Seyfarth Shaw has disclosed a data security incident in which a small number of client documents containing personal information were sent to an unauthorized recipient after an employee was deceived by someone posing as a member of the firm’s IT help desk.
The law firm informed officials in Texas and California about the incident. According to the disclosures, the compromised documents included sensitive information such as names and Social Security numbers.
Seyfarth said the incident resulted from a targeted social engineering attack. An individual impersonating an IT support employee allegedly persuaded one of the firm’s employees to email a limited number of client documents to an outside email address that was not authorized to receive them.
The firm said the incident was confined to a single employee and that its security measures prevented the attacker from gaining access to its broader network or internal systems.
In its notification to Texas authorities, Seyfarth described the incident as a data security breach involving personal information. A separate notice prepared for an affected individual in California said the firm had identified the unauthorized acquisition of a limited number of documents containing personal information obtained during legal services.
The firm’s investigation found no evidence that its network had been accessed without authorization. Instead, the exposure was limited to documents that were transmitted by email to an unauthorized recipient.
Seyfarth, which was founded in Chicago, has more than 1,000 lawyers working from 14 offices across the United States. Its practice includes major areas such as real estate as well as labor and employment work representing management.
The incident comes amid a growing number of cybersecurity problems affecting law firms, which routinely handle confidential business records and highly sensitive personal information.
A report released by BakerHostetler earlier this year said its digital asset and data management teams responded to nearly 60 incidents involving law firms during the previous year, representing a substantial increase from the year before.
Other major firms have also recently reported cybersecurity incidents. Greenberg Traurig disclosed a breach that was followed by proposed class-action lawsuits, while Quinn Emanuel, McDermott, Goodwin Procter and Herbert Smith have reported separate data-security incidents.
WilmerHale also faced a federal lawsuit following an alleged breach earlier this year.
The Seyfarth incident highlights how cyberattacks do not always require direct penetration of a company’s technology infrastructure. Social engineering tactics can instead exploit human interaction, persuading employees to disclose information or send sensitive material to unauthorized parties.

