In the first two days of October, three law firms filed data breach notices with the California Attorney General. Greenberg Traurig on October 1. Sheppard Mullin and Fragomen on October 2. Widen the window to three weeks, and the count reaches five, with Seyfarth Shaw and Tarter Krinsky & Drogin also on the public register.

That register exists because California requires any organization notifying more than 500 state residents about a single breach to send the Attorney General a sample copy of the notice, which is then posted publicly. It is one of the few places where you can read what a firm actually told its clients, rather than what a headline says happened.

Two of those notices are worth reading closely, because they describe the same thing happening twice.

The network was not the problem

Sheppard Mullin’s notice describes an incident on August 31 that was discovered the next day and involved one attorney. The firm calls it “a sophisticated social engineering event which resulted in the unauthorized disclosure of certain documents to an unknown third-party,” and states plainly that the firm’s broader systems and network were not compromised. One person was persuaded to send files. That was the whole mechanism.

Seyfarth Shaw’s notice reads much the same. The firm identified the unauthorized acquisition of a limited number of documents on August 18, determined there was no breach of its network, and described the documents as having been “sent by email to an unauthorized recipient.” The incident involved names and Social Security numbers. Afterward, the firm took additional steps, including employee training.

Neither firm reports a failed firewall, an unpatched server, or a stolen credential. In both cases, the documents went out through a legitimate account doing something that, at the time, looked like ordinary work. We wrote about a close cousin of this pattern in August, when fake IT support calls started targeting law firms by asking staff for access rather than stealing it. The request arrives looking authorized. The system behaves exactly as designed.

For a firm administrator, that is an uncomfortable finding, because most security conversations focus on keeping people out. These two incidents are about something leaving.

The second number in every notice

These filings include a second detail that gets less attention than the breach itself: how long it took.

Seyfarth identified its incident on August 18 and dated its notice letters September 18, a month later. Sheppard Mullin discovered its incident on September 1 and filed with California on October 2, also about a month. Greenberg Traurig’s incident is dated August 26, and it filed on October 1. Fragomen’s incident dates are May 4 and 5; it filed on October 2, roughly five months later.

That span is not mainly a legal question. It is an operational one. Between discovering that something left and telling clients what left sits a review: who had access, which files were in the account, what was actually in those files, and which named individuals appear in them. A firm that already documents mailbox and file-share access, retains the logs that show it, and can reconstruct its own data can answer those questions in weeks. A firm that reassembles that record after the fact takes months and spends every one of them with clients waiting.

This is the same readiness question we raised about knowing which vendors hold your client data and about where AI meeting notes end up. Each time it comes back to an inventory problem: you cannot report on data you cannot locate.

What we do about it

Law firms shouldn’t have to suffer preventable problems like these, and you deserve better than discovering your records were incomplete during a forensic review.

Innovative Computing Systems treats this as two jobs that belong to us, not a checklist we hand over.

The first is making the request harder to land. We run security awareness training built around what actually happens in a firm, including urgent document and payment requests with a plausible name attached, so your staff recognizes the pattern before they act. We pair that with email controls, multifactor authentication, and single sign-on, so a borrowed credential isn’t enough on its own. We run monitoring and detection across your environment so someone whose job it is to look sees unusual outbound activity and quiet mailbox changes. Attackers have gotten better at this, as recent survey data on AI-assisted attacks makes clear, which is exactly why you can’t leave detection to whoever notices first.

The second job is making the answer fast. We maintain documentation and asset inventory for your environment, including where data lives and who can reach it, so the question “what left, and whose information was in it” has a record behind it instead of a reconstruction. We keep backup and disaster recovery in place and tested. We bring this into your strategic reviews, so you close gaps on a schedule rather than discovering them during an incident. The same thinking applies to knowing which systems are quietly moving your documents around before something goes wrong.

None of that removes the possibility of a convincing request reaching one of your people. It changes what happens next, which is the part you can actually control: how quickly it is caught, how completely it is understood, and how soon your clients hear from you with something definite.

We’ve got your back

We have worked exclusively with law firms since 1989, which means we have sat with administrators through enough of these weeks to know that the hardest part is rarely the technology itself — it is standing in front of a managing partner and a client without a complete answer.

Our job is to make sure you have one. We build environments that are safe, secure, and reliable; we own the monitoring and the record-keeping that an incident demands; and we stay alongside your team rather than handing the work back.

If you would like to look at how your firm would answer those questions today, request a consultation and a Solutions Consultant will follow up to set up a conversation about your environment.