Holland & Knight and Squire Patton Boggs disclosed data security breaches to state regulators on October 9. Both firms said Social Security numbers were exposed during the incidents. Holland & Knight said "a threat actor used social engineering techniques to gain unauthorized remote access" to a firm computer. No services stopped.

WASHINGTON, Oct 9 (Reuters) - Two more large US law firms, Holland & Knight and Squire Patton Boggs, have disclosed data security breaches to state regulators, and a third was hit ​with a new proposed class action in federal court over a reported hack.

Holland & ‌Knight, which employs 2,200 lawyers, and the 2,600-attorney Squire Patton Boggs both told Vermont’s state attorney general on Thursday that Social Security numbers were exposed in the incidents that affected the firms.

Sign up here.

Holland & Knight in a ​statement said "a threat actor used social engineering techniques to gain unauthorized remote access to ​a firm computer." It said it "identified the small number of files involved ⁠and promptly notified the clients whose information was contained in those files."

Squire Patton Boggs in ​a statement said its incident involved "an unauthorized third party obtaining a limited set of information ​from the firm." Both firms said there was no disruption to their client services.

In a statement, the firm said a cyber group that targets law ​firms “accessed the laptop of a single user and copied a limited number of documents accessible by this user.”

The ‌firm, ⁠which employs more than 1,000 lawyers, said the incident “was contained and did not involve any other systems, devices, or accounts.” Nelson Mullins said it was in contact with law enforcement authorities and supporting their investigation.

The latest disclosures underscore cybersecurity risks for law firms, which routinely hold ​sensitive client communications, financial ​records and personal data ⁠that can be valuable to hackers.

Recent breaches at major law firms have highlighted how cybercriminals are increasingly targeting the legal industry through tactics ​including so-called social-engineering schemes designed to gain access to confidential information.

Several ​law firms ⁠including WilmerHale and Weil Gotshal have paid a ransom or suppression payment following a data breach. WilmerHale is also facing a lawsuit in DC federal court over its alleged breach.

Reporting by Mike Scarcella