow-ups address gaps.
  • See how human risk varies across your organization, departments and employees.
  • Review how your goals automatically steer risk reduction.

By submitting this form, you agree to our Privacy Policy.

ISO 27001-certified ISMSReview the certificate and its scope.
EU sovereign by architectureData sovereignty compliance built in.