DataBreachSearch.com

Did McDermott Will & Schulte LLP have a data breach?

Answer

Yes. McDermott Will & Schulte LLP reported a data breach to the Indiana Attorney General on August 28, 2026.

View the official filing

What the filing says

Reported to
Indiana Attorney General
Filing date
August 28, 2026
Breach date
May 7, 2026
People affected
Not stated in the filing

Information involved

  • Full Name
  • Social Security Number
  • Date of Birth
  • Mailing Address
  • Financial Account Information
  • Tax Record Information
  • Professional Compensation Details
  • Confidential Legal Correspondence

In plain terms

McDermott Will & Schulte LLP operates within the highly sensitive legal services sector, handling complex litigation, corporate transactions, intellectual property matters, and confidential client counseling. Because of the nature of their practice, law firms of this caliber routinely collect, process, and retain vast quantities of confidential, highly regulated data. This includes not only internal employee and operational records, but also extensive dossiers containing proprietary corporate information, sensitive financial details, personally identifiable information (PII) of corporate executives, and sometimes private personal documents related to individual clients involved in high-stakes legal disputes.

In 2026, McDermott Will & Schulte LLP reported a significant data security incident to the Indiana Attorney General, triggering legal scrutiny and mandatory notification procedures. While specific forensic details continue to emerge, incidents affecting prominent legal institutions typically involve sophisticated cyberattacks, such as ransomware deployments, unauthorized entry into legacy document management systems, or compromises of third-party vendor platforms used for e-discovery and client communication. Because law firms serve as central repositories for multiple interconnected corporate and individual networks, they present high-value targets for malicious actors seeking to exploit vulnerabilities in network perimeters or exfiltrate confidential files.

The exposure resulting from a breach of a major law firm threatens individuals whose sensitive records were stored within their systems. Compromised data categories frequently include full names, Social Security numbers, dates of birth, financial account details, tax documents, and confidential correspondence containing privileged or private disclosures. When cybercriminals obtain this combination of PII and financial or tax information, victims face an immediate and severe risk of identity theft, fraudulent credit card applications, unauthorized bank account takeovers, and targeted phishing schemes. For corporate clients and employees whose data is compromised, the fallout can extend to corporate espionage, fraudulent tax filings, and long-term reputational or financial distress.

As custodians of highly sensitive personal and professional data, McDermott Will & Schulte LLP is legally bound by state data protection statutes, common law duties of care, and professional standards of confidentiality to implement robust cybersecurity measures. Under Indiana law and applicable federal guidelines, organizations that collect and maintain PII have an affirmative obligation to deploy reasonable administrative, physical, and technical safeguards—such as multi-factor authentication, endpoint detection, regular vulnerability assessments, and robust data encryption—to prevent unauthorized access. The occurrence of a successful breach strongly indicates potential shortcomings or systemic failures in these required security protocols, raising serious questions about whether the firm fulfilled its legal duties to protect vulnerable data.

Receiving a data breach notification letter from McDermott Will & Schulte LLP serves as formal legal acknowledgment that your personal or professional information was compromised due to inadequate security safeguards. Under modern class action jurisprudence, the receipt of such a notification letter establishes legal standing to participate in a lawsuit, allowing affected individuals to demand accountability and compensation without needing to wait until actual financial fraud occurs. Our law firm is currently investigating potential class action claims against McDermott Will & Schulte LLP on behalf of affected individuals. We handle all data breach cases on a strict contingency fee basis, meaning you pay nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.

Commonly recommended next steps

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Indiana

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with McDermott Will & Schulte LLP.