Quinn Emanuel and McDermott data breaches: what we know, what to do
If you were named in this filing, here’s what is being claimed, and what it would mean for you.
Two major law firms, Quinn Emanuel and McDermott Will & Schulte, each confirmed a separate incident in which an employee was tricked and a limited number of documents reached an unauthorized person. McDermott said Social Security numbers and health records were involved and that 15 Vermont residents were affected. The firms say they notified people in those files; the copies cannot be taken back.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
What’s already out there about you?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
Quinn Emanuel confirmed that on August 14, 2026, an unauthorized person reached stored files for a single software application through one temporarily compromised user account, after an employee was tricked. The firm said a limited number of client documents were impacted, including some related to the investment firm Muddy Waters, that affected parties have been informed, and that law enforcement was notified. It has not reported any ongoing unauthorized access.
McDermott Will & Schulte described a separate incident involving a single user and a limited number of documents. In a public notice dated September 2, 2026, the firm said that on May 7, 2026, an employee inadvertently provided copies of a limited number of documents to an unauthorized person, and that health information was among them. McDermott reported the incident to the Vermont Attorney General on August 28, 2026, stating that 15 Vermont residents were affected and that the data included Social Security numbers and health records. It notified law enforcement, says the matter is resolved, and says its systems remain secure. No figure beyond “limited,” other than those 15 Vermont residents, has been published.
The small numbers are not a clean bill of health
Coverage has mostly followed the firms’ own wording: isolated, one user, a limited number of documents, systems still secure. Those points are what Quinn Emanuel and McDermott stated. There is no public evidence that the two incidents are connected, and neither firm has reported ongoing access.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
What that wording does not mean is that only a handful of people nationwide were involved, or that the information is trivial. McDermott’s figure of 15 Vermont residents is what it filed with one state attorney general. It is not a published nationwide total. Filings with other states have not been confirmed. “Limited” is how a large law firm describes a few files relative to everything it stores. If one of those files is about you, the incident is not limited. McDermott has already said Social Security numbers and health records were in the Vermont notice. Those are not passwords. They do not expire when the firm finishes its investigation.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
Law-firm documents also do not only describe the firm’s paying clients. Files can name counterparties, witnesses, employees, and family members. The firms say they have informed affected parties. That notice is the signal they have given. There is no public list of names, and typical “was I breached?” lookups do not contain these files. A clean result in a search tool does not mean you were checked against Quinn Emanuel’s or McDermott’s documents. It usually means those documents are not in anything such a tool can search.
The honest read is narrower than a mass consumer breach and more serious than “systems remain secure” sounds. Most people who see this news were not in those files. “Systems remain secure” means the firms say their computers are no longer open to the unauthorized person. It does not mean the copies came back. McDermott’s copies left on May 7; the public notice was September 2. If neither firm has contacted you, that is currently the only indication they have given that you were not among the affected parties. If one of them has, the live problem is not whether the network is patched. It is that copies of documents about you are already in someone else’s hands.
What to actually expect
- A letter or official notice from Quinn Emanuel or McDermott Will & Schulte, if they consider you affected. Quinn Emanuel says those parties have been informed. McDermott posted a consumer notice on September 2, 2026, and reported 15 Vermont residents to Vermont. Unexpected texts or “click here to see if you were in this claimed breach” pages are not how these firms have communicated.
- Nothing useful from ordinary breach-lookup sites. These were documents from single law-firm accounts, not a leaked customer database that those sites ingest.
- No public roster of victims, no named attacker, and no confirmation the two incidents are linked. Those details remain unconfirmed. Do not wait for a complete list to appear.
- If a McDermott notice to you mentions a Social Security number or health records, the near-term problems to watch for are new credit or tax filings in your name, and medical bills or insurance claims you do not recognize — not a password you can change.
What you can and cannot fix
The copies cannot be pulled back. If your information was in the documents that left Quinn Emanuel or McDermott, that transfer is done. A Social Security number that was in those files is still your Social Security number. A health record is still a health record. Neither the firms nor anyone else can delete those copies from the unauthorized person. Treat that as permanent.
- Treat only a notice from the firm as confirmation you were involved. If you have one, follow the steps in that notice first. If you do not, there is no public file you can search to double-check, and acting as if your identity is already stolen is not supported by what the firms have published.
- If a notice includes your Social Security number, freeze your credit with Equifax, Experian, and TransUnion. A freeze is what actually blocks most new accounts in your name. Watching statements or paying for monitoring only tells you after something has already been opened.
- If health information was involved, flag it with your insurer and your regular clinic or hospital. Ask them to note possible medical identity theft and review claims for care you did not receive. You cannot make the record secret again. You can make it harder to use for fraudulent treatment or billing.
- Remove the extra personal details that people-search sites publish about you. A leaked legal document or Social Security number becomes much easier to misuse when it can be joined to listings that add relatives, phone numbers, employers, and previous addresses. Those listings are not the stolen files — and unlike the stolen files, they can actually be taken down. That is the part of your public footprint you can still reduce.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Quinn Emanuel and McDermott.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
ShinyHunters 2026 Spree: 5 Major Breaches in 30 Days — Trend Analysis
In 30 days spanning Jan–Feb 2026, ShinyHunters claimed five major breaches: Match Group, Crunchbase,…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…