Seyfarth Shaw LLP, a national law firm headquartered in Chicago, has begun notifying individuals that an unauthorized party gained access to a limited number of documents containing their personal information. Law firms handle large volumes of sensitive personal and financial information on behalf of their own clients and the individuals involved in those clients’ matters, and they carry a responsibility to keep that information secure.
Seyfarth Shaw’s Data Breach Investigation
According to a notification letter filed with the California Attorney General’s office, Seyfarth Shaw identified on August 18, 2026 that an unauthorized party had obtained a limited number of documents containing personal information. The firm states it obtained the affected individuals’ information in the course of legal services it performed. Upon discovering the incident, Seyfarth Shaw says it promptly took steps to confirm the security of its network and began an investigation into the nature and scope of the event.
Seyfarth Shaw’s investigation reportedly confirmed that there was no evidence of unauthorized access to the firm’s broader computer network, and that the event was limited to a small number of documents sent by email to an unauthorized recipient. In other words, the firm describes this as a misdirected-email-style incident rather than a network intrusion or ransomware attack, a narrower category of exposure than incidents involving a compromised network or server.
Law firms are frequent targets for both opportunistic and targeted cyberattacks because of the sensitive nature of the material they hold, litigation records, settlement details, medical records tied to legal claims, and personal identifiers like Social Security numbers used in a wide range of legal matters. Even incidents that do not involve a network-wide compromise, such as a document mistakenly sent to the wrong recipient, can expose the same sensitive categories of information as a larger-scale breach, since a single misdirected file can contain Social Security numbers or other identifiers for many individuals at once.
Seyfarth Shaw states that it already had network monitoring, external access restrictions, and employee training and awareness programs in place, and that it is instituting additional employee training and awareness notifications in response to this incident. The firm’s response, additional training paired with credit monitoring for affected individuals, reflects a common industry pattern for addressing incidents that stem from human error in handling sensitive files, as opposed to a technical vulnerability that would require a different kind of remediation.
Individuals whose names and Social Security numbers are exposed in an incident like this face an elevated risk of identity theft, since a Social Security number combined with a name is often enough for a bad actor to attempt to open new credit accounts, file fraudulent tax returns, or pass other identity checks. Because Seyfarth Shaw obtained this information through legal services performed on behalf of a client, affected individuals may not have had any direct relationship with the firm itself, which can make it harder for them to learn they were affected unless they receive a direct notification letter.
When Did This Breach Occur?
Seyfarth Shaw states that it identified the unauthorized acquisition of documents on August 18, 2026. The firm’s notification letter to affected individuals is dated September 18, 2026.
What Information Was Breached?
According to Seyfarth Shaw’s notification letter, the information involved includes the affected individual’s name and Social Security number.
What You Can Do
Seyfarth Shaw is offering affected individuals access to Single Bureau Credit Monitoring, a Single Bureau Credit Report, and a Single Bureau Credit Score at no charge for 24 months, provided through Cyberscout. If you received a notification letter from Seyfarth Shaw, consider taking the following steps:
- Enroll in the complimentary credit monitoring services within 90 days of your notification letter
- Review your credit reports and financial statements regularly for unfamiliar activity
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Report any suspicious account activity to your financial institution and to law enforcement promptly
File a Data Breach Lawsuit Against Seyfarth Shaw
If you received a notice that your personal information may have been compromised in the Seyfarth Shaw data breach, you may have legal options available to you. Organizations that handle sensitive personal information, including law firms handling client and third-party data, have an obligation to keep that information reasonably secure.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.