2026 Blank Rome — IT vishing breach; 57,554 clients and individuals (May)
Data compromised
Per California AG sample notice and class-action filings: names, SSNs, addresses, emails, phones, dates of birth, taxpayer and government ID numbers, financial account and payment card data, medical and health-insurance information for current and former clients
Technical writeup
Verified breach — May–June 2026. Blank Rome LLP, a major U.S. law firm, reported a May 21, 2026 cybersecurity incident in which an unauthorized third party contacted an attorney, impersonated the firm's IT department, and persuaded the attorney to upload client files to an external Google Drive account. A California attorney-general breach notice cited at least 57,554 affected individuals; proposed class actions filed July 6, 2026 in Pennsylvania federal court allege plaintiffs were not informed until June 26 and seek more than $5 million in damages. Compromised categories listed in litigation summaries include names, Social Security numbers, government IDs, financial account data, payment card information, and medical/health-insurance records for current and former clients. The incident underscores law-firm vishing risk where a single trusted employee action can exfiltrate sensitive client matter files.
Root cause
Voice-phishing/social-engineering attack: caller posing as firm IT misled an attorney into uploading client files to an external Google Drive account
References
- https://www.law.com/thelegalintelligencer/2026/07/06/blank-rome-sued-twice-over-may-cyber-breach/
- https://news.bloomberglaw.com/business-and-practice/blank-rome-sued-over-breach-exposing-data-of-over-57-000-people
- https://www.forthepeople.com/blog/data-breach-brief-week-july-1st-2026/
- https://www.blankrome.com